ayedo Container Registry

Container Registry
Made in Germany

Private image management in the platform cluster – ayedo operates Harbor for you including scanning and updates. Faster go-live for CI/CD pipelines, predictable operations costs, developers push images instead of waiting on registry ops.

Leading companies trust our technology ↘

Manage images securely

Our container registry is based on Harbor and operated as a managed service in the platform cluster – including scanning, replication, RBAC, and updates by ayedo. Your team ships containers; we secure storage and compliance.

OCI compatible

Standards-based

Full compatibility with Docker, containerd, and common CI/CD tools. Push and pull without changing your workflows.
OCI Docker containerd

Vulnerability scanning

Security by design

Automatic scanning of images for known vulnerabilities. Policies block unsafe images before deployment.
CVE Scanning Security

RBAC & projects

Fine-grained access

Projects, teams, and roles for multi-tenant environments. Integration with your identity provider via OIDC.
RBAC OIDC Multi-Tenant

Geo-replication

Images close to the cluster

Replicate images between regions and clusters – for fast pulls and disaster recovery without external dependencies.
Replication HA DR

Kubernetes-native

Seamless integration

Automatic configuration of imagePullSecrets, policies, and managed apps – your registry is part of the platform.
Kubernetes GitOps ArgoCD

EU infrastructure

Sovereign hosting

Operated on European infrastructure. Images and metadata stay in the EU – GDPR-compliant.
EU GDPR Sovereignty

Pricing

Transparent pricing with no hidden costs – shared region billed by usage, same model as S3 storage.

ayedo Cloud

Pay-as-you-go · Multi-Tenant

€0.05 /GB/month

  • €0.05/GB/month
  • 1 TB storage included for managed service customers
  • Harbor-based, OCI-compatible
  • Vulnerability scanning included
  • No ingress costs
  • No egress costs
  • RBAC & OIDC

Dedicated

Dedicated platform cluster · Single-Tenant

from €1,495.95 /month

  • Dedicated platform cluster in an ayedo cloud region
  • Dedicated Harbor registry in the platform cluster
  • Vulnerability scanning & image signing
  • Geo-replication across regions
  • Own projects & repositories
  • No ingress/egress costs
  • Custom SLAs

BYOC / On-Premises

On your infrastructure

Custom

  • Fully dedicated
  • On your infrastructure
  • Unlimited repositories
  • Air-gapped support
  • Enterprise support
  • Compliance-ready
  • Custom SLAs

Comparison with Alternatives

Managed Harbor on EU infrastructure – with scanning, replication, and predictable storage costs.

vs. AWS ECR

Kriterium ayedo AWS ECR
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Pricing
€0.05/GB – transparent
Storage + transfer
Scanning
Harbor included
Additional costs
Vendor Lock-in
OCI standard
AWS-specific

vs. Azure Container Registry

Kriterium ayedo Azure Container Registry
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Pricing
Per GB, clear
Tiers + geo-repl.
Kubernetes
Native integration
AKS-focused
Support
Personal, German-speaking
Ticket system

vs. Google Artifact Registry

Kriterium ayedo Google Artifact Registry
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Egress Costs
None
Varies by region
Harbor Features
Replication, RBAC, OIDC
GCP-specific
On-Premise
Available
Cloud only

Compliance & Regulatory Requirements

The ayedo Software Delivery Platform meets the requirements of current EU regulations. From GDPR to NIS-2 to DORA – our platform is designed for regulated industries and critical infrastructures.

GDPR-Compliant Data Processing

Privacy by Design & Default.

EU data residency (Germany), Customer-Managed Keys (BYOK/BYOHSM), encryption at rest/in transit. ISO 27001-certified data protection management. Support for data subject rights, DPA, incident response. More about GDPR .

NIS-2-Compliant Operations

Resilience for critical infrastructures.

24/7 monitoring, incident response, BCP/DR processes, supply chain transparency (SBOM). EU-based operations, MFA/PAM, vulnerability management, patch processes. Ideal for essential/important entities. More about NIS-2 .

DORA-Ready for Financial Institutions

ICT resilience tailored.

ICT risk management framework, documented exit strategies, third-party risk management, TLPT readiness. Structured incident reporting chains, continuous resilience testing, ISO 27001-certified. More about DORA .

CRA-Compliant Software Supply Chain

Security by Design across the entire lifecycle.

SBOM generation, CVE scanning, vulnerability disclosure processes, update management. Signed container images, GitOps-based audit trails, transparent supply chain. More about CRA .

Cloud Sovereignty Framework

Digital sovereignty made measurable.

EU-based operations, open standards, exit capability without lock-in. Designed for SEAL-4 (Full Digital Sovereignty) across all eight sovereignty objectives. No dependencies on non-EU control. More about the Framework .

Data Act-Compliant Portability

Switching without barriers.

Open APIs (OpenAPI), standardized formats (YAML/JSON/OCI), complete exit runbooks, Infrastructure-as-Code portability. Multi-cloud capable, no egress fees, functional equivalence. More about Data Act .

Integrated Compliance Roadmap

Holistic approach.

How ayedo systematically addresses GDPR, NIS-2, DORA, CRA, Data Act, Cloud Sovereignty Framework, ISO 27001/9001. Certifications, processes, technical measures, audit readiness. To overview .

Integration with Polycrate

The container registry is part of the Polycrate Software Security Framework and integrates seamlessly with Kubernetes , S3 storage , and your CI/CD pipelines.

Managed Kubernetes

Pull inside the cluster

imagePullSecrets, policies, and local registry endpoints for your managed Kubernetes clusters – without routing through public registries.
Kubernetes Harbor imagePullSecret

Harbor

Enterprise registry

Built on Harbor – scanning, replication, Notary, and RBAC as a managed service on the ayedo platform.
Harbor CVE Signing

S3 Storage

Scalable blob storage

Registry data on S3 storage – the same sovereign infrastructure and per-GB pricing model.
S3 CEPH Storage
Polycrate API

Polycrate API

Central management

Manage projects, credentials, and roles via the Polycrate API – web UI or infrastructure as code.
API Terraform GitOps

You build it. We run it.

Excellent performance and maximum uptime - that’s what we wake up for. And sometimes even in the middle of the night.

100+ Clusters

under management

We operate more than 100 Kubernetes clusters in production for our customers.

300+ Databases

under management

We operate, monitor, and back up more than 300 databases in production.

1 Petabyte Object Storage

under management

We operate one petabyte of object storage for backups, artifacts, and application data.

100 Million Timeseries

on average

4 million datapoints per second are ingested by our monitoring systems.

38,000+ Logs

per second

Our collectors continuously ingest logs and store them in a GDPR-compliant way – more than 100 billion entries per month.

5,000+ Backups

per day

We secure more than 5,000 backups every day on encrypted long-term storage – around 150 terabytes of backup volume per month.

270 Million End Users

per month

More than 9 million end users use software we deploy every day, on the internet or on-premise.

99.99% Uptime

annual average

Our managed services are unavailable for less than 1 hour per year on average.

MTTD < 5 Minutes

on average

Our alerting typically detects errors and outages within a few minutes.
Kontakt aufnehmen