3. NGC Private Registry User Guide#

This guide is for users and administrators of NVIDIA NGC Private Registry.

3.1. NGC Private Registry for Enterprise#

This guide describes how to use the NVIDIA® NGC Private Registry. It assumes that you are familiar with Linux and Docker and that you have access to an NVIDIA GPU-based computing solution. Examples include an NVIDIA DGX system or an NVIDIA-Certified system configured for internet access and prepared for running NVIDIA GPU-accelerated Docker containers.

As data scientists build custom content, storing, sharing, and versioning that intellectual property is critical to meeting business needs. NVIDIA NGC Private Registry provides a secure space to store and share custom containers, models, Jupyter notebooks, and Helm charts within your enterprise. The NGC Private Registry is available to DGX and NVIDIA AI Enterprise customers.

3.1.1. Increased Collaboration#

Teams often share work in tools such as Slack or Microsoft Teams. NGC Private Registry lets you share artificial intelligence (AI) content such as containers, models, and Helm charts within your organization. Stakeholders can reuse existing assets instead of recreating them.

3.1.2. Enterprise Ready#

When you share content across a large organization, you need to manage who can access it. User and team management in NGC Private Registry lets administrators control access to content stored in the registry.

Content stored in the NGC Private Registry remains available through redundant storage, and you can access it from any location.

3.2. Getting Started#

3.2.1. Obtaining a Private Registry#

This section describes how DGX customers obtain a private registry.

After you purchase a support entitlement with NVIDIA, you receive an NVIDIA Entitlement Certificate by email. The email includes the instructions to register for technical support.

The following is an example of the NVIDIA Entitlement Certificate email.

NVIDIA Entitlement Certificate email with registration instructions

The Entitlement Certificate itself is provided as a PDF attachment. The following is an example of an NVIDIA Entitlement Certificate.

Example NVIDIA Entitlement Certificate PDF

The PDF also includes instructions for using the certificate.

Registration instructions in the Entitlement Certificate PDF
  • If you already have an account, you can immediately log in to the NVIDIA Enterprise Support portal.

  • If you are a new user without an NGC Support account, click the NVIDIA Enterprise Support Registration Form link.

This link includes embedded information about your account. Do not share this entitlement link outside of your organization.

Registration provides an NGC private registry account and an NVIDIA Enterprise Support account. You receive a welcome email. After you receive the email, you can activate your NGC private registry account.

3.2.2. Activating a New NGC Account#

Before using NGC, you must have an NGC account created by your organization owner or other administrators in your organization. You need an email address to set up an account. Choose one of the following processes depending on your situation for activating your NGC account.

3.2.2.1. Joining an NGC Org or Team With an Existing NVIDIA Account#

This section describes joining an org or team when your email address is already associated with an NVIDIA account.

After NVIDIA or your organization administrator adds you to a new org or team within an organization, you receive a welcome email that invites you to continue the activation and sign-in process.

Welcome email inviting an existing NVIDIA account user to join an NGC org
  1. Click the Accept Invitation and Sign In link to open the NGC sign-in page.

    Enter your email address and sign in using your NVIDIA account credentials.

    NGC sign-in page for an existing NVIDIA account

    The Set Your Organization screen appears.

    Set Your Organization screen listing available orgs and teams
  2. Select the new organization and team you have been invited to. Click Continue.

    You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.

To view artifacts in your private registry, select Private Registry in the app menu in the top left. Then, you can create collections, containers, Helm charts, models, and resources, as needed.

App menu with Private Registry selected

3.2.2.2. Joining an Org or Team With a New NVIDIA Account#

This section describes activating a new account where the domain of your email address is not mapped to an organization’s single sign-on (SSO).

After your organization administrator invites you to an org or team, you receive a welcome email that invites you to continue the activation and sign-in process.

Welcome email inviting a new user to join an NGC org
  1. Click the Accept Invitation and Sign In link to open the NGC sign-in dialog in your browser, or go to the NGC sign-in page.

    NGC sign-in page for a new user
  2. Enter your email address and click Continue. NGC prompts you to create a new NVIDIA account.

    Create an NVIDIA account form for a new user
  3. Fill in your information, create a password, agree to the Terms and Conditions, and click Create Account. An email is sent to you to verify your email address.

  4. Open the email and click Verify Email Address.

    Email verification message with Verify Email Address link
  5. In the Almost done! dialog, select your communication preferences and then click Submit.

  6. In the NVIDIA Account Terms of Use dialog, select the desired options and click Agree.

    NVIDIA Account Terms of Use dialog
  7. Select the organization and team you want to log in under and then click Continue.

    Set Your Organization screen listing available orgs and teams

You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.

To view artifacts in your private registry, select Private Registry from the app menu in the top left. Then, you can create collections, containers, Helm charts, models, and resources, as needed.

App menu with Private Registry selected

3.2.2.3. Joining an Org as Org Owner#

This section describes activating a new NGC org where you are joining as the org owner.

After NVIDIA sets up your NGC org, you receive a welcome email that invites you to continue the activation and sign-in process.

Welcome email for a new NGC org owner

In the example, “Novi Sciences” is the owner of the newly created organization. The following steps assume Novi is new to NGC and explain how to create a new NVIDIA account and sign in as org owner. If you already have an NVIDIA account managing other NGC orgs as org owner, click Use alternate method to sign in with your existing NVIDIA account and access your new org.

Take note of the following important information in the email.

  • “TB3-org” is the display name for your org. The display name identifies your org in the NGC web UI.

  • “njdfzzqagzno” is the unique identifier for your org. This identifier represents your org namespace. You can use this identifier in some CLI commands.

  1. Click Sign in to NGC, or using a browser, navigate to the NGC sign-in page.

    Enter your email address and click Continue.

    NGC sign-in page for a new org owner
  2. The create account screen appears. Verify your email and create a password. Review the NVIDIA Account Terms of Use and Privacy Policy, and click Create Account.

    Create account screen for a new org owner

    A verification email is sent.

  3. Open the email and click Verify Email Address.

    Email verification message for a new org owner
  4. In the Almost done! dialog, select your communication preferences and then click Submit.

    Almost done dialog for communication preferences
  5. In the NVIDIA Account Terms of Use dialog, select the desired options and click Agree.

    NVIDIA Account Terms of Use dialog
  6. Select the organization and team you want to log in under and then click Continue.

    Set Your Organization screen listing available orgs and teams

    You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.

3.2.2.4. Joining an Org or Team With an External SSO Company Account#

This section describes joining an org or team that your company has federated to an external SSO or identity provider (IdP) authentication service. Your email address domain requires NGC authentication against your company’s SSO.

After your organization administrator adds you to a new org or team within the organization, you receive a welcome email that invites you to continue the activation and sign-in process.

Welcome email inviting a user with company SSO to join an NGC org
  1. Click the Accept Invitation and Sign In link to open the NGC sign-in page. Enter your email address and click Continue.

    NGC sign-in page for a company SSO user

    If your email address domain is associated with an external SSO identity provider, NGC redirects you and prompts you to authenticate with that method.

    For example:

    External SSO identity provider sign-in page

    After you authenticate, NGC redirects you to the NGC website.

    If you are a member of more than one NGC org, the Set Your Organization screen appears.

    Set Your Organization screen after SSO authentication
  2. Select the new organization and team you have been invited to and click Continue.

    You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.

    The NGC web UI opens to the NGC Catalog landing page.

To view artifacts in your private registry, select Private Registry from the app menu in the top left. Then you can create collections, containers, Helm charts, models, and resources, as needed.

App menu with Private Registry selected

3.2.2.5. Switching Orgs or Teams After Logging into NGC#

This section describes switching to a different org or team after logging in.

In the top menu bar, click your user account icon. Then, select your org menu to expand the view to other available orgs. If you manage many orgs, you can use the search field to find the specific org you want to select. Click the org that you want to select.

User account menu for switching the current NGC org or team

Depending on the org or team you select, your current page can also refresh.

3.2.3. NGC API Keys#

NVIDIA NGC API keys are required to authenticate with NGC services using NGC CLI, Docker CLI, or direct API requests.

NGC provides two types of API keys:

Personal Keys

  • Any NGC org user can generate a personal key.

  • An NGC org user can grant a personal key up to the permissions assigned to them in the NGC org.

  • A personal key is linked to the user’s NGC org lifecycle.

    • If the user’s permissions change, the available permissions that can be or are assigned to the personal key also change.

    • If the user is removed from the NGC org, the key’s validity is revoked.

  • Supports updating permissions, rotation, and deletion (immediate revocation).

    • Org owners and user_admins can revoke any member’s key on demand.

  • Each user can generate up to eight personal keys.

Use personal keys to begin using NGC services within your sandbox. Personal keys are suited to individuals working on early development and testing code before moving to pre-production and production releases.

To authorize the services you have access to in the org and generate a personal key, go to Generating a Personal API Key.

Important

Use the legacy NGC API Key to authenticate with Base Command Platform, Fleet Command, or other NGC services that do not support “Personal key” authentication. For cross-org authorization, continue using the legacy NGC API Key. NVIDIA plans to deprecate the legacy NGC API key after 2025. NVIDIA encourages you to use the Personal Key, but if you need to continue using the legacy API key, go to Generating a Legacy NGC API Key to find out where to create a new one. Also, your current NGC API key will continue to work.

Service Keys

  • The lifecycle of service keys is linked to the NGC org account, not associated with an individual user.

  • Only NGC org owners and user_admins can manage service keys.

  • A service key can be scoped to access only the permissions and services required, or full access to the services enabled in the org.

  • Supports scoped permissions, updating permissions, on-demand revocation, rotation, and deletion.

  • An NGC org can have up to 64 service keys.

Use service keys when you require automated communication between machines and deploying to pre-production and production environments where you do not want to depend on a user’s membership status in the NGC org.

Note

Service keys currently do not support listing artifacts in NGC CLI or Docker CLI. This functionality will be added in the future. In the meantime, use a Personal API key to list artifacts.

Examples using NGC API Keys

Here are some examples of using NGC API keys to authenticate with NGC CLI and Docker CLI:

NGC CLI

$ ngc config set

Paste your key value at the API_KEY prompt:

[Enter API key [****API-Key]. Choices: [<VALID_APIKEY>]

Important

Always use the latest NGC CLI version to access the newest features, bug fixes, performance improvements, and security updates. Check for the latest versions at NGC CLI Installers or run ngc version list to view the latest releases, then upgrade using

ngc version upgrade

Docker CLI

docker login nvcr.io --username '$oauthtoken'

For the username, enter '$oauthtoken' exactly as shown. It is a special name that indicates that you authenticate with an API key. Paste your key value at the Password prompt.

