3. NGC Private Registry User Guide#
This guide is for users and administrators of NVIDIA NGC Private Registry.
3.1. NGC Private Registry for Enterprise#
This guide describes how to use the NVIDIA® NGC Private Registry. It assumes that you are familiar with Linux and Docker and that you have access to an NVIDIA GPU-based computing solution. Examples include an NVIDIA DGX system or an NVIDIA-Certified system configured for internet access and prepared for running NVIDIA GPU-accelerated Docker containers.
As data scientists build custom content, storing, sharing, and versioning that intellectual property is critical to meeting business needs. NVIDIA NGC Private Registry provides a secure space to store and share custom containers, models, Jupyter notebooks, and Helm charts within your enterprise. The NGC Private Registry is available to DGX and NVIDIA AI Enterprise customers.
3.1.1. Increased Collaboration#
Teams often share work in tools such as Slack or Microsoft Teams. NGC Private Registry lets you share artificial intelligence (AI) content such as containers, models, and Helm charts within your organization. Stakeholders can reuse existing assets instead of recreating them.
3.1.2. Enterprise Ready#
When you share content across a large organization, you need to manage who can access it. User and team management in NGC Private Registry lets administrators control access to content stored in the registry.
Content stored in the NGC Private Registry remains available through redundant storage, and you can access it from any location.
3.2. Getting Started#
3.2.1. Obtaining a Private Registry#
This section describes how DGX customers obtain a private registry.
After you purchase a support entitlement with NVIDIA, you receive an NVIDIA Entitlement Certificate by email. The email includes the instructions to register for technical support.
The following is an example of the NVIDIA Entitlement Certificate email.
The Entitlement Certificate itself is provided as a PDF attachment. The following is an example of an NVIDIA Entitlement Certificate.
The PDF also includes instructions for using the certificate.
If you already have an account, you can immediately log in to the NVIDIA Enterprise Support portal.
If you are a new user without an NGC Support account, click the NVIDIA Enterprise Support Registration Form link.
This link includes embedded information about your account. Do not share this entitlement link outside of your organization.
Registration provides an NGC private registry account and an NVIDIA Enterprise Support account. You receive a welcome email. After you receive the email, you can activate your NGC private registry account.
3.2.2. Activating a New NGC Account#
Before using NGC, you must have an NGC account created by your organization owner or other administrators in your organization. You need an email address to set up an account. Choose one of the following processes depending on your situation for activating your NGC account.
3.2.2.1. Joining an NGC Org or Team With an Existing NVIDIA Account#
This section describes joining an org or team when your email address is already associated with an NVIDIA account.
After NVIDIA or your organization administrator adds you to a new org or team within an organization, you receive a welcome email that invites you to continue the activation and sign-in process.
Click the Accept Invitation and Sign In link to open the NGC sign-in page.
Enter your email address and sign in using your NVIDIA account credentials.
The Set Your Organization screen appears.
Select the new organization and team you have been invited to. Click Continue.
You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.
To view artifacts in your private registry, select Private Registry in the app menu in the top left. Then, you can create collections, containers, Helm charts, models, and resources, as needed.
3.2.2.2. Joining an Org or Team With a New NVIDIA Account#
This section describes activating a new account where the domain of your email address is not mapped to an organization’s single sign-on (SSO).
After your organization administrator invites you to an org or team, you receive a welcome email that invites you to continue the activation and sign-in process.
Click the Accept Invitation and Sign In link to open the NGC sign-in dialog in your browser, or go to the NGC sign-in page.
Enter your email address and click Continue. NGC prompts you to create a new NVIDIA account.
Fill in your information, create a password, agree to the Terms and Conditions, and click Create Account. An email is sent to you to verify your email address.
Open the email and click Verify Email Address.
In the Almost done! dialog, select your communication preferences and then click Submit.
In the NVIDIA Account Terms of Use dialog, select the desired options and click Agree.
Select the organization and team you want to log in under and then click Continue.
You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.
To view artifacts in your private registry, select Private Registry from the app menu in the top left. Then, you can create collections, containers, Helm charts, models, and resources, as needed.
3.2.2.3. Joining an Org as Org Owner#
This section describes activating a new NGC org where you are joining as the org owner.
After NVIDIA sets up your NGC org, you receive a welcome email that invites you to continue the activation and sign-in process.
