How credentials are handled
Whichever method you choose, the panel assembles a Kubernetes.dockerconfigjson in your browser and sends it once, on create, as part of the request.
From then on:
- The backend masks it. It is never returned to the UI.
- Only a sanitized descriptor comes back — the registry
server, the credentialtype, and an expiry timestamp where one applies — so the UI can show “credentials configured for this registry” without ever holding the secret. - Xano provisions a microservice-owned pull secret named after the service, in the form
<identifier>-pull. For a microservice namedecho-dockerthat isecho_docker-pull, and it appears in the Summary pane and in the generated XanoScript.
Authentication methods
- Docker / v2
- Google Artifact Registry
- AWS ECR
Use for: Docker Hub, GHCR, GitLab, Quay, or any Docker v2 registry.Provide a username and a password or access token. Prefer an access token over an account password wherever the registry offers one.The registry host is derived from the image automatically —
index.docker.io when the image has no host prefix. It stays editable, and auto-derivation stops as soon as you edit it by hand, so a later change to the image won’t overwrite a host you set deliberately.