3.2.3.1. Supported NGC Applications and API Key Types#

The following NVIDIA NGC applications and services support Personal and Service Keys.

NGC Applications and Services#

NGC Application/Services

Service Description

NVIDIA NGC Catalog

Grants your key permission to access or download containers and artifacts from the NGC Catalog. The permission level matches your account’s permissions for the catalog.

NVIDIA NGC Private Registry

The key is authorized to perform actions on your organization’s private registry service, such as pulling, retrieving, creating, or deleting containers and artifacts. The permission level assigned to the key matches the permission level of your user account. Therefore, your user account must have permissions for the Private Registry.

NVIDIA Cloud Functions

This authorization allows your key to perform actions on your organization’s cloud functions service. If your organization has private functions published by NVIDIA, or if your cloud functions service enables you to create, deploy, and run your own functions, your personal key has the same permissions as your user account for the cloud functions service. Therefore, it is important that your user account has the necessary permissions for Cloud Functions.

NVIDIA Public API Endpoints

Grants permission for your key to access NVIDIA NIM inference endpoints listed in the NVIDIA API Catalog. Therefore, your user account must have Public API Endpoints permissions.

NVIDIA Secrets Manager

Authorizes your key to perform actions on the NVIDIA Secrets Manager service, which is used to store and manage secrets. Your key has the same permission level as your user account, so your user account must possess Secrets Manager permissions.

3.2.3.2. Generating NGC API Keys#

Generating API keys is essential for authenticating with NGC services using the NGC CLI, Docker CLI, or direct API requests.

3.2.3.2.1. Generating a Personal API Key#
  1. Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.

  2. Click your user account icon in the top-right corner and select Setup.

    User profile menu setup
  3. Click Generate API Key from the available options.

    Generate API key option
  4. On the Setup > API Keys page, click + Generate Personal Key on the menu or the pane.

    API key generate page
  5. In the Generate Personal Key dialog, fill in the required information for your key.

    Generate personal key dialog
    • Key Name: Enter a unique name for your key.

    • Expiration: Choose the expiration date for the key.

      API key expiration options
    • Services Included: Choose from the available services the key is permitted to access. Refer to Assigning Services to Your Personal API Key to learn more about each service and when to assign service access to your Personal Key.

  6. Click Generate Personal Key when finished.

    Your API key appears in the following dialog.

  7. NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by selecting Copy Personal Key or using the copy icon to the right of the API key.

    API key confirmation dialog

    You can generate up to eight personal keys and manage them from the Setup > Personal Keys dashboard. To activate or deactivate a key, click the Active toggle. The Actions (ellipsis) menu allows you to rotate or delete a personal key.

    Personal keys dashboard
3.2.3.2.1.1. Assigning Services to Your Personal API Key#

The services you can assign to a personal API key depend on two factors:

  • The services enabled for the NGC org where you generate the API key.

  • The service roles assigned to you by your NGC org owner or administrator.

For example, consider an NGC org with the following services enabled:

NGC org subscriptions

An NGC user account might have the following access roles assigned:

NGC user account example

In this scenario, the NGC org has enabled NVIDIA Microservices, Private Registry, NVIDIA AI Enterprise, and Cloud Functions (NVCF). The user account has been granted access roles for all these services. Therefore, a personal API key can be generated with permissions to access one or all of them.

Generate personal key dialog with services

If a service is unavailable for assignment to the API key, the org owner or administrator has not granted you the necessary role for that service.

For details about each service listed above and its function, refer to the table Supported NGC Applications and API Key Types.

3.2.3.2.1.2. Generating a Legacy NGC API Key#

To generate a legacy API key, go to Setup > API Keys and click + Generate Legacy Key in the Legacy Keys drop-down.

Legacy key option

In the Generate Legacy Key dialog, click + Generate Legacy Key.

Generate legacy key dialog
3.2.3.2.2. Generating a Service API Key#
  1. Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.

  2. Select Organization from the user account menu on the upper right.

    User account menu organization

    Select Service Keys on the organization dashboard.

    Organization dashboard service keys
  3. On the Organization > Service Keys page, click + Create Service Key to create a key.

    Create service key page
  4. In the Create Service Key dialog, fill in the required configuration. Service keys currently support services such as NVIDIA NIM, NGC Catalog, and Private Registry. Assign scopes and resource permissions to the key.

    Create service key form

    In the Entity Type field, select from the available options to grant to the API key.

    Service key entity type options

    In the Scope field, choose from the available options.

    Service key scope options
  5. Click Next Step to review your key configuration.

    Service key form next step
  6. After you verify the configuration, click Confirm to generate your service key. Your service key appears in the next dialog.

    Service key confirmation
  7. NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by clicking the copy icon to the right of the API key or the Copy Service Key button.

    Copy service key

    Copy the key value before leaving this page. After you navigate away, the key value cannot be retrieved, and you must generate a new key to replace it. NGC supports multiple Service API keys, which are managed from the Organization > Service Keys dashboard.

    To activate or deactivate a key, click the Active toggle. The Actions (ellipsis) menu allows you to rotate or delete a service key.

    Service keys dashboard

Note

When managing containers, ensure the scopes Get Container and Get Container list are assigned to your service key. For other types of artifacts, add the Get Artifact and Get Artifact list scopes. These scopes are the minimum required to discover the artifacts that need to be managed. Refer to the NGC Catalog User Guide and Private Registry User Guide for more information.

3.2.4. Managing Users and Teams in NGC#

This section applies to organization and team administrators, and explains the tasks that an organization or team administrator can perform from the NGC website.

When NVIDIA created the organization, it assigned an organization owner from the primary technical contact information provided during the sales process. This organization owner receives an email from NGC. As the NGC org owner for your organization, you can invite other users to join your organization’s NGC account. You can then assign users as members of teams within your organization. Teams are useful for keeping custom work private within the organization. You can also create other administrators in the organization to share that responsibility.

The general workflow for building teams of users is as follows:

  1. The organization admin invites users to the organization’s NGC account.

  2. The organization admin creates teams within the organization.

  3. The organization admin adds users to appropriate teams, and typically assigns at least one user to be the team admin.

  4. The organization or team admin can then add other users to the team.

3.2.4.1. NGC Registry User Roles#

Before adding users and teams, familiarize yourself with the following definitions of each role.

The NGC container registry supports the following user roles.

Organizational and Team Level Roles

The following roles can be assigned to a user.

  • Org Owner: This user is created at the time of Org creation. Up to two users can be assigned the Org Owner role at a given moment. This user can download, upload, push, pull, or delete artifacts, add or remove users, and create teams within an organization.

  • Registry Admin: This user can download, upload, push, pull, or delete artifacts within an organization or team.

  • Registry User: This user can download, upload, push, and pull artifacts within an organization or team.

  • Registry Read: This user can download and pull artifacts within an organization or team.

  • User Admin: This user can view and invite other users and user admins within an organization. At the team level, the User Admin can view and invite other users and user admins to that team. A User Admin can only grant roles that they possess.

  • User Read: This user can view details of an organization or team.

Note

A user must have a Registry Read, Registry User, or User Admin role to be a member of the organization or any team.

User Role Capabilities#

Capability

Registry Admin

Registry User

User Admin

Registry Read

User Read

Add teams

X

X

✔

X

X

Add new users to orgs or teams

X

X

✔

X

X

View users

✔

X

✔

X

X

Delete images

✔

X

X

X

X

View or edit all image information using the UI and CLI

✔

✔

X

X

X

View all artifacts, namely containers, models, and resources

✔

✔

✔

✔

X

Download all artifacts, namely containers, models, and resources

✔

✔

X

✔

X

Create and push or upload all artifacts, namely containers, models, and resources

✔

✔

X

X

X

3.2.4.2. Creating Teams#

Creating teams is useful for allowing users to share images within a team while keeping them invisible to other teams in the same organization. Only organization administrators can create teams.

To create a team:

  1. Sign in to the NGC application.

  2. Select Organization from the user account menu. From the dashboard or left navigation, select Teams. Then, click Create Team at the top of the screen.

    NGC create team
  3. Enter a team name and description, then click Create Team. Team names must be all lowercase.

3.2.4.3. Creating Users#

As the organization owner or user administrator, you must create user accounts to allow others to use the NGC container registry within the organization.

  1. Sign in to the NGC application.

  2. Click Organization from the user account menu. From the dashboard or left navigation, select Users. Then, click Invite User at the top right of the screen.

    NGC users invite
  3. Fill out the Invite New User form for the new user as follows:

    NGC new user form
    • Enter the display name and email where indicated.

    • Select the organization or team to be assigned.

    • Select the roles to assign to the user.

    • Click Add Role and then click Invite User when done.

    An invitation email is automatically sent to the user.

3.2.4.4. Adding a New User to a Team#

Org owners or org-level user administrators can add users to any team in the organization. Team user administrators can add users to their teams.

  1. Sign in to the NGC application.

  2. Click Organization from the user account menu. Select Teams from the left navigation, and then select the team that you want to add a user to.

  3. On the Users page, click Invite New User.

    NGC add user
  4. In the Invite New User dialog, follow the steps in section Creating Users to fill out the add user form and invite the new user to the team. Confirm that the user is invited at the desired team context.

    Users can be members of more than one team. To add a user to another team, repeat these steps for any additional teams.

3.2.4.5. Adding an Existing User to a Team#

Org owners or org-level user administrators can add users to any team in the organization. Team user administrators can add users to their teams.

  1. Sign in to the NGC application.

  2. Click Organization from the user account menu. From the dashboard or the left navigation, select Teams. Then, select the team that you want to add a user to.

  3. On the Users page, click Add Existing User.

    NGC add existing user
  4. In the Find Existing User dialog, enter the name of the user you want to add.

    NGC find existing user
  5. Select the user and click Edit User.

  6. On the user information page, assign the user to the desired team and roles. Click Add Role to save your changes.

    NGC update user

Users can be members of more than one team. To add a user to another team, repeat these steps for any additional teams.

3.2.4.6. Changing User Roles#

You can change user assignments and roles for any users you create.

  1. Sign in to the NGC application.

  2. Select the org and team for which you want to change the user role. Click your user icon to select from the list of orgs, select an org, and if applicable, select a team.

  3. Click Organization from the user account menu. Select Users from the left navigation. A list of all the users in the current registry space appears.

  4. Select the user whose role you want to change. The User Information form appears.

  5. Click Edit Membership.

    NGC edit membership

    A prompt appears for editing membership roles.