In the example, “Novi Sciences” is the owner of the newly created organization. The following steps assume Novi is new to NGC and explain how to create a new NVIDIA account and sign in as org owner. If you already have an NVIDIA account managing other NGC orgs as org owner, click Use alternate method to sign in with your existing NVIDIA account and access your new org.
Take note of the following important information in the email.
“TB3-org” is the display name for your org. The display name identifies your org in the NGC web UI.
“njdfzzqagzno” is the unique identifier for your org. This identifier represents your org namespace. You can use this identifier in some CLI commands.
Click Sign in to NGC, or using a browser, navigate to the NGC sign-in page.
Enter your email address and click Continue.
The create account screen appears. Verify your email and create a password. Review the NVIDIA Account Terms of Use and Privacy Policy, and click Create Account.
A verification email is sent.
Open the email and click Verify Email Address.
In the Almost done! dialog, select your communication preferences and then click Submit.
In the NVIDIA Account Terms of Use dialog, select the desired options and click Agree.
Select the organization and team you want to log in under and then click Continue.
You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.
3.2.2.4. Joining an Org or Team With an External SSO Company Account#
This section describes joining an org or team that your company has federated to an external SSO or identity provider (IdP) authentication service. Your email address domain requires NGC authentication against your company’s SSO.
After your organization administrator adds you to a new org or team within the organization, you receive a welcome email that invites you to continue the activation and sign-in process.
Click the Accept Invitation and Sign In link to open the NGC sign-in page. Enter your email address and click Continue.
If your email address domain is associated with an external SSO identity provider, NGC redirects you and prompts you to authenticate with that method.
For example:
After you authenticate, NGC redirects you to the NGC website.
If you are a member of more than one NGC org, the Set Your Organization screen appears.
Select the new organization and team you have been invited to and click Continue.
You can always change to a different org or team that you are a member of after logging in. Refer to Switching Orgs or Teams After Logging into NGC for more information.
The NGC web UI opens to the NGC Catalog landing page.
To view artifacts in your private registry, select Private Registry from the app menu in the top left. Then you can create collections, containers, Helm charts, models, and resources, as needed.
3.2.2.5. Switching Orgs or Teams After Logging into NGC#
This section describes switching to a different org or team after logging in.
In the top menu bar, click your user account icon. Then, select your org menu to expand the view to other available orgs. If you manage many orgs, you can use the search field to find the specific org you want to select. Click the org that you want to select.
Depending on the org or team you select, your current page can also refresh.
3.2.3. NGC API Keys#
NVIDIA NGC API keys are required to authenticate with NGC services using NGC CLI, Docker CLI, or direct API requests.
NGC provides two types of API keys:
Personal Keys
Any NGC org user can generate a personal key.
An NGC org user can grant a personal key up to the permissions assigned to them in the NGC org.
A personal key is linked to the user’s NGC org lifecycle.
If the user’s permissions change, the available permissions that can be or are assigned to the personal key also change.
If the user is removed from the NGC org, the key’s validity is revoked.
Supports updating permissions, rotation, and deletion (immediate revocation).
Org owners and user_admins can revoke any member’s key on demand.
Each user can generate up to eight personal keys.
Use personal keys to begin using NGC services within your sandbox. Personal keys are suited to individuals working on early development and testing code before moving to pre-production and production releases.
To authorize the services you have access to in the org and generate a personal key, go to Generating a Personal API Key.
Important
Use the legacy NGC API Key to authenticate with Base Command Platform, Fleet Command, or other NGC services that do not support “Personal key” authentication. For cross-org authorization, continue using the legacy NGC API Key. NVIDIA plans to deprecate the legacy NGC API key after 2025. NVIDIA encourages you to use the Personal Key, but if you need to continue using the legacy API key, go to Generating a Legacy NGC API Key to find out where to create a new one. Also, your current NGC API key will continue to work.
Service Keys
The lifecycle of service keys is linked to the NGC org account, not associated with an individual user.
Only NGC org owners and user_admins can manage service keys.
A service key can be scoped to access only the permissions and services required, or full access to the services enabled in the org.
Supports scoped permissions, updating permissions, on-demand revocation, rotation, and deletion.
An NGC org can have up to 64 service keys.
Use service keys when you require automated communication between machines and deploying to pre-production and production environments where you do not want to depend on a user’s membership status in the NGC org.
Note
Service keys currently do not support listing artifacts in NGC CLI or Docker CLI. This functionality will be added in the future. In the meantime, use a Personal API key to list artifacts.
