Retention runs
See the registry's past retention sweeps, preview what a sweep would do to one repository, and start a sweep yourself.
Requires: registry/audit/read, registry/retention/manage
The portal has no page for retention runs; use the API, here through stsh api. Listing runs
and previewing need registry/audit/read at the platform root; starting a run needs
registry/retention/manage there. Platform Owner and Platform Contributor have both, Platform
Reader the first.
Important
In this version the sweep finds no pushed images to consider, so runs report
0images seen and previews return empty lists; see Retention.
See past runs
stsh api GET "/v1/registries/retention/runs?limit=20"The newest runs come first; limit is 1 to 200, 50 by default. Each run has:
| Field | Meaning |
|---|---|
startedAt, finishedAt |
When it ran |
dryRun |
Whether it only recorded what it would delete |
digestsSeen |
How many distinct images it looked at |
digestsDeleted |
How many it deleted, or would have deleted in a dry run |
bytesFreed |
Always 0 in this version |
isFinished, isSuccess |
Whether it has finished, and without an error |
error |
What went wrong, when it failed |
Preview a repository
To see what the next sweep would keep and delete in one repository, without deleting anything:
stsh api GET "/v1/registries/retention/preview?boundary=<boundary-id>&repository=apps/<boundary-id>/<namespace>/<app-name>"The answer lists keepDigests and deleteDigests. A non-empty skippedReason means the sweep
would leave the repository alone; no-pin-data says that no app or function has reported
its images in the last hour — see Retention. Repository names are in the repository field of the
audit log.
Start a run
A run started by hand goes through every repository, like the nightly one, and answers when it has finished. Try it as a dry run first:
stsh api POST /v1/registries/retention/runs -d '{"dryRun": true}'A dry run deletes nothing and records a delete.dryrun event in the audit log for each image it
would delete. Every run, dry or not, also writes the registry's pending audit events to the log;
see Registry audit log. Send {"dryRun": false} to delete; leave dryRun out to use the module's
setting. The answer is the run, with the fields above.