Ocireg is an MCP server that allows large language model applications to interact directly with Open Container Initiative (OCI) registries. Built using Server-Sent Events (SSE), the server connects AI assistants to container image registries such as Docker Hub and private OCI-compliant repositories. It is designed for DevOps engineers, platform teams, and developers who need automated workflows for inspecting container artifacts. Through structured tool calls, the server enables connected clients to query image references to retrieve comprehensive metadata, including image digest values, total size, architecture, operating system, creation dates, and layer counts. It also provides tools to list available repository tags, fetch raw image manifests, and inspect detailed runtime configurations such as entrypoints, environment variables, and exposed network ports. For private registries, the server supports bearer tokens, username-and-password credentials, and local Docker configuration files. By bringing container registry introspection directly into LLM-driven development environments, Ocireg assists with verifying image deployments, auditing build artifacts, and debugging container setup requirements without requiring manual command-line registry queries.
Category: Cloud & Infrastructure
Tags: containers, docker, kubernetes, oci, registry
thv client setup. 3. Run the server using ToolHive with thv run oci-registry. 4. If accessing private registries, set authentication credentials with thv secret set oci-token or thv secret set oci-username and thv secret set oci-password. 5. Run the server with secrets passed: thv run --secret oci-token,target=OCI_TOKEN oci-registry. 6. Check server status with thv list or thv registry info oci-registry. Alternatively, compile from source with Go 1.21 or later using go test ./... and launch ./ocireg-mcp -port 8080, configuring authentication via OCI_TOKEN or OCI_USERNAME and OCI_PASSWORD environment variables.get_image_info. - Enumerate repository tags: List all published tags for any public or private OCI repository using the list_tags tool. - Extract image manifests: Fetch raw JSON manifest schemas and digest pointers for container image references using the get_image_manifest tool. - Inspect container configurations: Query runtime environments, entrypoints, working directories, and exposed network ports using the get_image_config tool.Part of MCP Servers
Ocireg is a Model Context Protocol server that communicates via Server-Sent Events to let AI agents query OCI-compliant container registries. It exposes tools to fetch image specifications, list tags, review configurations, and inspect raw manifests across public and private container repositories.
You can deploy Ocireg using ToolHive by running thv client setup followed by thv run oci-registry. If you prefer manual setup, build the server from source with Go 1.21 or later, configure registry credentials via environment variables, and run the binary using the -port flag.
Ocireg authenticates against private registries using four methods in order of priority: an HTTP Authorization Bearer token header, an OCI_TOKEN environment variable, OCI_USERNAME and OCI_PASSWORD environment variables, or a fallback to local Docker credentials located in your Docker configuration file.
Ocireg provides four core tools: get_image_info for size, OS, and layer metadata; list_tags to fetch all tags for a repository; get_image_manifest for raw manifest schemas; and get_image_config for inspecting container environment variables, entrypoints, and exposed ports.
Yes, Ocireg is open source software released under the Apache v2 License. You can inspect the source code, contribute pull requests, file bug reports, and review implementation details directly on GitHub in the StacklokLabs ocireg-mcp repository.