Mirrors and air-gapped hosts
Your machines do not have to reach our registry. Point Artifactory, Nexus or Harbor at it once, and your machines pull from that mirror. Only the mirror talks to us. For a host with no network at all, copy the image to a file and carry it over.
The backend's Mirrors tab has every step below, with your hostname, image name and version filled in.
Before you start
Create a registry credential for the mirror under Settings, in Image registry. Name it after the mirror, so its pulls are easy to tell apart. One credential covers every backend in your organization.
See Pull your image.
The examples below pull the image ci-payments at version v2026.09.23.3.
Artifactory
Add two remote repositories: a Docker one for the images, and a Generic one for the files that ship with them. Fill in these fields and leave the rest as they are:
Repository Key mockzilla
Package Type Docker
URL https://<your-org>.registry.mockzilla.org
Docker API V2
Username <the credential's username>
Password <the credential's password>
Enable token authentication yes
Repository Key mockzilla-files
Package Type Generic
URL https://<your-org>.registry.mockzilla.org/files
Username <the credential's username>
Password <the credential's password>Then pull through it:
docker login artifactory.example.com
docker pull artifactory.example.com/mockzilla/ci-payments:v2026.09.23.3The files come through the second repository, at https://artifactory.example.com/artifactory/mockzilla-files/ci-payments/v2026.09.23.3.
Nexus
Add two proxy repositories: a docker one for the images, and a raw one for the files that ship with them.
Recipe docker (proxy)
Remote storage https://<your-org>.registry.mockzilla.org
Docker Index Use proxy registry
Authentication Username, with the credential above
Recipe raw (proxy)
Remote storage https://<your-org>.registry.mockzilla.org/files
Authentication Username, with the credential aboveThen pull through it:
docker login nexus.example.com:8443
docker pull nexus.example.com:8443/ci-payments:v2026.09.23.3Here 8443 stands for the HTTP connector port you gave the docker repository. The files come through the raw one, at https://nexus.example.com/repository/mockzilla-files/ci-payments/v2026.09.23.3.
Harbor
Add a registry endpoint, then a proxy cache project that uses it:
Administration › Registries › New endpoint
Provider Docker Registry
Name mockzilla
Endpoint URL https://<your-org>.registry.mockzilla.org
Access ID <the credential's username>
Access Secret <the credential's password>
Verify Remote Cert yes
Projects › New project
Project Name mockzilla
Proxy Cache on, with the mockzilla endpointThen pull through it:
docker login harbor.example.com
docker pull harbor.example.com/mockzilla/ci-payments:v2026.09.23.3Harbor keeps images only. Take the files that ship with the image straight from your registry.
A host with no network
On a machine that can reach your registry, copy the image to a file with crane, a small command line tool for registries:
docker login <your-org>.registry.mockzilla.org
crane pull <your-org>.registry.mockzilla.org/ci-payments:v2026.09.23.3 ci-payments.tarTake the files that ship with the image along too. Move both to the other side, then load the image:
docker load -i ci-payments.tarOr push it into the registry your machines pull from:
crane push ci-payments.tar registry.internal/ci-payments:v2026.09.23.3An image on a host with no network cannot fetch its license. It has to carry it inside, or read a license file you mount.
See Licenses.