  6. You can assign new roles, update and delete user roles, and click Add Role when done.

3.2.5. Introduction to the NGC Catalog and NGC CLIs#

Unified NGC and Enterprise Catalog

Note

The Enterprise Catalog, formerly a separate repository for NVIDIA AI Enterprise-supported software, is now integrated into the public NGC Catalog. NVIDIA AI Enterprise customers can access their exclusive software and features within the NGC Catalog using their active entitlements.

The NGC Catalog provides a centralized catalog of publicly available entities (for example, containers, models, and resources) alongside those that are part of products called entitled entities. You can search and filter across all entities.

You can view and download entitled entities by signing in to NGC. You can also download software with the NGC CLI using an API key. Access to all granted products remains when you switch org or team context. Unauthenticated users are prompted to log in or gain access to the product when they attempt to download gated features or entitled entities.

Publishers can publish and map entities to products. Access to entities is restricted by entity type, entity access type, user subscriptions, and roles. For entitled entities, guest users can convert to registered or subscribed status to access product-specific entities.

Introduction to NGC CLIs

The NGC CLIs are command-line interfaces for managing content within the NGC Registry. The CLI operates within a shell and lets you use scripts to automate commands.

NGC Catalog CLI

The NGC Catalog CLI is available to you if you have guest access to the NGC Registry, and with it, you can:

  • View a list of GPU-accelerated Docker container images, pretrained deep-learning models, and scripts for creating deep-learning models.

  • Download container images, models, and resources.

NGC Registry CLI

The NGC Registry CLI is available to you if you are logged in with your own NGC account or with an NGC Private Registry account, and with it, you can:

  • View a list of GPU-accelerated Docker containers available and detailed information about each image.

  • View a list of deep-learning models and resources and detailed information about them.

  • Download container images, models, and resources.

  • Upload container images, models, and resources.

  • Create and manage users and teams (available to NGC Private Registry administrators).

For more details and best practices, refer to the NGC CLI documentation page.

3.2.5.1. Installing NGC Registry CLI#

To install NGC Registry CLI:

  1. Log in to your enterprise account on the NGC website.

  2. In the top right corner, click your user account icon and select Setup, then click Downloads under CLI from the Setup page.

  3. From the CLI Install page, click the Windows, Linux, or macOS tab, according to the platform from which you run NGC Registry CLI.

  4. Follow the instructions to install the CLI.

  5. Verify the installation by entering ngc --version. The output should be NGC CLI x.y.z where x.y.z indicates the version.

3.2.5.2. Managing Users and Teams#

This section applies to the organization and team administrators.

As the NGC administrator for your organization, you can invite other users to join your organization’s NGC account. You can then assign users as members of teams within your organization. Teams are useful for keeping custom work private within the organization.

The general workflow for building teams of users is as follows:

  1. The organization admin invites users to the organization’s NGC account.

  2. The organization admin creates teams within the organization.

  3. The organization admin adds users to appropriate teams, and typically assigns at least one user to be the team admin.

  4. The organization or team admin can then add other users to the team.

3.2.5.2.1. Inviting Users to the Organization’s NGC Account#

Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)

Syntax

C:\> ngc org add-user <email> <name>

Example of adding John Smith (email: jsmith@example.com)

C:\> ngc org add-user jsmith@example.com "John Smith"
3.2.5.2.2. Creating Teams#

Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)

Syntax

C:\> ngc org add-team <name> <description>

Example of adding Team A

C:\> ngc org add-team team_a "Team A"
Team created.
----------------------------------------------------
 Team Information
 Id: 363
 Name: team-a
 Description: Team A
 Deleted: False
----------------------------------------------------
3.2.5.2.3. Adding Users to Teams#

Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE) or Team Admin (REGISTRY_WRITE_TEAM_ADMIN_ROLE)

Syntax

C:\> ngc team add-user <email> <name>

Example of adding existing user John Smith to Team A as a regular user

C:\> ngc team add-user jsmith@example.com "John Smith" --team team-a --role REGISTRY_WRITE_USER_ROLE

Note

You do not need the --team argument if the target team is already set in your current NGC configuration.

3.2.5.2.4. Creating a Team and Adding a User in the Same Command#

Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)

Syntax

C:\> ngc org add-user <email> <name> --team <name> --role <user-role>

Example of inviting new user John Smith to Team A as a team admin

C:\> ngc org add-user jsmith@example.com "John Smith" --team team-a --role REGISTRY_WRITE_TEAM_ADMIN_ROLE

Note

You do not need the --team argument if the target team is already set in your current NGC configuration.

3.2.5.2.4.1. User Roles and Permissions#
User Roles and Permissions#

Role

Service

Access Levels

ADMIN

ACE

READ, ADMIN, WRITE

ADMIN

CONTAINER

READ, ADMIN, WRITE

ADMIN

DATASET

READ, ADMIN, WRITE

ADMIN

HELM

READ, ADMIN, WRITE

ADMIN

JOB

READ, ADMIN, WRITE

ADMIN

MODEL

READ, ADMIN, WRITE

ADMIN

MODELSCRIPT

READ, ADMIN, WRITE

ADMIN

ORG

READ, ADMIN, WRITE

ADMIN

TEAM

READ, ADMIN, WRITE

ADMIN

USER

READ, ADMIN, WRITE

ADMIN

WORKSPACE

READ, ADMIN, WRITE

EGX_ADMIN

EGX

READ, ADMIN, WRITE

EGX_ADMIN

ORG

READ, ADMIN, WRITE

EGX_ADMIN

TEAM

READ, ADMIN, WRITE

EGX_ADMIN

USER

READ, ADMIN, WRITE

EGX_READ

EGX

READ

EGX_READ

ORG

READ

EGX_READ

TEAM

READ

EGX_USER

EGX

READ, WRITE

EGX_USER

ORG

READ, WRITE

EGX_USER

TEAM

READ, WRITE

REGISTRY_READ

CONTAINER

READ

REGISTRY_READ

HELM

READ

REGISTRY_READ

MODEL

READ

REGISTRY_READ

MODELSCRIPT

READ

REGISTRY_READ

ORG

READ

REGISTRY_READ

TEAM

READ

REGISTRY_ADMIN

CONTAINER

READ, ADMIN, WRITE

REGISTRY_ADMIN

HELM

READ, ADMIN, WRITE

REGISTRY_ADMIN

MODEL

READ, ADMIN, WRITE

REGISTRY_ADMIN

MODELSCRIPT

READ, ADMIN, WRITE

REGISTRY_ADMIN

ORG

READ, ADMIN, WRITE

REGISTRY_ADMIN

TEAM

READ, ADMIN, WRITE

REGISTRY_ADMIN

USER

READ, ADMIN, WRITE

REGISTRY_USER

CONTAINER

READ, WRITE

REGISTRY_USER

HELM

READ, WRITE

REGISTRY_USER

MODEL

READ, WRITE

REGISTRY_USER

MODELSCRIPT

READ, WRITE

REGISTRY_USER

ORG

READ, WRITE

REGISTRY_USER

TEAM

READ, WRITE

USER_ADMIN

CONTAINER

READ, ADMIN, WRITE

USER_ADMIN

HELM

READ, ADMIN, WRITE

USER_ADMIN

MODEL

READ, ADMIN, WRITE

USER_ADMIN

MODELSCRIPT

READ, ADMIN, WRITE

USER_ADMIN

ORG

READ, ADMIN, WRITE

USER_ADMIN

TEAM

READ, ADMIN, WRITE

USER_ADMIN

USER

READ, ADMIN, WRITE

USER

ACE

READ, WRITE

USER

CONTAINER

READ, WRITE

USER

DATASET

READ, WRITE

USER

HELM

READ, WRITE

USER

JOB

READ, WRITE

USER

MODEL

READ, WRITE

USER

MODELSCRIPT

READ, WRITE

USER

ORG

READ, WRITE

USER

TEAM

READ, WRITE

USER

WORKSPACE

READ, WRITE

3.3. Docker Containers#

Software containers simplify deployment of data center applications at scale. Containers encapsulate an application along with its libraries and other dependencies to provide reproducible and reliable execution of applications and services without the overhead of a full virtual machine.

GPU support within Docker containers enables GPU-based applications that are portable across multiple machines, similar to how Docker® enables CPU-based applications to be deployed across multiple machines.

  • Docker container: A Docker container is an instance of a Docker image. A Docker container deploys a single application or service per container.

  • Docker image: A Docker image is the software (including the filesystem and parameters) that you run within an NVIDIA Docker container.

3.3.1. What Is A Docker Container?#

A Docker container bundles a Linux application with all of its libraries, data files, and environment variables so that the execution environment is always the same. The environment stays the same on whatever Linux system it runs and between instances on the same host.

Unlike a VM, which has its own isolated kernel, containers use the host system kernel. Therefore, all kernel calls from the container are handled by the host system kernel. DGX™ systems use Docker containers as the mechanism for deploying deep learning frameworks.

A Docker container is the running instance of a Docker image.

3.3.2. Why Use A Container?#

You can install your application, dependencies, and environment variables one time into the container image, rather than on each system you run on. Key benefits of using containers also include:

  • There is no risk of conflict with libraries that are installed by others.

  • Containers allow use of multiple different deep learning frameworks, which can have conflicting software dependencies, on the same server.

  • After you build your application into a container, you can run it on other systems, especially servers, without having to install any software.

  • Legacy accelerated compute applications can be containerized and deployed on newer systems, on premises, or in the cloud.

  • Specific GPU resources can be allocated to a container for isolation and better performance.

  • You can share, collaborate, and test applications across different environments.

  • Multiple instances of a given deep learning framework can be run concurrently with each having one or more specific GPUs assigned.

  • Containers can resolve network-port conflicts between applications by mapping container-ports to specific externally-visible ports when launching the container.

3.3.3. Using NGC Container Registry from the Docker Command Line#

3.3.3.1. Accessing the NGC Container Registry#

You can access the NGC container registry by running a Docker command from your client computer. You are not limited to using your NVIDIA DGX platform to access the NGC container registry. You can use any Linux computer with internet access on which Docker is installed.

Before accessing the NGC container registry, ensure that the following prerequisites are met:

  • Your NGC account is activated.

  • You have an NGC API key for authenticating your access to NGC container registry. For more information, refer to Generating NGC API Keys.

  • You are logged in to your client computer as an administrator user.

An alternate approach for enabling other users to run containers without giving them sudo privilege, and without having to type sudo before each docker command, is to add each user to the docker group, with the command:

sudo usermod -aG docker $USER

Note

While this approach is more convenient and commonly used, it is less secure because any user who can send commands to the docker engine can escalate privilege and run root level operations. If you choose to use this method, only add users to the docker group who you would trust with root privileges.