Examples using NGC API Keys
Here are some examples of using NGC API keys to authenticate with NGC CLI and Docker CLI:
NGC CLI
$ ngc config set
Paste your key value at the API_KEY prompt:
[Enter API key [****API-Key]. Choices: [<VALID_APIKEY>]
Important
Always use the latest NGC CLI version to access the newest features, bug fixes, performance improvements, and security updates. Check for the latest versions at NGC CLI Installers or run ngc version list to view the latest releases, then upgrade using
ngc version upgrade
Docker CLI
docker login nvcr.io --username '$oauthtoken'
For the username, enter '$oauthtoken' exactly as shown. It is a special name that indicates that you authenticate with an API key. Paste your key value at the Password prompt.
3.2.3.1. Supported NGC Applications and API Key Types#
The following NVIDIA NGC applications and services support Personal and Service Keys.
NGC Application/Services |
Service Description |
|---|---|
NVIDIA NGC Catalog |
Grants your key permission to access or download containers and artifacts from the NGC Catalog. The permission level matches your account’s permissions for the catalog. |
NVIDIA NGC Private Registry |
The key is authorized to perform actions on your organization’s private registry service, such as pulling, retrieving, creating, or deleting containers and artifacts. The permission level assigned to the key matches the permission level of your user account. Therefore, your user account must have permissions for the Private Registry. |
NVIDIA Cloud Functions |
This authorization allows your key to perform actions on your organization’s cloud functions service. If your organization has private functions published by NVIDIA, or if your cloud functions service enables you to create, deploy, and run your own functions, your personal key has the same permissions as your user account for the cloud functions service. Therefore, it is important that your user account has the necessary permissions for Cloud Functions. |
NVIDIA Public API Endpoints |
Grants permission for your key to access NVIDIA NIM inference endpoints listed in the NVIDIA API Catalog. Therefore, your user account must have Public API Endpoints permissions. |
NVIDIA Secrets Manager |
Authorizes your key to perform actions on the NVIDIA Secrets Manager service, which is used to store and manage secrets. Your key has the same permission level as your user account, so your user account must possess Secrets Manager permissions. |
3.2.3.2. Generating NGC API Keys#
Generating API keys is essential for authenticating with NGC services using the NGC CLI, Docker CLI, or direct API requests.
3.2.3.2.1. Generating a Personal API Key#
Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.
Click your user account icon in the top-right corner and select Setup.
Click Generate API Key from the available options.
On the Setup > API Keys page, click + Generate Personal Key on the menu or the pane.
In the Generate Personal Key dialog, fill in the required information for your key.
Key Name: Enter a unique name for your key.
Expiration: Choose the expiration date for the key.
Services Included: Choose from the available services the key is permitted to access. Refer to Assigning Services to Your Personal API Key to learn more about each service and when to assign service access to your Personal Key.
Click Generate Personal Key when finished.
Your API key appears in the following dialog.
NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by selecting Copy Personal Key or using the copy icon to the right of the API key.
You can generate up to eight personal keys and manage them from the Setup > Personal Keys dashboard. To activate or deactivate a key, click the Active toggle. The Actions (ellipsis) menu allows you to rotate or delete a personal key.
3.2.3.2.1.1. Assigning Services to Your Personal API Key#
The services you can assign to a personal API key depend on two factors:
The services enabled for the NGC org where you generate the API key.
The service roles assigned to you by your NGC org owner or administrator.
For example, consider an NGC org with the following services enabled:
An NGC user account might have the following access roles assigned:
In this scenario, the NGC org has enabled NVIDIA Microservices, Private Registry, NVIDIA AI Enterprise, and Cloud Functions (NVCF). The user account has been granted access roles for all these services. Therefore, a personal API key can be generated with permissions to access one or all of them.
If a service is unavailable for assignment to the API key, the org owner or administrator has not granted you the necessary role for that service.
For details about each service listed above and its function, refer to the table Supported NGC Applications and API Key Types.
3.2.3.2.1.2. Generating a Legacy NGC API Key#
To generate a legacy API key, go to Setup > API Keys and click + Generate Legacy Key in the Legacy Keys drop-down.
In the Generate Legacy Key dialog, click + Generate Legacy Key.
3.2.3.2.2. Generating a Service API Key#
Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.
Select Organization from the user account menu on the upper right.
Select Service Keys on the organization dashboard.
On the Organization > Service Keys page, click + Create Service Key to create a key.
