From e0ba472be9ff5c9a735293616f78b732801884f2 Mon Sep 17 00:00:00 2001 From: Brian Rubinton Date: Wed, 30 Sep 2026 14:13:29 -0500 Subject: [PATCH 1/2] docs: clarify dhi.io proxy access in mirroring guide Signed-off-by: Brian Rubinton --- content/manuals/dhi/how-to/mirror.md | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/content/manuals/dhi/how-to/mirror.md b/content/manuals/dhi/how-to/mirror.md index e363758862e..0827d1383d3 100644 --- a/content/manuals/dhi/how-to/mirror.md +++ b/content/manuals/dhi/how-to/mirror.md @@ -232,10 +232,19 @@ You can use any standard workflow to mirror the image, such as the API](/reference/api/registry/latest/), third-party registry tools, or CI/CD automation. -However, to preserve the full security context, including attestations, you must -also mirror its associated OCI artifacts. DHI repositories store the image -layers on `dhi.io` (or `docker.io` for customized images) and the signed -attestations in a separate registry (`registry.scout.docker.com`). +Mirroring an image requires copying both the image and its associated signed +attestations, including SBOMs, provenance, and VEX. Copying only the image does +not preserve these attestations in your destination registry. + +When you access a DHI image through `dhi.io`, the proxy provides access to both +the image and its associated attestations. It retrieves image manifests and +layers from Docker Hub, and attestations from `registry.scout.docker.com`. + +The examples that follow copy from your organization's mirrored repository on +Docker Hub. They therefore use two source locations: +`docker.io//` for the image and +`registry.scout.docker.com//` for its attestations. Both +are copied into the same repository in your destination registry. To copy both, you can use [`regctl`](https://regclient.org/cli/regctl/), an OCI-aware CLI that supports mirroring images along with attached artifacts such From 6c635e2af23d706dd798f9c91cf7f1587e3cc1d3 Mon Sep 17 00:00:00 2001 From: Brian Rubinton Date: Wed, 30 Sep 2026 15:15:25 -0500 Subject: [PATCH 2/2] docs: distinguish catalog access from customer mirrors Signed-off-by: Brian Rubinton --- content/manuals/dhi/how-to/mirror.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/content/manuals/dhi/how-to/mirror.md b/content/manuals/dhi/how-to/mirror.md index 0827d1383d3..48a6077eea4 100644 --- a/content/manuals/dhi/how-to/mirror.md +++ b/content/manuals/dhi/how-to/mirror.md @@ -236,12 +236,13 @@ Mirroring an image requires copying both the image and its associated signed attestations, including SBOMs, provenance, and VEX. Copying only the image does not preserve these attestations in your destination registry. -When you access a DHI image through `dhi.io`, the proxy provides access to both -the image and its associated attestations. It retrieves image manifests and -layers from Docker Hub, and attestations from `registry.scout.docker.com`. +The `dhi.io` proxy provides access to DHI catalog images and their associated +attestations. It retrieves image manifests and layers from Docker Hub, and +attestations from `registry.scout.docker.com`. -The examples that follow copy from your organization's mirrored repository on -Docker Hub. They therefore use two source locations: +Customer mirrors and customized images are accessed through your organization's +repositories on Docker Hub. These repositories are not available through +`dhi.io`. The following examples therefore use two source locations: `docker.io//` for the image and `registry.scout.docker.com//` for its attestations. Both are copied into the same repository in your destination registry.