  1. Log in to the NGC container registry.

    docker login nvcr.io
    
  2. When prompted for your username, enter the following text:

    $oauthtoken
    

    The $oauthtoken username is a special username that indicates that you authenticate with an API key and not a username and password.

  3. When prompted for your password, enter your NGC API key as shown in the following example.

    Username: $oauthtoken
    Password: my-api-key
    

Tip

When you get your API key (refer to Generating NGC API Keys), copy it to the clipboard so that you can paste the API key into the command shell when you are prompted for your password.

Note

The three steps above can be combined into a single command for convenience:

docker login -u \$oauthtoken -p $NGC_API_KEY nvcr.io

3.3.3.2. Uploading an NVIDIA Container Image onto Your System#

No container images are preloaded onto a DGX system. Instead, containers are available for download from the NGC container registry. NVIDIA has provided a number of containers for download from the NGC container registry. If your organization has provided you with access to any custom containers, you can download those as well.

Before loading an NGC container image, ensure that the following prerequisites are met:

Tip

To browse the available containers in the NGC container registry, use a web browser to log in to your NGC account on the NGC website.

  1. Run the command to download the container that you want from the registry.

    sudo docker pull registry/registry-space/repository:tag
    
    • registry: The URL of the container registry, which for the NGC container registry is nvcr.io.

    • registry-space: The name of the space within the registry that contains the container. For example, nvidia is the registry space for containers provided by NVIDIA.

    • repository: Repositories are collections of containers of the same name, but distinguished from each other by their tags. This value is the main container name.

    • tag: A tag that identifies the version of the container.

  2. To confirm that the container was downloaded, list the Docker images on your system.

    sudo docker images
    

The following are several examples of pulling container images.

  • Example of pulling tensorflow:18.06-py3 from the nvidia registry space.

~$ sudo docker pull nvcr.io/nvidia/tensorflow:18.06-py3
  • Example of pulling a custom container image tagged v2.0 from the acme organization registry space.

~$ sudo docker pull nvcr.io/acme/custom-image:v2.0
  • Example of pulling a custom container image tagged v2.0 from the acme/team team registry space.

~$ sudo docker pull nvcr.io/acme/zoom/custom-image:v2.0

3.3.3.3. Tagging and Pushing a Container Image#

You can upload custom images to the registry if you have write access to the registry space. Uploading a container image involves first tagging the image and then pushing the image to the registry space.

In the following examples, you are a member of the Acme (mxa8oi8djw7m) organization and the Zoom team within the Acme organization. Refer to Joining an Org as Org Owner for how to find your org name.

  • Tagging Example

    This example tags a local container image mycaffe in the mxa8oi8djw7m/zoom team space with v1.5.

    ~$ sudo docker tag mycaffe nvcr.io/mxa8oi8djw7m/zoom/mycaffe:v1.5
    
  • Pushing Example

    This example pushes version v1.5 of the mycaffe local container image to the mxa8oi8djw7m/zoom team space:

    ~$ sudo docker push nvcr.io/mxa8oi8djw7m/zoom/mycaffe:v1.5
    

3.3.4. Using the Container Registry#

The ngc registry image commands let you access ready-to-use GPU-accelerated container images from the registry.

3.3.4.1. Viewing Container Image Information#

There are several commands for viewing information about available container images.

To list container images:

C:\>ngc registry image list
+-------------+-------------+-------------+------------+---------+------------+
| Name        | Repository  | Latest Tag  | Image Size | Updated | Permission |
|             |             |             |            | Date    |            |
+-------------+-------------+-------------+------------+---------+------------+
| BigDFT      | hpc/bigdft  | cuda10-ubun | 2.37 GB    | Oct 18, | unlocked   |
|             |             | tu1804-ompi |            | 2019    |            |
|             |             | 4-mkl       |            |         |            |
| CANDLE      | hpc/candle  | 20180326    | 1.52 GB    | Oct 18, | unlocked   |
|             |             |             |            | 2019    |            |
...

“Unlocked” permissions indicate images that do not require an API key to access.

To view detailed information about a specific image, specify the image and the tag.

Example:

C:\>ngc registry image info nvidia/caffe:19.02-py2
--------------------------------------------------
 Image Information
 Name: nvidia/caffe:19.02-py2
 Architecture: amd64
 Schema Version: 1
--------------------------------------------------

3.3.4.2. Pulling a Container Image#

With the NGC Registry CLI you can pull (download) images to your system.

To pull an image to your registry space, specify the image and, optionally, the tag.

C:\>ngc registry image pull <image-name>[:<tag>]

If a tag is not specified, then the tag latest is used.

3.3.4.3. Pushing a Container Image#

With the NGC Registry CLI you can push (upload) images to your registry space.

To push an image to your registry space, specify the image and, optionally, the tag.

C:\>ngc registry image push <image-name>[:<tag>]

If a tag is not specified, then the tag latest is used.

3.3.4.4. Removing a Container Image#

With the NGC Registry CLI you can remove images that are no longer needed from your registry space.

To remove all versions of an image, specify the image.

C:\>ngc registry image remove <image-name>

To remove a specific image version, specify the image and tag.

C:\>ngc registry image remove <image-name>:<tag>

3.3.5. Updating Container Metadata#

You can find best practices on how to fill out the metadata for your container in the Product Page Guidelines.

3.3.5.1. Updating Container Metadata Via the NGC Website#

Use the following steps to update the container metadata using the NGC website.

  1. Click the vertical ellipsis in the upper-right corner of your container product page to reveal the entity action menu.

    Container product page entity action menu
  2. Select Edit Details from the entity action menu.

  3. Update the container description and all other container metadata as needed.

  4. To save your changes, click the vertical ellipsis again to reveal the entity action menu and select Save.

3.3.5.2. Updating Container Metadata Using the NGC CLI#

With the NGC Registry CLI you can update the container description and all the other container metadata.

To update container metadata, use the following command.

ngc registry image update [--ace <name>] [--built-by <name>] [--debug]
                          [--desc <desc>] [--format_type <fmt>]
                          [--label <label>] [--logo <url>] [--org <name>]
                          [--overview <file.md>] [--publisher <publisher>]
                          [--team <name>] [-h]
                          <image>[:<tag>]

Specify a named argument (field to update, and values to update the field) as well as a positional argument (name of the container image and, optionally, tag).

Positional Arguments

  • <image>[:<tag>]: Name of the image repository or tagged image, <image>[:<tag>]

Named Arguments

  • --debug: Enable debug mode.

  • --format_type: Possible choices: ascii, csv, json. Specify the output format type. Supported formats are: [‘ascii’, ‘csv’, ‘json’]. Only commands that produce tabular data support csv format. Default: ascii.

  • --org: Specify the organization name. Use “–org no-org” to override other sources and specify no org. Default: current configuration.

  • --ace: Specify the ACE name. Use “–ace no-ace” to override other sources and specify no ACE. Default: current configuration.

  • --team: Specify the team name. Use “–team no-team” to override other sources and specify no team. Default: current configuration.

  • --desc: Description for the target image.

  • --overview: Documentation (text or markdown file) for the image.

  • --label: A label to describe the repository. Can be used multiple times.

  • --logo: A URL pointing to the logo for the repository.

  • --publisher: The person or entity publishing the image.

  • --built-by: The person who built the container image. Specify the image and, optionally, the tag.

Example: Changing Description of a Container Image

To view the existing container metadata use the following command.

$ ngc registry image info nvidia/testcontainer
--------------------------------------------------
 Image Repository Information
   Name: testcontainer
   Short Description: Test description.
   Built By: Kristina
   Publisher: NVIDIA
   Logo: www.logo.com/logo.png
     Labels: Machine Learning, Classification, Retail
   Public: No
   Last Updated: May 8, 2020
   Latest Image Size: 60.27 MB
   Latest Tag: 3.0
   Tags:
         3.0
       2.0
       1.0
--------------------------------------------------

Update the container description with the following command.

$ ngc registry image update --desc "A test container image with useful tools." nvidia/testcontainer
--------------------------------------------------
Updating repository metadata
Repository metadata updated.

To confirm that the update succeeded, run the info command again.

$ ngc registry image info nvidia/testcontainer
--------------------------------------------------
 Image Repository Information
   Name: testcontainer
   Short Description: A test container image with useful tools.
   Built By: Kristina
   Publisher: NVIDIA
   Logo: www.logo.com/logo.png
     Labels: Machine Learning, Classification, Retail
   Public: No
   Last Updated: May 8, 2020
   Latest Image Size: 60.27 MB
   Latest Tag: 3.0
   Tags:
         3.0
       2.0
       1.0
--------------------------------------------------

$ ngc registry image update Command Overview

3.3.6. Multi-Architecture Support for NGC Container Images#

When running an image, Docker automatically selects an image variant that matches your OS and architecture.

NGC Container Registry supports Docker multi-architecture images. A single image can contain variants for different architectures, such as ARM, x86, Power, and others, and sometimes for different operating systems, such as Windows.

Manifest Lists and Tags

NGC Container Registry supports the manifest list schema application/vnd.docker.distribution.manifest.list.v2+json, which provides the ability to assign multiple tags per image. For instructions to inspect a manifest list, refer to the Docker manifest V2, Schema 2 specification.

The NGC UI lets you navigate through the supported architectures.

NGC container page showing supported architectures

3.3.7. Using OCI 1.1.1 Referrers in NGC Private Registry#

3.3.7.1. Overview#

NGC Private Registry supports Open Container Initiative (OCI) 1.1.1 Referrers on nvcr.io. Use this feature to attach and discover artifacts such as software bills of materials (SBOMs), Vulnerability Exploitability eXchange (VEX) documents, signatures, provenance, and attestations by image digest. The registry stores and discovers the artifact. Use your OCI or security tool to create, attach, discover, and verify it. For this release, use an open source command-line interface (CLI) that supports the OCI Referrers API, such as OCI Registry As Storage (ORAS) or Cosign, or use the registry API. Dedicated NGC CLI and UI referrer views are not available.

3.3.7.2. Before You Begin#

Before you begin, ensure that you meet the following requirements.

  • An NGC account and an active Personal Key or Service Key with access to the target repository.

  • Repository permission to discover or publish artifacts, as required.

  • ORAS with OCI 1.1 Referrers support.

For account setup, keys, permissions, and repository naming, refer to Getting Started, NGC API Keys, NGC Registry User Roles, and Tagging and Pushing a Container Image.