In the Create Service Key dialog, fill in the required configuration. Service keys currently support services such as NVIDIA NIM, NGC Catalog, and Private Registry. Assign scopes and resource permissions to the key.
In the Entity Type field, select from the available options to grant to the API key.
In the Scope field, choose from the available options.
Click Next Step to review your key configuration.
After you verify the configuration, click Confirm to generate your service key. Your service key appears in the next dialog.
NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by clicking the copy icon to the right of the API key or the Copy Service Key button.
Copy the key value before leaving this page. After you navigate away, the key value cannot be retrieved, and you must generate a new key to replace it. NGC supports multiple Service API keys, which are managed from the Organization > Service Keys dashboard.
To activate or deactivate a key, click the Active toggle. The Actions (ellipsis) menu allows you to rotate or delete a service key.
Note
When managing containers, ensure the scopes Get Container and Get Container list are assigned to your service key. For other types of artifacts, add the Get Artifact and Get Artifact list scopes. These scopes are the minimum required to discover the artifacts that need to be managed. Refer to the NGC Catalog User Guide and Private Registry User Guide for more information.
3.2.4. Managing Users and Teams in NGC#
This section applies to organization and team administrators, and explains the tasks that an organization or team administrator can perform from the NGC website.
When NVIDIA created the organization, it assigned an organization owner from the primary technical contact information provided during the sales process. This organization owner receives an email from NGC. As the NGC org owner for your organization, you can invite other users to join your organization’s NGC account. You can then assign users as members of teams within your organization. Teams are useful for keeping custom work private within the organization. You can also create other administrators in the organization to share that responsibility.
The general workflow for building teams of users is as follows:
The organization admin invites users to the organization’s NGC account.
The organization admin creates teams within the organization.
The organization admin adds users to appropriate teams, and typically assigns at least one user to be the team admin.
The organization or team admin can then add other users to the team.
3.2.4.1. NGC Registry User Roles#
Before adding users and teams, familiarize yourself with the following definitions of each role.
The NGC container registry supports the following user roles.
Organizational and Team Level Roles
The following roles can be assigned to a user.
Org Owner: This user is created at the time of Org creation. Up to two users can be assigned the Org Owner role at a given moment. This user can download, upload, push, pull, or delete artifacts, add or remove users, and create teams within an organization.
Registry Admin: This user can download, upload, push, pull, or delete artifacts within an organization or team.
Registry User: This user can download, upload, push, and pull artifacts within an organization or team.
Registry Read: This user can download and pull artifacts within an organization or team.
User Admin: This user can view and invite other users and user admins within an organization. At the team level, the User Admin can view and invite other users and user admins to that team. A User Admin can only grant roles that they possess.
User Read: This user can view details of an organization or team.
Note
A user must have a Registry Read, Registry User, or User Admin role to be a member of the organization or any team.
Capability |
Registry Admin |
Registry User |
User Admin |
Registry Read |
User Read |
|---|---|---|---|---|---|
Add teams |
X |
X |
✔ |
X |
X |
Add new users to orgs or teams |
X |
X |
✔ |
X |
X |
View users |
✔ |
X |
✔ |
X |
X |
Delete images |
✔ |
X |
X |
X |
X |
View or edit all image information using the UI and CLI |
✔ |
✔ |
X |
X |
X |
View all artifacts, namely containers, models, and resources |
✔ |
✔ |
✔ |
✔ |
X |
Download all artifacts, namely containers, models, and resources |
✔ |
✔ |
X |
✔ |
X |
Create and push or upload all artifacts, namely containers, models, and resources |
✔ |
✔ |
X |
X |
X |
3.2.4.2. Creating Teams#
Creating teams is useful for allowing users to share images within a team while keeping them invisible to other teams in the same organization. Only organization administrators can create teams.
To create a team:
Sign in to the NGC application.
Select Organization from the user account menu. From the dashboard or left navigation, select Teams. Then, click Create Team at the top of the screen.
Enter a team name and description, then click Create Team. Team names must be all lowercase.
3.2.4.3. Creating Users#
As the organization owner or user administrator, you must create user accounts to allow others to use the NGC container registry within the organization.
Sign in to the NGC application.
Click Organization from the user account menu. From the dashboard or left navigation, select Users. Then, click Invite User at the top right of the screen.
Fill out the Invite New User form for the new user as follows:
Enter the display name and email where indicated.
