Image catalog
The set of images anyone can run is a list somebody approved.
Introduced Aug 4, 2026
How it works
Three slots.
Workspace, agent runtime, and MCP images register separately, with per-organization visibility and tag filters that keep release channels in front of people.
A list somebody approved.
Environments and agents choose from the catalog, not from arbitrary registry strings — and versions are discovered from the registry, not typed.
Credentials stay out of the cluster.
Registry credentials are stored write-only, and every pull goes through the platform's image proxy — they never reach the cluster that runs the workload.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.