MockzillaMockzilla

Pull your image

Updated Sep 29, 2026·3 min read

Your organization has a registry of its own, at <your-org>.registry.mockzilla.org. Every build lands there, and you pull it with a credential you create. The hostname never changes.

Create a credential

Open Settings and the Image registry tab. The tab shows once you have a self-hosted backend. Owners and admins manage credentials.

Choose Create credential, give it a name, such as the tool or team that uses it, and choose Create. The dialog shows the username and password, with the docker login that uses them. Copy the password now: it is shown once and never again.

Image registry: your registry's hostname, what you can pull, and your credentials.
  • One credential pulls every backend in your organization.
  • Several can be active at once. To replace one, create the new one, switch to it, then revoke the old one.
  • Revoke stops a credential within five minutes.
  • Last pull shows when a credential was last used.

A credential proves who is pulling. Your license decides what it may pull, at the moment of each pull. Once a license expires, its image can no longer be pulled.

Pull with docker

Sign in once, then pull the version you want:

docker login <your-org>.registry.mockzilla.org
docker pull <your-org>.registry.mockzilla.org/ci-payments:v2026.09.23.3

Here ci-payments is the image name and v2026.09.23.3 the version. The backend's Registry tab shows this command with your own filled in, and every version you can pull.

Pull in Kubernetes

Create a pull secret with the credential's username and password:

kubectl create secret docker-registry mockzilla \
  --docker-server=<your-org>.registry.mockzilla.org \
  --docker-username=<username> \
  --docker-password=<password>

Then name it under imagePullSecrets in the pod spec. The backend's Quick start has a whole Deployment.

See Run the image.

The files that ship with it

Each version has a folder of files next to the image:

https://<your-org>.registry.mockzilla.org/files/<image name>/<version>
  • README.md and README.html: how to run the image, for a team with a registry credential and no Mockzilla account.
  • license.json: the license the image was built with.
  • data.mockz: your contexts, scenarios and service config, as packed into the image.
  • storage: a folder for each storage driver the image holds, with its settings and the files that set up its database.
  • SHA256SUMS: a checksum for each file.
  • linux-amd64 and linux-arm64: per platform, the image as a file, its SBOMs and its security report.

Open the folder in a browser and sign in with the same credential, or fetch a file with curl:

curl -u <username>:<password> -O \
  https://<your-org>.registry.mockzilla.org/files/ci-payments/v2026.09.23.3/license.json

When a pull is refused

  • 401 Unauthorized: the username or password is wrong, or the credential was revoked.
  • 403 Forbidden: the credential is fine, but the pull is not allowed, for example because the license expired. The error says why.

Each pull counts toward your organization's pull allowance, and so does each file you fetch.

Where to go next

Was this page helpful?