3.3.7.3. Authenticate to the NGC Private Registry#

Authenticate with the special username '$oauthtoken' and pass your NGC key through standard input.

export NGC_API_KEY='<your-ngc-api-key>'
printf '%s' "$NGC_API_KEY" | oras login nvcr.io \
  --username '$oauthtoken' --password-stdin

Follow your organization’s credential storage policy and remove credentials from shared build agents after use.

3.3.7.3.1. Set the Subject Reference#

Set the subject reference using a tag or digest. The ORAS attach and discover commands accept both forms.

SUBJECT_REF='nvcr.io/<org>/<team>/<repository>:<tag>'

For an organization-level repository, omit the <team>/ segment. To target an immutable subject, use a digest-qualified reference such as SUBJECT_REF='nvcr.io/<org>/<team>/<repository>@sha256:<64-hex-character-digest>'. When using a digest-qualified reference, NGC supports only SHA-256 digests.

3.3.7.6. Use the Referrers API Directly#

Use the HTTP endpoint only for client integration or troubleshooting. Unlike the ORAS commands, the Referrers API path requires a subject digest. If you started with a tag, resolve it with oras resolve "$SUBJECT_REF". Obtain a scoped registry bearer token through the standard authentication challenge.

3.3.7.6.1. Request#

Send a request in the following format.

GET /v2/<org>/<team>/<repository>/referrers/<subject-digest> HTTP/1.1
Host: nvcr.io
Accept: application/vnd.oci.image.index.v1+json
Authorization: Bearer <scoped-registry-token>

To filter by artifact type, use the following request path.

GET /v2/<org>/<team>/<repository>/referrers/<subject-digest>?artifactType=<URL-Encoded Value>
3.3.7.6.2. Response#

A successful request returns 200 OK and an OCI image index. An empty manifests array is valid. When you use artifactType, confirm that the OCI-Filters-Applied response header is set.

3.3.7.7. Important Behavior#

Keep the following behavior in mind.

  • Keep the referrer and subject in the same repository. The ORAS attach and discover commands can use a tag or digest, and the relationship is recorded against the resolved digest. NGC Private Registry supports only SHA-256 digests. For multi-architecture images, the index and each child manifest have different digests.

  • A native relationship is created only when the referring object is an OCI image manifest or OCI image index with a valid subject field. The referenced subject does not need to exist when the referrer is pushed, so you can push the subject and its referrers in either order.

  • Deleting a subject does not delete its referrers. Deleting a referrer removes it from discovery results.

  • A subject supports up to 64 distinct referrers. Remove obsolete referrers before retrying at the limit.

  • Existing valid fallback referrer indexes remain readable and are de-duplicated in discovery results. Use oras discover "$SUBJECT_REF" with either the subject tag or digest. The direct Referrers API requires the subject digest. Fallback tags cannot be created or updated.

  • Existing tag-based workflows for signing and verifying image signatures (.sig), attaching and retrieving SBOMs (.sbom), and publishing and retrieving VEX documents (.vex) continue to work, but the Referrers API does not return subjectless artifacts.

  • Use oras copy -r to copy a subject with its referrers.

3.3.7.8. Troubleshooting the Referrers API#

Use the following table to troubleshoot the Referrers API.

Referrers API Troubleshooting#

Symptom

Likely Cause

What to Do

401 Unauthorized

The key is missing, expired, revoked, or incorrectly supplied.

Log in again with '$oauthtoken' and an active key. Confirm that the key includes Private Registry access.

403 Forbidden

The identity does not have access to the organization, team, or repository.

Confirm the selected NGC org and team, and request the required read or write role.

400 Bad Request

The digest syntax is invalid, or a parameter is malformed.

Use a SHA-256 digest in the form sha256:<64-hex-character-digest>. Other digest algorithms are not supported.

200 with no manifests

No referrers match the subject digest or requested type.

Resolve the tag again, remove the filter, and compare the subject digest used when the evidence was attached.

Copied subject has no evidence

The copy operation did not traverse referrers.

Use recursive referrer-aware copy, and compare discovery results at the source and destination.

3.4. NGC Models#

The NGC private registry lets you upload and access deep-learning models.

3.4.1. Creating New NGC Models Using the NGC CLI#

Issue ngc registry model create -h to display a description of available options and command descriptions for creating a model.

This example creates a new model called “Final Review Model” with all required and optional arguments used:

$ ngc registry model create \
 --application OBJECT_DETECTION \
 --format "cpkt" \
 --framework TensorFlow\
 --precision FP16 \
 --short-desc "A model for object detection using TensorFlow" \
 --built-by "My Name" \
 --display-name "Final Review Model" \
 --label "fast" --label "sparkly" \
 --owner-name "MyTeam" \
 --overview-filename /path/to/my/overview/file.md \
 --publisher "NVIDIA MyTeam" \
 --public-dataset-license <license> \
 --public-dataset-link "www.example.com" \
 --public-dataset-name "200_10x200_images" \
 nvidia/myteam/final_review_model

3.4.2. Creating a New Model Using the NGC Website#

To create a new model asset, select Private Registry from the app menu in the top left. Then, select Models from the left navigation menu. Click Create Model on the top right of the page.

Models page with Create Model

The Create Model page walks you through the process of creating a new model asset.

Create Model form, first section Create Model form, second section Create Model form, third section

After you complete and submit this form, you have the option of creating a model version. You can skip this step and complete it later. Refer to Uploading an NGC Model Version Using the NGC Website for more information.

Model Creation Fields#

Field

Validation

Description

Options

Name

String

The name of the model

Publisher

String

The name of the individual who owns the asset (dropdown)

Description

String

Short description of the model

Overview

Markdown (String)

A place to share more details/usage instructions for the model

Labels

String (List)

Tags to make the asset more discoverable

Use Case

String

Intended use case

Annotation, Automatic Speech Recognition, Image Classification, Image Segmentation, Image Synthesis, Natural Language Processing, Object Detection, Translation

Framework

String

Deep learning framework used to build the model

Caffe, Clara, NeMo/PyTorch, PyTorch, TensorFlow, TensorRT, Transfer Learning Toolkit

Model Format

String

Output format of the weights file

caffemodel, HDF5, ONNX, protobuf, PyTorch PTH, SavedModel, TensorFlow CKPT, TensorRT Plan, TLT

Precision

String

Training precision used

AMP, FP16, FP32, INT8

3.4.3. Uploading a New NGC Model Version Using the NGC CLI#

Issue ngc registry model upload-version -h to display a description of available options and command descriptions for uploading a model version. If the command terminates or fails, rerunning the same command automatically resumes from the last checkpoint.

An example using all required and optional arguments to create model version 1 for the model created in the previous section.

$ ngc registry model upload-version \
  --accuracy-reached 96.5 \
  --batch-size 2000 \
  --gpu-model "V100" \
  --memory-footprint 4GB \
  --num-epochs 100 \
  --desc "A new and exciting version: 1" \
  --link "www.example.com/model/v1" \
  --link-type Other \
  --owner-name "My Name" \
  --source path/to/my/model/version/dir \
  nvidia/myteam/final_review_model:1

Adding Custom Metrics

You can also upload custom metrics tables for each model version. Each table can hold up to 12 key-value attribute pairs. Three tables maximum per model version.

Metrics tables are defined as JSON tables - one table per file. You can add the table to the upload with --metrics-file.

Some example metrics files:

zeppelin_table.json:

{
    "name": "ZeppelinTable",
    "attributes": [
        {"key": "Robert", "value": "Plant"},
        {"key": "Jimmy", "value": "Page"},
        {"key": "John", "value": "Bonham"},
        {"key": "John", "value": "Paul Jones"}
    ]
}

rhcp_table.json:

{
    "name": "RHCPTable",
    "attributes": [
        {"key": "Anthony", "value": "Keidis"},
        {"key": "Michael", "value": "Balzary"},
        {"key": "John", "value": "Frusciante"},
        {"key": "Chad", "value": "Smith"}
    ]
}

The above example with custom metrics tables included:

$ ngc registry model upload-version \
  --accuracy-reached 95.5 \
  --batch-size 2000 \
  --gpu-model "SomeGPUModel" \
  --memory-footprint 4GB \
  --num-epochs 100 \
  --desc "A new and exciting version: 1" \
  --link "www.example.com/model/v1" \
  --link-type Other \
  --owner-name "My Name" \
  --metrics-file zeppelin_table.json \
  --metrics-file rhcp_table.json \
  --source path/to/my/model/version/dir \
  nvidia/myteam/final_review_model:1

3.4.4. Uploading an NGC Model Version Using the NGC Website#

There are two ways to upload a new version of a model using the NGC website.

  • From the Model Creation page discussed above

  • From the Model Details page for any model

Create model version options

From the version creation page, shown below, you can specify all the relevant information about the specific version that you are uploading. You can also upload files directly from your browser.

Create model version form

After you complete the form and upload any relevant files, submitting publishes the new version of the content.

Adding Custom Metrics

As deep learning models evolve, you might also want to convey different information to distinguish between different versions. Using the NGC Model Registry, you can specify up to 36 different metrics to help people find the right versions.

When creating your version, click Add Custom Metrics to create the tables.

Add custom metrics for a model version
  • Model Name - String - The name of the model for which you want to upload a version

  • Owner - String - The name of the individual who owns the asset (dropdown)

  • Version - String - A way of identifying that version (use semantic versioning)

  • Overview - Markdown - A place to share more details/usage instructions for the model (shared across all versions)

  • Number of Epochs - String - Number of Epochs trained (or N/A)

  • Batch Size - String - Training Batch Size (or N/A)

  • GPU Model - Drop Down - GPU family used for training

  • Accuracy Reached - String - Accuracy of the model (or N/A)

  • Memory Footprint - String - Memory Footprint used by the model

  • Related Resources - You can optionally specify additional resources for your model

    • Link Text - Drop Down - The text to display for additional resources, such as containers or code samples, to accompany your version.

    • URL - String - The URL of the additional resource

After you enter the key/value pairs, select Add Table.

3.4.5. Editing NGC Model Information Using the NGC CLI#

Issue ngc registry model update -h to display a description of available options and command descriptions for editing a model or model version.

An example updating a model’s overview file for a model.

$ ngc registry model update \
  --overview-filename "path/to/my/updated/overview/file.md" \
  nvidia/myteam/final_review_model

An example updating a model-version’s accuracy reached and memory footprint.

