MockzillaMockzilla

Mirrors and air-gapped hosts

Updated Sep 29, 2026·4 min read

Your machines do not have to reach our registry. Point Artifactory, Nexus or Harbor at it once, and your machines pull from that mirror. Only the mirror talks to us. For a host with no network at all, copy the image to a file and carry it over.

The backend's Mirrors tab has every step below, with your hostname, image name and version filled in.

Mirrors: the steps for Artifactory, with your registry filled in.

Before you start

Create a registry credential for the mirror under Settings, in Image registry. Name it after the mirror, so its pulls are easy to tell apart. One credential covers every backend in your organization.

See Pull your image.

The examples below pull the image ci-payments at version v2026.09.23.3.

Artifactory

Add two remote repositories: a Docker one for the images, and a Generic one for the files that ship with them. Fill in these fields and leave the rest as they are:

Repository Key   mockzilla
Package Type     Docker
URL              https://<your-org>.registry.mockzilla.org
Docker API       V2
Username         <the credential's username>
Password         <the credential's password>
Enable token authentication   yes

Repository Key   mockzilla-files
Package Type     Generic
URL              https://<your-org>.registry.mockzilla.org/files
Username         <the credential's username>
Password         <the credential's password>

Then pull through it:

docker login artifactory.example.com
docker pull artifactory.example.com/mockzilla/ci-payments:v2026.09.23.3

The files come through the second repository, at https://artifactory.example.com/artifactory/mockzilla-files/ci-payments/v2026.09.23.3.

Nexus

Add two proxy repositories: a docker one for the images, and a raw one for the files that ship with them.

Recipe           docker (proxy)
Remote storage   https://<your-org>.registry.mockzilla.org
Docker Index     Use proxy registry
Authentication   Username, with the credential above

Recipe           raw (proxy)
Remote storage   https://<your-org>.registry.mockzilla.org/files
Authentication   Username, with the credential above

Then pull through it:

docker login nexus.example.com:8443
docker pull nexus.example.com:8443/ci-payments:v2026.09.23.3

Here 8443 stands for the HTTP connector port you gave the docker repository. The files come through the raw one, at https://nexus.example.com/repository/mockzilla-files/ci-payments/v2026.09.23.3.

Harbor

Add a registry endpoint, then a proxy cache project that uses it:

Administration › Registries › New endpoint
Provider         Docker Registry
Name             mockzilla
Endpoint URL     https://<your-org>.registry.mockzilla.org
Access ID        <the credential's username>
Access Secret    <the credential's password>
Verify Remote Cert   yes

Projects › New project
Project Name     mockzilla
Proxy Cache      on, with the mockzilla endpoint

Then pull through it:

docker login harbor.example.com
docker pull harbor.example.com/mockzilla/ci-payments:v2026.09.23.3

Harbor keeps images only. Take the files that ship with the image straight from your registry.

A host with no network

On a machine that can reach your registry, copy the image to a file with crane, a small command line tool for registries:

docker login <your-org>.registry.mockzilla.org
crane pull <your-org>.registry.mockzilla.org/ci-payments:v2026.09.23.3 ci-payments.tar

Take the files that ship with the image along too. Move both to the other side, then load the image:

docker load -i ci-payments.tar

Or push it into the registry your machines pull from:

crane push ci-payments.tar registry.internal/ci-payments:v2026.09.23.3

An image on a host with no network cannot fetch its license. It has to carry it inside, or read a license file you mount.

See Licenses.

Where to go next

Was this page helpful?