Select the organization or team to be assigned.
Select the roles to assign to the user.
Click Add Role and then click Invite User when done.
An invitation email is automatically sent to the user.
3.2.4.4. Adding a New User to a Team#
Org owners or org-level user administrators can add users to any team in the organization. Team user administrators can add users to their teams.
Sign in to the NGC application.
Click Organization from the user account menu. Select Teams from the left navigation, and then select the team that you want to add a user to.
On the Users page, click Invite New User.
In the Invite New User dialog, follow the steps in section Creating Users to fill out the add user form and invite the new user to the team. Confirm that the user is invited at the desired team context.
Users can be members of more than one team. To add a user to another team, repeat these steps for any additional teams.
3.2.4.5. Adding an Existing User to a Team#
Org owners or org-level user administrators can add users to any team in the organization. Team user administrators can add users to their teams.
Sign in to the NGC application.
Click Organization from the user account menu. From the dashboard or the left navigation, select Teams. Then, select the team that you want to add a user to.
On the Users page, click Add Existing User.
In the Find Existing User dialog, enter the name of the user you want to add.
Select the user and click Edit User.
On the user information page, assign the user to the desired team and roles. Click Add Role to save your changes.
Users can be members of more than one team. To add a user to another team, repeat these steps for any additional teams.
3.2.4.6. Changing User Roles#
You can change user assignments and roles for any users you create.
Sign in to the NGC application.
Select the org and team for which you want to change the user role. Click your user icon to select from the list of orgs, select an org, and if applicable, select a team.
Click Organization from the user account menu. Select Users from the left navigation. A list of all the users in the current registry space appears.
Select the user whose role you want to change. The User Information form appears.
Click Edit Membership.
A prompt appears for editing membership roles.
You can assign new roles, update and delete user roles, and click Add Role when done.
3.2.5. Introduction to the NGC Catalog and NGC CLIs#
Unified NGC and Enterprise Catalog
Note
The Enterprise Catalog, formerly a separate repository for NVIDIA AI Enterprise-supported software, is now integrated into the public NGC Catalog. NVIDIA AI Enterprise customers can access their exclusive software and features within the NGC Catalog using their active entitlements.
The NGC Catalog provides a centralized catalog of publicly available entities (for example, containers, models, and resources) alongside those that are part of products called entitled entities. You can search and filter across all entities.
You can view and download entitled entities by signing in to NGC. You can also download software with the NGC CLI using an API key. Access to all granted products remains when you switch org or team context. Unauthenticated users are prompted to log in or gain access to the product when they attempt to download gated features or entitled entities.
Publishers can publish and map entities to products. Access to entities is restricted by entity type, entity access type, user subscriptions, and roles. For entitled entities, guest users can convert to registered or subscribed status to access product-specific entities.
Introduction to NGC CLIs
The NGC CLIs are command-line interfaces for managing content within the NGC Registry. The CLI operates within a shell and lets you use scripts to automate commands.
NGC Catalog CLI
The NGC Catalog CLI is available to you if you have guest access to the NGC Registry, and with it, you can:
View a list of GPU-accelerated Docker container images, pretrained deep-learning models, and scripts for creating deep-learning models.
Download container images, models, and resources.
NGC Registry CLI
The NGC Registry CLI is available to you if you are logged in with your own NGC account or with an NGC Private Registry account, and with it, you can:
View a list of GPU-accelerated Docker containers available and detailed information about each image.
View a list of deep-learning models and resources and detailed information about them.
Download container images, models, and resources.
Upload container images, models, and resources.
Create and manage users and teams (available to NGC Private Registry administrators).
For more details and best practices, refer to the NGC CLI documentation page.
3.2.5.1. Installing NGC Registry CLI#
To install NGC Registry CLI:
Log in to your enterprise account on the NGC website.
In the top right corner, click your user account icon and select Setup, then click Downloads under CLI from the Setup page.
From the CLI Install page, click the Windows, Linux, or macOS tab, according to the platform from which you run NGC Registry CLI.
Follow the instructions to install the CLI.
Verify the installation by entering
ngc --version. The output should beNGC CLI x.y.zwhere x.y.z indicates the version.
3.2.5.2. Managing Users and Teams#
This section applies to the organization and team administrators.
As the NGC administrator for your organization, you can invite other users to join your organization’s NGC account. You can then assign users as members of teams within your organization. Teams are useful for keeping custom work private within the organization.