$ ngc registry model update \
  --accuracy-reached 96.5 \
  --memory-footprint 16GB \
  nvidia/myteam/final_review_model:1

Common Model Commands:

  • ngc registry model info nvidia/model-name - show information about a model

  • ngc registry model info nvidia/model-name:version - show information about a model version

  • ngc registry model list - list available models

  • ngc registry model download-version nvidia/model-name:version - download the specified model-version

  • ngc registry model remove nvidia/model-name:version - remove a model-version

  • ngc registry model remove nvidia/model-name - remove a model

3.4.6. Editing NGC Model Information Using the NGC Website#

To edit a model’s metadata or overview tab, select Edit from the top right of the model details page.

Model details page with Edit selected

You can then edit any of the model’s details, or delete the model.

Editable model details page

3.4.7. Cloning NGC Model Version Using the NGC Website#

Use the NGC website to create a new version of an existing model by cloning it.

Cloning a model version creates a new version based on an existing one, allowing you to make modifications while preserving the original version. The NGC UI provides two methods to clone a model version:

Method 1: Clone from Entity Creation Page

  1. Navigate to the Entity Creation page.

  2. Select Create Model.

  3. Choose Clone Version from the available options.

  4. Select the model version you want to clone from the list of available models.

Clone Version option on the Entity Creation page

Method 2: Clone from Model Details Page

  1. Navigate to the Model Details page.

  2. Select the Version History tab.

  3. Click Clone Version for the desired model version.

Clone Version action on the Version History tab

On the Clone Version page, you can:

  • Specify version information and metadata

  • Remove files from the existing version

  • Upload new files directly from your browser

Clone Version form for a model

After completing the form and uploading any necessary files, click Submit to create the new cloned version of the model.

3.4.8. Creating a New NGC Model Version Using the NGC CLI#

You can create a new version of an existing model using the NGC CLI.

The NGC CLI provides a command-line interface for creating new model versions. This method is useful for automation and batch processing.

Use the upload-version command

The basic syntax for creating a new version is:

ngc registry model upload-version <model-name>:<new-version> --base-version <base-version> --source <source-directory>

Where:

  • <model-name> is the name of your model (for example, nvidia/hp_test)

  • <new-version> is the version tag for the new version (for example, v2)

  • <base-version> is the version you want to base the new version on (for example, v1)

  • <source-directory> is the path to the directory containing your new version files

Example: Creating version v2 from base version v1

To create a new version v2 based on version v1, using files from the ./src directory:

ngc registry model upload-version nvidia/hp_test:v2 --base-version v1 --source ./src

3.4.9. Customer Managed Keys#

Customer Managed Keys (CMK) provide an additional layer of security for models and containers within the NGC Private Registry.

Although NGC artifacts are already encrypted at rest with unique NGC keys, Customer Managed Keys let you add an additional layer of encryption using your organization’s key for stronger privacy control. With CMKs, you control the cryptographic keys, so if you revoke access to a key, associated models and containers become unreadable.

You can create CMKs using the NGC CLI or the NGC Private Registry UI on the model creation page.

3.4.9.1. Using Customer Managed Keys via the NGC CLI#

This section provides CLI commands to manage and use Customer Managed Keys (CMK) for model encryption in the NGC Private Registry.

Note

Before you begin, ensure that you have NGC CLI (version 4.3.0 or later) installed and configured for your organization.

3.4.9.1.1. Managing Encryption Keys#

You can create an encryption key at the time of model creation to auto-generate a new CMK. You can also list, view, and delete encryption keys within your organization or team namespace.

3.4.9.1.1.1. Create a New Encryption Key#

This command generates a new encryption key at the time of model creation.

Command

$ ngc registry model create <model>  --encryption-key-description <key_description> --framework <model_framework> --application <model_application> --format <model_format> --precision <model_precision> --short-desc <model_description>

Example

Command to create a new encryption key
3.4.9.1.1.3. List Encryption Keys#

This command lists all available encryption keys in your configured organization and (optionally) team.

Command

$ ngc registry encryption-key list

Example

Command to list encryption keys
3.4.9.1.2. Using Encryption Keys with Models#

You can view which models are associated with an encryption key, and how to find the encryption key associated with a model.

3.4.9.1.2.1. View Key and Associated Models#

This command displays information about the encryption key, including its ID, description, and associated models.

Command

$ ngc registry encryption-key info <encryption_key_target>

Example

$ ngc registry encryption-key info my-org/12345678-4321-abcd-efg1-12345abcde67

Output

Encryption Key Details:

 Encryption Key: my-org/12345678-4321-abcd-efg1-12345abcde67

 Associated Artifacts:

  MODEL:

   my-org/research/confidential-llm     Here is a short description about confidential-llm
3.4.9.1.2.2. View Associated Key for a Model#

This command checks a model’s information to determine which encryption key, if any, is associated with it. The encryption key ID is listed in the output.

Command

$ ngc registry model info <org>/[team/]<model_name>

Example

$ ngc registry model info my-org/research/confidential-llm

Output

Model Information:
  Name: confidential-llm
  Application: NATURAL_LANGUAGE_PROCESSING
  Framework: other
  Model Format: other
  Precision: other
  Short Description: Here is a short description about confidential-llm
  Display Name:
  Logo:
  Org: my-org
  Team: research
  Built By:
  Publisher:
  Created Date: 2025-09-19T23:20:24.674Z
  Updated Date: 2025-09-19T23:20:24.674Z
  Has Signed Version: False
  Access Type:
  Associated Products:
  Labels
  Latest Version ID:
  Latest Version Size (bytes): 0
  Public Dataset Used
     Name:
     Link:
     License:
  Encryption Key
     ID: 12345678-4321-abcd-efg1-12345abcde67
3.4.9.1.3. Revoking Access to Models#

To revoke access, either disassociate the encryption key from a specific model or delete the key to remove access from all associated models. Both actions are irreversible and run asynchronously.

3.4.9.1.3.1. Disassociate Key from Model#

This command revokes access to all versions of a single model by removing the model’s association with its encryption key. This is a one-time, irreversible action. You must create a new model and associate a new or existing CMK to restore access. For more information, refer to Managing Encryption Keys.

Command

$ ngc registry encryption-key disassociate --model <org>/[team/]<model_name> --no-wait

Example

$ ngc registry encryption-key disassociate --model my-org/research/confidential-llm --no-wait

The --no-wait flag initiates the background task and immediately returns a status URL.

Output

Are you sure you would like to remove model my-org/research/confidential-llm? [y/n]y

+---------------+--------------------+-----------+------------------------+---------+
| Artifact Type | Artifact Name      | Status    | Status URL             | Message |
+---------------+--------------------+-----------+------------------------+---------+
| model         | my-org/research/   | completed | /v2/artifact-registry/ |         |
|               |confidential-llmm   |           | org/m8sc4demnvoe/workf |         |
|               |                    |           | lows/org-my-org-team-  |         |
|               |                    |           | research-12345678-4321 |         |
|               |                    |           | -abcd-efg1-12345abcde  |         |
|               |                    |           | 67-model-confidential- |         |
|               |                    |           | llm-disassociate       |         |
+---------------+--------------------+-----------+------------------------+---------+
3.4.9.1.3.2. Delete an Encryption Key#

This command deletes an encryption key and revokes access to all associated models.

Warning

This is a destructive and irreversible action. Deleting a key revokes access to all associated models; they are permanently deleted within 24 hours.

Command

$ ngc registry encryption-key remove <key_id> --no-wait

Example

$ ngc registry encryption-key remove my-org/12345678-4321-abcd-efg1-12345abcde67 --no-wait

Output

+-----------------------------+-----------+------------------------------+---------+
| Encryption Key              | Status    | Status URL                   | Message |
+-----------------------------+-----------+------------------------------+---------+
| my-org/12345678-4321-       | completed | /v2/artifact-registry/org/my |         |
| abcd-efg1-12345abcde67      |           | -org/workflows/org-my-org    |         |
|                             |           | -12345678-4321-abcd-efg1-    |         |
|                             |           | 12345abcde67-delete          |         |
+-----------------------------+-----------+------------------------------+---------+
3.4.9.1.3.3. Check Operation Status#

Since disassociation and deletion are asynchronous, you can use the status URL returned by the commands to check the progress of the workflow. The command will return a status of IN_PROGRESS, COMPLETED, or FAILED.

Command

$ ngc registry encryption-key status <status_url>

Example

$ ngc registry encryption-key status "/v2/artifact-registry/org/my-org/workflows/org-my-org-MODEL-4b7c04a4-delete"

3.4.9.2. Using Customer Managed Keys via the Private Registry UI#

3.4.9.2.1. Creating an Encryption Key#

You can add a CMK to a new model using the Entity Creation Hub UI.

  1. Ensure your organization is enabled for Customer Managed Keys.

  2. Sign in to the Private Registry. On the Entity Creation Hub page, select Create Model under Create a Model.

    Entity creation hub
  3. Fill in the required fields on the Create Model form. In the Encryption Key section, select the Link Customer Managed Encryption Key option.

    Create model
  4. Choose one of the following options to add a CMK to the model:

    • Existing key: Select an existing customer-managed encryption key.

    • New key: Create a new customer-managed encryption key.

      Create model options
    1. If you choose to create a new key, select Create a new Customer Managed Encryption Key and add a short description.

      Create new key

      After creating the model, the encryption key appears in the left details pane on the model page.

      Model page with key selected
    2. If you choose to add an existing encryption key, select a key from the list of available keys.

      Create model form existing key

      After creating the model, the selected key appears in the left details pane on the model page.

3.4.9.2.2. Unlinking the Encryption Key#

You can remove the association between an encryption key and a model from the Private Registry models page. Removing an encryption key from a model deletes the associated model. This action is irreversible.

There are two ways to unlink an encryption key from a model:

  • Unlink the key from a model on the model details page.

  • Unlink the key from the Models > Customer Managed Encryption Keys list page to remove it from the associated model.

3.4.9.2.3. Revoking the Encryption Key#

You can revoke access to an encryption key and all associated models by deleting the key.

Warning

Revoking an encryption key deletes the key and all associated models. This action is irreversible.

  1. In the Models > Customer Managed Encryption Keys tab, select the … (ellipsis) action menu for the key and choose Revoke Key.

    Revoke key from key list
  2. A confirmation dialog appears similar to the following.

    Revoke key from key list
  3. Confirm the revoke action by selecting the checkbox and clicking Revoke Key & Delete Models.

    Revoke key from key list confirm
  4. A message appears next to the key indicating that the revoke operation is in progress. Wait for the operation to complete.

    Revoke key from key list in progress
  5. After the operation completes, the models and the key (in this example, Test-key) are deleted.

