Container Registry
Made in Germany

Private container registry for your images on sovereign EU infrastructure. Secure management, high performance, and seamless integration with your Kubernetes clusters.

Private container registry on sovereign EU infrastructure. Secure image management, seamless Kubernetes integration, and compliance – Made in Germany.

Learn more

Leading companies trust our technology ↘

Manage images securely

Our container registry is based on Harbor and operated as a managed service on your Kubernetes platform – including scanning, replication, and RBAC.

OCI compatible

Standards-based

Full compatibility with Docker, containerd, and common CI/CD tools. Push and pull without changing your workflows.
OCI Docker containerd

Vulnerability scanning

Security by design

Automatic scanning of images for known vulnerabilities. Policies block unsafe images before deployment.
CVE Scanning Security

RBAC & projects

Fine-grained access

Projects, teams, and roles for multi-tenant environments. Integration with your identity provider via OIDC.
RBAC OIDC Multi-Tenant

Geo-replication

Images close to the cluster

Replicate images between regions and clusters – for fast pulls and disaster recovery without external dependencies.
Replication HA DR

Kubernetes-native

Seamless integration

Automatic configuration of imagePullSecrets, policies, and managed apps – your registry is part of the platform.
Kubernetes GitOps ArgoCD

EU infrastructure

Sovereign hosting

Operated on European infrastructure. No transfer of sensitive images to US clouds – GDPR-compliant.
EU GDPR Sovereignty

Pricing

Transparent pricing with no hidden costs – shared region billed by usage, same model as S3 storage.

Shared Region

Pay-as-you-go · Multi-Tenant

€0.05 /GB/month

  • €0.05/GB/month
  • 1 TB storage included for managed service customers
  • Harbor-based, OCI-compatible
  • Vulnerability scanning included
  • No ingress costs
  • No egress costs
  • RBAC & OIDC

Dedicated Region

Dedicated cluster · Single-Tenant

from €1,495.95 /month

  • Dedicated Kubernetes cluster in an ayedo cloud region
  • Dedicated Harbor registry on your cluster
  • Vulnerability scanning & image signing
  • Geo-replication across regions
  • Own projects & repositories
  • No ingress/egress costs
  • Custom SLAs

On-Premise

In your data center

Custom

  • Fully dedicated
  • On your infrastructure
  • Unlimited repositories
  • Air-gapped support
  • Enterprise support
  • Compliance-ready
  • Custom SLAs

Comparison with Alternatives

Our container registry is the sovereign alternative to the registry services of US hyperscalers.

vs. AWS ECR

Kriterium ayedo AWS ECR
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Pricing
€0.05/GB – transparent
Storage + transfer
Scanning
Harbor included
Additional costs
Vendor Lock-in
OCI standard
AWS-specific

vs. Azure Container Registry

Kriterium ayedo Azure Container Registry
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Pricing
Per GB, clear
Tiers + geo-repl.
Kubernetes
Native integration
AKS-focused
Support
Personal, German-speaking
Ticket system

vs. Google Artifact Registry

Kriterium ayedo Google Artifact Registry
Jurisdiction
EU / GDPR compliant
US / Cloud Act
Egress Costs
None
Varies by region
Harbor Features
Replication, RBAC, OIDC
GCP-specific
On-Premise
Available
Cloud only

Compliance & Regulatory Requirements

The ayedo Software Delivery Platform meets the requirements of current EU regulations. From GDPR to NIS-2 to DORA – our platform is designed for regulated industries and critical infrastructures.

GDPR-Compliant Data Processing

Privacy by Design & Default.

EU data residency (Germany), Customer-Managed Keys (BYOK/BYOHSM), encryption at rest/in transit. ISO 27001-certified data protection management. Support for data subject rights, DPA, incident response. More about GDPR.

NIS-2-Compliant Operations

Resilience for critical infrastructures.

24/7 monitoring, incident response, BCP/DR processes, supply chain transparency (SBOM). EU-based operations, MFA/PAM, vulnerability management, patch processes. Ideal for essential/important entities. More about NIS-2.

DORA-Ready for Financial Institutions

ICT resilience tailored.

ICT risk management framework, documented exit strategies, third-party risk management, TLPT readiness. Structured incident reporting chains, continuous resilience testing, ISO 27001-certified. More about DORA.

CRA-Compliant Software Supply Chain

Security by Design across the entire lifecycle.

SBOM generation, CVE scanning, vulnerability disclosure processes, update management. Signed container images, GitOps-based audit trails, transparent supply chain. More about CRA.

Cloud Sovereignty Framework

Digital sovereignty made measurable.

EU-based operations, open standards, exit capability without lock-in. Designed for SEAL-4 (Full Digital Sovereignty) across all eight sovereignty objectives. No dependencies on non-EU control. More about the Framework.

Data Act-Compliant Portability

Switching without barriers.

Open APIs (OpenAPI), standardized formats (YAML/JSON/OCI), complete exit runbooks, Infrastructure-as-Code portability. Multi-cloud capable, no egress fees, functional equivalence. More about Data Act.

Integrated Compliance Roadmap

Holistic approach.

How ayedo systematically addresses GDPR, NIS-2, DORA, CRA, Data Act, Cloud Sovereignty Framework, ISO 27001/9001. Certifications, processes, technical measures, audit readiness. To overview.

Integration with Polycrate

The container registry is part of the Polycrate Software Security Framework and integrates seamlessly with Kubernetes, S3 storage, and your CI/CD pipelines.

Managed Kubernetes

Pull inside the cluster

imagePullSecrets, policies, and local registry endpoints for your managed Kubernetes clusters – without routing through public registries.
Kubernetes Harbor imagePullSecret

Harbor

Enterprise registry

Built on Harbor – scanning, replication, Notary, and RBAC as a managed service on the ayedo platform.
Harbor CVE Signing

S3 Storage

Scalable blob storage

Registry data on S3 storage – the same sovereign infrastructure and per-GB pricing model.
S3 CEPH Storage

Polycrate API

Central management

Manage projects, credentials, and roles via the Polycrate API – web UI or infrastructure as code.
API Terraform GitOps

You build it. We run it.

Excellent performance and maximum uptime - that’s what we wake up for. And sometimes even in the middle of the night.

270 Million End Users

per month

More than 9 million end users use software we deploy every day, on the internet or on-premise.
User Endanwender Software

99.99% Uptime

annual average

Our managed services are unavailable for less than 1 hour per year on average.
Uptime Verfügbarkeit SLA

MTTD < 5 Minutes

on average

Our granular alerting system detects errors and outages faster than you can say ‘Service Level Agreement’.
MTTD Monitoring Detection

34 Billion Logs

per month

More than 10000 logs per second are collected by our collectors and stored GDPR-compliant.
Logs Observability Ingestion

71 Million Active Timeseries

per month

2.7 million datapoints are measured per second by our monitoring systems.
Monitoring Metrics Datapoints

50 TB Backups

per month

More than 2000 backups are stored daily on our encrypted long-term storage.
Backup Storage Sicherheit