The general workflow for building teams of users is as follows:
The organization admin invites users to the organization’s NGC account.
The organization admin creates teams within the organization.
The organization admin adds users to appropriate teams, and typically assigns at least one user to be the team admin.
The organization or team admin can then add other users to the team.
3.2.5.2.1. Inviting Users to the Organization’s NGC Account#
Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)
Syntax
C:\> ngc org add-user <email> <name>
Example of adding John Smith (email: jsmith@example.com)
C:\> ngc org add-user jsmith@example.com "John Smith"
3.2.5.2.2. Creating Teams#
Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)
Syntax
C:\> ngc org add-team <name> <description>
Example of adding Team A
C:\> ngc org add-team team_a "Team A"
Team created.
----------------------------------------------------
Team Information
Id: 363
Name: team-a
Description: Team A
Deleted: False
----------------------------------------------------
3.2.5.2.3. Adding Users to Teams#
Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE) or Team Admin (REGISTRY_WRITE_TEAM_ADMIN_ROLE)
Syntax
C:\> ngc team add-user <email> <name>
Example of adding existing user John Smith to Team A as a regular user
C:\> ngc team add-user jsmith@example.com "John Smith" --team team-a --role REGISTRY_WRITE_USER_ROLE
Note
You do not need the --team argument if the target team is already set in your current NGC configuration.
3.2.5.2.4. Creating a Team and Adding a User in the Same Command#
Required Role: Org Admin (REGISTRY_WRITE_ADMIN_ROLE)
Syntax
C:\> ngc org add-user <email> <name> --team <name> --role <user-role>
Example of inviting new user John Smith to Team A as a team admin
C:\> ngc org add-user jsmith@example.com "John Smith" --team team-a --role REGISTRY_WRITE_TEAM_ADMIN_ROLE
Note
You do not need the --team argument if the target team is already set in your current NGC configuration.
3.2.5.2.4.1. User Roles and Permissions#
Role |
Service |
Access Levels |
|---|---|---|
ADMIN |
ACE |
READ, ADMIN, WRITE |
ADMIN |
CONTAINER |
READ, ADMIN, WRITE |
ADMIN |
DATASET |
READ, ADMIN, WRITE |
ADMIN |
HELM |
READ, ADMIN, WRITE |
ADMIN |
JOB |
READ, ADMIN, WRITE |
ADMIN |
MODEL |
READ, ADMIN, WRITE |
ADMIN |
MODELSCRIPT |
READ, ADMIN, WRITE |
ADMIN |
ORG |
READ, ADMIN, WRITE |
ADMIN |
TEAM |
READ, ADMIN, WRITE |
ADMIN |
USER |
READ, ADMIN, WRITE |
ADMIN |
WORKSPACE |
READ, ADMIN, WRITE |
EGX_ADMIN |
EGX |
READ, ADMIN, WRITE |
EGX_ADMIN |
ORG |
READ, ADMIN, WRITE |
EGX_ADMIN |
TEAM |
READ, ADMIN, WRITE |
EGX_ADMIN |
USER |
READ, ADMIN, WRITE |
EGX_READ |
EGX |
READ |
EGX_READ |
ORG |
READ |
EGX_READ |
TEAM |
READ |
EGX_USER |
EGX |
READ, WRITE |
EGX_USER |
ORG |
READ, WRITE |
EGX_USER |
TEAM |
READ, WRITE |
REGISTRY_READ |
CONTAINER |
READ |
REGISTRY_READ |
HELM |
READ |
REGISTRY_READ |
MODEL |
READ |
REGISTRY_READ |
MODELSCRIPT |
READ |
REGISTRY_READ |
ORG |
READ |
REGISTRY_READ |
TEAM |
READ |
REGISTRY_ADMIN |
CONTAINER |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
HELM |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
MODEL |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
MODELSCRIPT |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
ORG |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
TEAM |
READ, ADMIN, WRITE |
REGISTRY_ADMIN |
USER |
READ, ADMIN, WRITE |
REGISTRY_USER |
CONTAINER |
READ, WRITE |
REGISTRY_USER |
HELM |
READ, WRITE |
REGISTRY_USER |
MODEL |
READ, WRITE |
REGISTRY_USER |
MODELSCRIPT |
READ, WRITE |
REGISTRY_USER |
ORG |
READ, WRITE |
REGISTRY_USER |
TEAM |
READ, WRITE |
USER_ADMIN |
CONTAINER |
READ, ADMIN, WRITE |
USER_ADMIN |
HELM |
READ, ADMIN, WRITE |
USER_ADMIN |
MODEL |
READ, ADMIN, WRITE |
USER_ADMIN |
MODELSCRIPT |
READ, ADMIN, WRITE |
USER_ADMIN |
ORG |
READ, ADMIN, WRITE |
USER_ADMIN |
TEAM |
READ, ADMIN, WRITE |
USER_ADMIN |
USER |
READ, ADMIN, WRITE |
USER |
ACE |
READ, WRITE |
USER |
CONTAINER |
READ, WRITE |
USER |
DATASET |
READ, WRITE |
USER |
HELM |
READ, WRITE |
USER |
JOB |
READ, WRITE |
USER |
MODEL |
READ, WRITE |
USER |
MODELSCRIPT |
READ, WRITE |
USER |
ORG |
READ, WRITE |
USER |
TEAM |
READ, WRITE |
USER |
WORKSPACE |
READ, WRITE |
3.3. Docker Containers#
Software containers simplify deployment of data center applications at scale. Containers encapsulate an application along with its libraries and other dependencies to provide reproducible and reliable execution of applications and services without the overhead of a full virtual machine.