    Revoke key from key list completed

3.5. NGC Resources#

The NGC private registry lets you upload and access resources for deep-learning models.

3.5.1. Before You Begin#

With the NGC Registry CLI you can update the container description and all the other container metadata.

Confirm your context, or which org and team you are logged in to. This determines which registry space your model is uploaded to. You can do this by entering the following:

$ ngc config current

If you intend to upload a model to a different registry space, or if no team is reported and you intend to upload to a team space, then you can either:

Use ngc config set to switch to another org or team:

$ ngc config set [--org <new org>][--team <new team>]

or

Set the context at each command, using the same --org or --team options.

3.5.2. Uploading a Resource#

The following is the general process for uploading a resource to the model script registry.

  1. Create a resource in the registry. This is a placeholder for your model and contains metadata about the resource.

    Example of creating resource “cmr_gnmt”.

    $ ngc registry resource create nvidia/cmr_gnmt
    

    To display a complete list of required and optional arguments, enter the following.

    $ ngc registry resource create -h
    
  2. Upload your resource files.

    Each time you upload files to the same resource, the upload becomes a unique version of the resource. You can specify the version when you upload, or let the CLI increment the version automatically.

    Example: Uploading version 1 of the resource ‘cmr_gnmt’ (required arguments omitted for simplicity).

    $ ngc registry resource upload-version nvidia/cmr_gnmt:first-upload [--source .<directory or file path for the model contents>]
    
    ----------------------------------------------------
    Transfer id: cmr_gnmt[version=first-upload] Upload status: Completed.
    Uploaded local path: C:\resource
    Total files uploaded: 26
    Total uploaded size: 134.48 KB
    Started at: 2019-03-15 17:18:09.083000
    Completed at: 2019-03-15 17:18:21.698000
    Duration taken: 12s seconds
    ----------------------------------------------------
    

3.5.3. Updating a Resource#

You can update or revise information for a resource or resource version.

The following is the basic command.

$ ngc registry resource update <org>/[<team>/]<resource-name[:version]>

To update information, use the optional arguments to specify the information to change. To display the list of arguments, run:

$ ngc registry resource update -h

3.5.4. Resource Commands#

The full list of optional commands for NGC resources are listed below.

  • --accuracy-reached <accuracy>
    • Accuracy reached with target version.

  • --ace <name>
    • Specify the ACE name. Use --ace no-ace to override other sources and specify no ACE. Default: current configuration

  • --advanced-filename <path>
    • Advanced guide. Provide the path to a file that contains the “Advanced Guide” for the resource.

  • --application <app>
    • Target model application. Allowed values: CLASSIFICATION, OBJECT_DETECTION, SEGMENTATION, TRANSLATION, TEXT_TO_SPEECH, RECOMMENDER, SENTIMENT, NLP, KUBEFLOW_PIPELINE, OTHER.

  • --batch-size <size>
    • The batch size of the target version.

  • --built-by <name>
    • Builder of the target model.

  • --debug
    • Enable debug mode.

  • --desc <desc>
    • Full description of target version.

  • --display-name <name>
    • Display name.

  • --format <fmt>
    • Format of the target model.

  • --format_type <fmt>
    • Specify the output format type. Supported formats are: ascii, csv, json. Only commands that produce tabular data support csv format. Default: ascii

  • --framework <fwk>
    • Framework used to train the target model. Allowed values: TensorFlow, Caffe2, CNTK, Torch, PyTorch, MXNet, Keras, Other.

  • --gpu-model <model>
    • The GPU used to train the target version.

  • --label <label>
    • Label for the resource. To specify more than one label, use multiple --label arguments.

  • --logo <url>
    • URL for the resource logo image.

  • --memory-footprint <footprint>
    • The memory footprint of the target version.

  • --num-epochs <num>
    • The number of epochs for the target version.

  • --org <name>
    • Specify the organization name. Use --org no-org to override other sources and specify no org. Default: current configuration

  • --overview-filename <path>
    • Overview. Provide the path to a file that contains the overview for the resource.

  • --performance-filename <path>
    • Performance data. Provide the path to a file that contains the performance data for the resource.

  • --precision <prec>
    • Precision the target model was trained with. Allowed Values: FP16, FP32, INT8, FPBOTH, OTHER.

  • --public-dataset-license <lcs>
    • License for public dataset used in the target model.

  • --public-dataset-link <url>
    • Link to public dataset used in the target model.

  • --public-dataset-name <name>
    • Name of public dataset used in the target model.

  • --publisher <name>
    • Publisher of the target model.

  • --quick-start-guide-filename <path>
    • Quick start information. Provide the path to a file that contains the “Quick Start Guide” information for the resource.

  • --release-notes-filename <path>
    • Release notes. Provide the path to a file that contains the release notes for the resource.

  • --setup-filename <path>
    • Setup instructions. Provide the path to a file that contains the setup instructions for the resource.

  • --short-desc <desc>
    • Short description.

  • --team <name>
    • Specify the team name. Use --team no-team to override other sources and specify no team. Default: current configuration

3.5.5. Deleting a Resource#

Only admins and creators of the model can delete a model.

Confirm that the context is set appropriately for the resource you want to delete. For example, if you want to delete a model that you created in the team_A space, then set the context as --team team_A.

To remove the resource, including all versions of the resource, enter the following.

$ ngc registry resource remove <org>/[<team>/]<resource>

To remove only a specific version of the resource, enter the following.

$ ngc registry resource remove <org>/[<team>/]<resource:version>

3.6. NGC Helm Charts#

This guide describes how to use the NGC registry to manage Helm charts.

3.6.1. Introduction to NGC and Helm Charts#

Helm is an application package manager running on top of Kubernetes. It lets you create Helm charts where you can define, install, and upgrade Kubernetes applications.

This guide describes how to share Helm charts with others in your org or team using the NGC registry.

Prerequisites

These instructions assume the following prerequisites are met.

  • Helm v3.x installed

    This is only required if you are creating or packaging Helm charts yourself. It is not needed otherwise.

  • NGC organization account

    Refer to the section Getting Started for instructions.

Note

The asset ngcdocstest referenced below was created for example purposes only. It is intended merely as a guide and is not a requirement for publishing Helm assets to NGC.

3.6.2. Creating and Packaging a Helm Chart#

This section describes how to package a Helm chart for publishing to NGC.

You do not need to deploy the Helm chart to publish your chart to NGC. A .tgz file of the chart can be published to an org in NGC without being deployed first to the GPU infrastructure.

  1. Create a Helm chart template by issuing the following.

    $ helm create <chart-name>
    

    Where <chart-name> is the name of your choosing.

    Example:

    $ helm create ngcdocstest
    
  2. Modify the contents of the template with your Helm chart data. Use the following convention:

    • Chart names: must be lowercase or uppercase alphanumeric characters, and must start with a letter. Words can be separated with hyphens (-) or underscores (_). Dots (.) are not allowed.

    • Versions: must be a valid semantic versioning (SemVer 2.0.0) string.

  3. Package the Helm chart by issuing the following.

    $ helm package <chart-name>
    

    Example:

    $ helm package ngcdocstest
    

    This example creates the tar package ngcdocstest-0.1.0.tgz.

3.6.3. Manage Helm Charts Using the NGC Web UI#

3.6.3.1. Viewing the List of Helm Charts and Getting Fetch Commands#

From the NGC website you can:

  • View the contents of the Helm chart repository.

  • Get the fetch command for a specific Helm chart in the repository.

  1. From a browser, log in to the NGC website.

  2. If you are a member of more than one org, select the one that contains the Helm charts that you are interested in, then click Sign In.

  3. Click Helm Charts from the left-side navigation pane.

    Helm Charts in the NGC left navigation
  4. The page presents cards for each available Helm chart.

    Helm chart cards in the NGC catalog
  5. Select one of the Helm chart cards. The page for each Helm chart provides information about the chart.

    Helm chart details page
  6. Click the Fetch Version dropdown menu from the upper right corner to copy the fetch command to the clipboard.

3.6.3.2. Adding Helm Charts Using the NGC Web UI#

Note

Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry User” or “Registry Admin”. For details, refer to NGC Registry User Roles.

Before a chart can be uploaded to your organization’s registry, you must first create a record containing the basic information about the chart.

  1. Click Entity Creation Hub under the Private Registry section of the left side menu.

    Entity Creation Hub in the Private Registry menu
  2. Click Create Helm Chart.

  3. Fill in information about your Helm chart.

    Create Helm Chart form
  4. Click Create Helm Chart.

  5. To push (upload) a Helm chart to your org space, use the NGC CLI.

    Example:

    $ ngc registry chart push nvidian/ngcdocstest:0.1.0
    

    Refer to Pushing a Helm Chart for details.

3.6.3.3. Updating the Helm Chart Page From the Website#

To update the fields in the NGC Helm Chart page for a specific Helm chart, click Edit Details.

Edit Details on a Helm chart page

Edit each field as needed, then click Save.

3.6.3.4. Removing Helm Charts from the Web UI#

Note

Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry Admin”. For details, refer to NGC Registry User Roles.

To delete a Helm chart, click Edit Details from the details page of the Helm chart to delete.

Edit Details on a Helm chart page before delete
  1. Click Delete to remove the Helm chart.

  2. Click Delete at the confirmation dialog.

3.6.4. Manage Helm Charts Using the NGC CLI#

3.6.4.1. Searching for Available Helm Charts in an Org#

The NGC CLI supports wildcard searches, using standard Unix shell-style wildcards. For example, to display a list of all available Chart packages in your org, run the following command.

$ ngc registry chart list "*<org_name>*"

Example:

$ ngc registry chart list "*nvidian*"

That command returns all charts with ‘nvidian’ anywhere in the name.

Sample Helm Chart Info#

Name

Repository

Version

Size

Created By

Description

Created Date

Last Modified

fluentd-elasti csearch

nvidian/fluen ntd-elasticse arch

4.8.1

245.61 KB

stg-3emmf14t83v d0s5v81qasfi479

Changed sho rt descript ion

Nov 15, 2019

Dec 17, 2019

clara

nvidian/repo1 /clara

0.0.1

65.66 KB

stg-p6urlvepnjb q06qfis28l5m6a4

Feb 07, 2020

Mar 12, 2021

3.6.4.2. Fetching Helm Charts#

To download (or “pull”) a Chart package, run the following command.

Note

If no version is specified, the most recent version is pulled.

