A Kubernetes controller that synchronizes container images from cluster workloads to external registries.
// readme
k8s-copycat
k8s-copycat watches the container images referenced by Kubernetes workloads and copies them into a registry you control. It keeps a mirror of your runtime dependencies in AWS ECR or another Docker-compatible registry, without changing your workloads.
Quick start · Configuration · Example configuration · Troubleshooting · Optional Kyverno use case
What does it do?
An upstream image can disappear, a tag can be deleted or changed, and a public registry can become unavailable, overloaded, or rate-limited. k8s-copycat provides an insurance policy: preserve the images your cluster uses while they are still available, so you have your own copy when you need it.
flowchart LR
W[Kubernetes workloads] -->|reference images in| U[Upstream registry]
W -->|observed by| C[k8s-copycat]
U -->|image manifests and layers| C
C -->|copies images| R[Your registry]
The controller watches Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, and Pods, including regular, init, and ephemeral…