Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Container Registry
  • Service shutdown
  • Getting started
  • Yandex Container Solution
    • All tutorials
    • Migrating to Yandex Cloud Registry
    • Signing and verifying Docker images in Managed Service for Kubernetes
    • Scanning for vulnerabilities during continuous deployment of Managed Service for Kubernetes applications using GitLab
    • Continuous deployment of containerized applications using GitLab
    • Building a CI/CD pipeline in GitLab using serverless products
    • Storing Docker images created in Yandex Managed Service for GitLab projects
    • Connecting to Container Registry from VPC
    • Configuring a fault-tolerant architecture in Yandex Cloud
    • Running a containerized app in Yandex Serverless Containers
    • Deploying a gRPC service based on a Docker image
    • Deploying a service based on a Docker image in DataSphere
    • Deploying a service based on a Docker image with FastAPI in DataSphere
    • Setting up a Managed Service for PostgreSQL connection from Serverless Containers
    • Integration with Container Registry
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Troubleshooting
  • FAQ

In this article:

  • Getting started
  • Start migration
  • Managing redirects when launching migration
  • Check the migration status
  • Managing redirects after migration
  • Check Docker pull and push
  • If the migration terminated with an error
  1. Tutorials
  2. Migrating to Yandex Cloud Registry

Migrating from Container Registry to Cloud Registry

Written by
Yandex Cloud
Updated at October 9, 2026
View in Markdown
  • Getting started
  • Start migration
    • Managing redirects when launching migration
  • Check the migration status
  • Managing redirects after migration
  • Check Docker pull and push
  • If the migration terminated with an error

Warning

Starting October 13, 2026, Yandex Container Registry will be unavailable to new users.

The existing users can create resources until November 10, 2026. Afterwards, Yandex Container Registry will go read-only and cease to operate on December 14, 2026. For more information on how it will be handled, see this article on Yandex Container Registry sunset.

There are two ways to launch migration:

  • Across folder: You migrate all registries in the folder of your choice.
  • Across cloud: You migrate all registries in all folders of the cloud of your choice.

When you start migrating, it starts running in all registries in the folder or cloud concurrently. You can it launch it only for specific registries. If your folder or cloud houses any registries you do not need, make sure to delete them prior to running your migration.

Both registry IDs and Docker image addresses persist after migration, so you will not have to edit links to Docker images.

When migrating, the system will transfer all data and metadata from Container Registry to Cloud Registry, which includes:

  • Registry metadata.
  • Access permission settings, such as permissions to access a registry and repositories within it.
  • IP address access policies.
  • Lifecycle policies.
  • Scan settings.
  • Registry aliases.

Getting startedGetting started

  1. If you do not have the Yandex Cloud CLI yet, install and initialize it.

  2. Get the cloud or folder ID (depending on which type of migration you are running) and save it to a variable:

    • For folder migration, get the folder ID and save it to FOLDER_ID:

      export FOLDER_ID="<folder_ID>"
      
    • For cloud migration, get the cloud ID and save it to CLOUD_ID:

      export CLOUD_ID="<cloud_ID>"
      
  3. Assign the following roles for the cloud or folder (depending on which type of migration you are running):

    • cloud-registry.registries.migrationRunner: For the subject (user or service account) that will be launching migration. This role includes the permission to launch migration (cloud-registry.registries.startMigration) and view its status (cloud-registry.registries.getMigrationStatus).

      To assign this role, you must be the resource owner or admin.

    • cloud-registry.registries.migrationViewer: For subjects that only need to track the migration status.

    • container-registry.images.puller and container-registry.images.pusher: For subjects that will run test Docker pull and push. These roles do not grant access to Docker images.

    For more on how to assign roles, see Assigning a role.

Start migrationStart migration

You may want to use --async: this way, you will get the operation ID without needing to wait until it completes.

Folder migration
Cloud migration
yc cloud-registry v1 migration start-folder "$FOLDER_ID" \
  --profile <profile_name> \
  --async \
  --format json
yc cloud-registry v1 migration start-cloud "$CLOUD_ID" \
  --profile <profile_name> \
  --async \
  --format json

The id field that will be returned means the operation ID.

Warning

Before running this command again, check the current operation’s status.

To get the status, run the following command:

yc cloud-registry v1 operation get <operation_ID> --profile <profile_name>

If the operation is complete, the migration is also complete. To see how the data transfer is going, you can view the migration dashboard.