$ ngc registry chart pull org/[team/]chart[:version]

Example:

$ ngc registry chart pull nvidian/nginx-ingress:1.2.3 (pulls version 1.2.3)

$ ngc registry chart pull nvidian/nginx-ingress (pulls the latest version)

3.6.4.3. Adding Helm Charts to a Private Registry#

Note

Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry User” or “Registry Admin”. For details, refer to NGC Registry User Roles.

Creating a Chart

Before a chart can be uploaded to your organization’s registry, you must first create a record containing the basic information about the chart. There are several values you can specify (issue ngc registry chart create --help to view all of them), but you must at least provide a short description of the chart.

$ ngc registry chart create <org>/[<team>/]<chart_name> --short-desc <description>

Example:

$ ngc registry chart create nvidian/ngcdocstest --short-desc "Doc testing chart"

Successfully created chart 'nvidian/ngcdocstest'.
--------------------------------------------------
Chart Information
 Name: ngcdocstest
 Short Description: Doc testing chart
 Display Name:
 Team:
 Publisher:
 Built By:
 Labels:
 Logo:
 Created Date: 2021-03-22 18:48:36 UTC
 Updated Date: 2021-03-22 18:48:36 UTC
 Read Only: False
 Latest Version ID:
 Latest Version Size (bytes):
 Overview:
--------------------------------------------------

Updating a Chart

You can update the metadata about a chart after it has been created with the update command.

$ ngc registry chart update <org>/[<team>/]<chart_name> --<property> <value>

Example:

$ ngc registry chart update nvidian/ngcdocstest --publisher "test account" --display-name "Helm Demo Chart" --built-by "my team"

Successfully updated chart 'nvidian/ngcdocstest'.
--------------------------------------------------
Chart Information
 Name: ngcdocstest
 Short Description: Doc testing chart
 Display Name: Helm Demo Chart
 Team:
 Publisher: test account
 Built By: my team
 Labels:
 Logo:
 Created Date: 2021-03-22 18:48:36 UTC
 Updated Date: 2021-03-22 18:52:01 UTC
 Read Only: False
 Latest Version ID: 0.1.0
 Latest Version Size (bytes): 10664
 Overview:
 --------------------------------------------------

3.6.4.4. Getting Information About a Helm Chart#

You can view the information about a chart at any time by running the info command:

Example:

$ ngc registry chart info nvidian/ngcdocstest
--------------------------------------------------
Chart Information
 Name: ngcdocstest
 Short Description: Doc testing chart
 Display Name: Helm Demo Chart
 Team:
 Publisher: test account
 Built By: my team
 Labels:
 Logo:
 Created Date: 2021-03-22 18:48:36 UTC
 Updated Date: 2021-03-22 18:54:44 UTC
 Read Only: False
 Latest Version ID: 0.1.0
 Latest Version Size (bytes): 10664
 Overview:
--------------------------------------------------

3.6.4.5. Pushing a Helm Chart#

To push (upload) a Helm chart to your org space, issue the following.

$ ngc registry chart push <org>/[<team>/]<chart_name>:<version>

Example:

This example expects the packaged chart file ngcdocstest-0.1.0.tgz to be present in the current directory.

$ ngc registry chart push nvidian/ngcdocstest:0.1.0

Looking for chart ngcdocstest-0.1.0.tgz
Successfully pushed chart version 'ngcdocstest:0.1.0'.
--------------------------------------------------
Chart Version Information
 Created Date: 2021-03-22 18:54:44 UTC
 Updated Date: 2021-03-22 18:54:44 UTC
 Version ID: 0.1.0
 Total File Count: 11
 Total Size: 10.41 KB
 Status: UPLOAD_COMPLETE
--------------------------------------------------

3.6.4.6. Listing Helm Chart Versions#

To display a list of all available versions for a chart, specify the chart name.

Example:

$ ngc registry chart list nvidian/nginx-ingress
+---------+------------+-----------+--------------+
| Version | File Count | File Size | Created Date |
+=========+============+===========+==============+
| 0.8.0   | 27         | 181.94 KB | Mar 12, 2021 |
| 1.0.0   | 25         | 149.51 KB | Oct 02, 2020 |
| 0.0.6   | 25         | 149.51 KB | Oct 02, 2020 |
| 0.0.5   | 25         | 149.51 KB | Oct 02, 2020 |
| 0.6.0   | 25         | 149.51 KB | Sep 17, 2020 |
| 0.6.1   | 25         | 149.51 KB | Sep 17, 2020 |
| 1.26.2  | 68         | 109.19 KB | Feb 08, 2020 |
+---------+------------+-----------+--------------+

3.6.4.7. Removing Helm Charts from a Private Registry#

Note

Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry Admin”. For details, refer to NGC Registry User Roles.

If you are an admin, you can delete a specific version of a chart running the following command:

$ ngc registry chart remove <org>/[<team>/]<chart_name>:<version>

The following example removes just version 0.1.0:

$ ngc registry chart remove nvidian/ngcdocstest:0.1.0

The following example removes all versions and data about the chart:

$ ngc registry chart remove nvidian/ngcdocstest

If you do not specify a version, every version of the chart, as well as the chart metadata, is deleted.

Example:

$ ngc registry chart remove nvidia/ngcdocstest

Are you sure you would like to remove nvidia/ngcdocstest? [y/n]y
Successfully removed chart version 'nvidia/ngcdocstest:0.1.0'.
Successfully removed chart 'nvidia/ngcdocstest'.

3.6.5. Manage Helm Charts Using the NGC API#

3.6.5.1. Updating Information on the Helm Chart Page#

The NGC API lets you specify information about your Helm chart. Use the NGC API Explorer page for updating artifact in an org to build the JSON file for use in a CURL command.

The following page elements can be edited.

Helm Chart Page Elements#

Page Element

JSON Field

Description

Helm Chart name

displayName

The name of the Helm chart appearing in the title on the tile and Helm chart page

Publisher

publisher

The organization/entity responsible for creating the asset

Logo

logo

URL of the image to use as the logo for the asset

Description

shortDescription

A short description for the Helm chart

Labels

labels

Tags to enhance search results

Overview tab

description

Content of the “Overview” tab which can provide publishers to convey additional

The JSON column shows the corresponding JSON fields to use when updating the page using the NGC API.

The following shows the relevant fields in the JSON file.

{
  "attributes": [
    {
      "key": "string",
      "value": "string"
    }
  ],
  "builtBy": "string",
  "description": "string",
  "displayName": "string",
  "labels": [
    "string"
  ],
  "logo": "string",
  "publisher": "string",
  "shortDescription": "string"
}

Example

The following shows example JSON values.

{
  "builtBy": "NVIDIA",
  "description": "#NGC Docs Chart",
  "displayName": "NGC DOCS CHART TEST",
  "labels": [
    "Helm Chart",
    "Documentation"
  ],
  "shortDescription": "This charts is for the docs!"
}

The following is an example CURL command.

curl -X PATCH --header 'Content-Type: application/json' \
   --header 'Accept: application/json' \
   --header 'Authorization: Bearer <<BEARER_TOKEN>>' \
   -d '{ "builtBy": "NVIDIA", "description": "#Le Chart", "displayName": "NGC DOCS TEST", "labels": [ "Helm Chart", "Documentation" ], "shortDescription": "This chart is for the docs&#33;" }' \
   'https://api.ngc.nvidia.com/v2/org/nvidian/helm-charts/ngcdocstest'

3.6.5.2. Deleting Helm Charts Using the NGC API#

Refer to Delete artifact in an org for a description of the relevant API.

To delete a Helm chart from an org space, issue the following:

$ curl -X DELETE --header 'Accept: application/json' --header 'Authorization: Bearer <Bearer Token>' 'https://api.ngc.nvidia.com/v2/org/<org-name>/helm-charts/<chart-name>'

To delete a Helm chart from a team space, issue the following:

$ curl -X DELETE --header 'Accept: application/json' --header 'Authorization: Bearer <Bearer Token>' 'https://api.ngc.nvidia.com/v2/org/<org-name>/team/<team-name>/helm-charts/<chart-name>'

3.6.6. Manage Helm Charts Using the Helm CLI#

3.6.6.1. Setting Up an NGC Helm Repository#

  1. Obtain an NGC API Key. Refer to Generating NGC API Keys for instructions.

  2. Export the API Key for use in commands.

    $ export NGC_API_KEY=<your-api-key>
    
  3. Add the NGC org to your Helm repository.

    $ helm repo add <repo-name> https://helm.ngc.nvidia.com/<org-name> --username=\$oauthtoken --password=$NGC_API_KEY
    

    Where <repo-name> is a name of your choosing by which you reference the repository.

3.6.6.2. Updating the Local Helm Repository#

To reconcile your local Helm repository with the remote NGC Helm registry, run the following. This refreshes the local cache so you can discover new charts and charts that have been removed since the repo was last added or refreshed.

$ helm repo update <repo-name>

3.6.6.3. Searching for Available Helm Charts#

To view a list of available Chart packages in your org, issue the following.

$ helm search repo <repo-name>

3.6.6.4. Fetching Helm Charts#

To download (or “fetch”) a Helm chart package from the repo, issue the following.

$ helm pull <repo-name>/<chart-name>

3.6.6.5. Adding Helm Charts to a Private NGC Org/Team#

These instructions assume the Helm push plug-in is installed. To install the plug-in, issue the following.

$ helm plugin install https://github.com/chartmuseum/helm-push

To push (upload) a Helm chart to your org space, issue the following.

$ helm cm-push <chart-name>.tgz <repo-name>

Then update the local Helm cache to view the new chart.

$ helm repo update <repo-name>

3.6.6.6. Removing Helm Charts from a Private NGC Org/Team#

To remove Helm charts from your org or team, you must use the NGC CLI, NGC Web UI, or NGC API.

3.7. Private Registry Quotas and Limits#

The following size limits apply to the Private Registry:

Quotas and Limits#

Description

Limit

Note

Single image layer size

10 GB

Size limit per layer for Docker images (recommended).

Total image size

1 TB

Size limit for all Docker images stored in the registry (recommended).

Total model/resource size

5 TB

Size limit for all models or resources stored in the registry (enforced).

Chart file size

5 MB

Configurable; default per-file limit for Helm charts.

Compressed chart size

100 MB

Configurable; default. Current maximum is 19 MB.

Files per chart

10,000

Maximum number of files in a single Helm chart.

Note

Avoid creating an unbound number of Helm chart versions.

3.8. Getting Support for NGC Container and Helm Chart Registries#

For additional information on using the NGC container registry or the NGC Helm chart registry, or for help if you encounter issues with either, send an email to enterprisesupport@nvidia.com with a description of your issue. A ticket is created for you.