Managing redirects when launching migrationManaging redirects when launching migration

By default, launching registry migration triggers redirects, which means all requests to cr.yandex get redirected to Cloud Registry. This allows you to use the current address without changing anything in your infrastructure.

If this is not an option for you and you want to split your traffic, i.e., send requests to cr.yandex to Container Registry, and those to registry.yandexcloud.net, to Cloud Registry, launch migration using --disable-redirects:

Folder migration
Cloud migration
yc cloud-registry v1 migration start-folder "$FOLDER_ID" \
  --profile <profile_name> \
  --disable-redirects \
  --async \
  --format json
yc cloud-registry v1 migration start-cloud "$CLOUD_ID" \
  --profile <profile_name> \
  --disable-redirects \
  --async \
  --format json

When redirects are disabled, Container Registry and Cloud Registry work as two independent data copies. If you apply this configuration, make sure to update your links from cr.yandex to registry.yandexcloud.net.

You can also enable or disable redirects later on. For details, see Managing redirects after migration.

Check the migration statusCheck the migration status

View the migration dashboard to see the overall status, registry, repository, and tag count, and objects with errors and those currently being migrated.

To open this dashboard, run:

Folder migration
Cloud migration
yc cloud-registry v1 migration get-folder-migration-status-dashboard "$FOLDER_ID" \
  --profile <profile_name>
yc cloud-registry v1 migration get-cloud-migration-status-dashboard "$CLOUD_ID" \
  --profile <profile_name>

The status meanings are as follows:

Status Meaning
CREATED Object added to migration queue
SCHEDULED Object migration scheduled
IN_PROGRESS Data being transferred
COMPLETED Migration complete
FAILED Migration error

The migration is complete if:

  • The overall status is COMPLETED.
  • failed is 0 for registries, repositories, and tags.
  • completedis total.

Docker pull and push requests depend on the migration status:

  • CREATED: Docker pull requests go to Container Registry. Docker push requests may temporary end with the 429 Too Many Requests error and Retry-After header; in this case, just run your request again after the time specified.
  • SCHEDULED: all Docker pull and push requests are redirected to Cloud Registry.

Managing redirects after migrationManaging redirects after migration

You can also enable or disable redirects after migration, both for a specific registry, all registries in a folder, or in the cloud. For this, use --enabled:

  • true means the redirects are on, and the requests to cr.yandex go to Cloud Registry.
  • false means the redirects are off, and the requests to cr.yandex still go to Container Registry.
Registry
Folder
Cloud
yc cloud-registry v1 migration toggle-registry-redirects <registry_ID> \
  --profile <profile_name> \
  --enabled=<true_or_false>
yc cloud-registry v1 migration toggle-folder-redirects "$FOLDER_ID" \
  --profile <profile_name> \
  --enabled=<true_or_false>
yc cloud-registry v1 migration toggle-cloud-redirects "$CLOUD_ID" \
  --profile <profile_name> \
  --enabled=<true_or_false>

Check Docker pull and pushCheck Docker pull and push

If the redirects are:

  • On: You can use the same Container Registry address, i.e., cr.yandex.
  • Off: You need to use the Cloud Registry address, i.e., registry.yandexcloud.net.

Save the registry ID to REGISTRY_ID:

export REGISTRY_ID="<registry_ID>"

Save the repository name to REPOSITORY_NAME:

export REPOSITORY_NAME="<repository_name>"

Save the local Docker image name to LOCAL_IMAGE:

export LOCAL_IMAGE="<Docker_image_name>"

Save the Docker image tag to TAG:

export TAG="<tag>"

Check whether the Docker pull and push commands run correctly:

yc iam create-token --profile <profile_name> \
  | docker login --username iam --password-stdin cr.yandex

docker pull \
  "cr.yandex/$REGISTRY_ID/$REPOSITORY_NAME:$TAG"

docker tag "$LOCAL_IMAGE" \
  "cr.yandex/$REGISTRY_ID/migration-check:test"

docker push \
  "cr.yandex/$REGISTRY_ID/migration-check:test"

The hash of the image you downloaded should match the one before you launched migration. After running Docker push, the new tag should appear in Cloud Registry.

If the migration terminated with an errorIf the migration terminated with an error

If your migration failed, reach out to our support. In your ticket, include:

  • The ID of the cloud or folder you were running migration for.
  • Migration dashboard as JSON.
  • Error time and request ID, if you have one in the CLI output.

Was the article helpful?

Previous
All tutorials
Next
Overview
© 2026 Direct Cursus Technology L.L.C.