GPU support within Docker containers enables GPU-based applications that are portable across multiple machines, similar to how Docker® enables CPU-based applications to be deployed across multiple machines.
Docker container: A Docker container is an instance of a Docker image. A Docker container deploys a single application or service per container.
Docker image: A Docker image is the software (including the filesystem and parameters) that you run within an NVIDIA Docker container.
3.3.1. What Is A Docker Container?#
A Docker container bundles a Linux application with all of its libraries, data files, and environment variables so that the execution environment is always the same. The environment stays the same on whatever Linux system it runs and between instances on the same host.
Unlike a VM, which has its own isolated kernel, containers use the host system kernel. Therefore, all kernel calls from the container are handled by the host system kernel. DGX™ systems use Docker containers as the mechanism for deploying deep learning frameworks.
A Docker container is the running instance of a Docker image.
3.3.2. Why Use A Container?#
You can install your application, dependencies, and environment variables one time into the container image, rather than on each system you run on. Key benefits of using containers also include:
There is no risk of conflict with libraries that are installed by others.
Containers allow use of multiple different deep learning frameworks, which can have conflicting software dependencies, on the same server.
After you build your application into a container, you can run it on other systems, especially servers, without having to install any software.
Legacy accelerated compute applications can be containerized and deployed on newer systems, on premises, or in the cloud.
Specific GPU resources can be allocated to a container for isolation and better performance.
You can share, collaborate, and test applications across different environments.
Multiple instances of a given deep learning framework can be run concurrently with each having one or more specific GPUs assigned.
Containers can resolve network-port conflicts between applications by mapping container-ports to specific externally-visible ports when launching the container.
3.3.3. Using NGC Container Registry from the Docker Command Line#
3.3.3.1. Accessing the NGC Container Registry#
You can access the NGC container registry by running a Docker command from your client computer. You are not limited to using your NVIDIA DGX platform to access the NGC container registry. You can use any Linux computer with internet access on which Docker is installed.
Before accessing the NGC container registry, ensure that the following prerequisites are met:
Your NGC account is activated.
You have an NGC API key for authenticating your access to NGC container registry. For more information, refer to Generating NGC API Keys.
You are logged in to your client computer as an administrator user.
An alternate approach for enabling other users to run containers without giving them sudo privilege, and without having to type sudo before each docker command, is to add each user to the docker group, with the command:
sudo usermod -aG docker $USER
Note
While this approach is more convenient and commonly used, it is less secure because any user who can send commands to the docker engine can escalate privilege and run root level operations. If you choose to use this method, only add users to the docker group who you would trust with root privileges.
Log in to the NGC container registry.
docker login nvcr.io
When prompted for your username, enter the following text:
$oauthtokenThe
$oauthtokenusername is a special username that indicates that you authenticate with an API key and not a username and password.When prompted for your password, enter your NGC API key as shown in the following example.
Username: $oauthtoken Password: my-api-key
Tip
When you get your API key (refer to Generating NGC API Keys), copy it to the clipboard so that you can paste the API key into the command shell when you are prompted for your password.
Note
The three steps above can be combined into a single command for convenience:
docker login -u \$oauthtoken -p $NGC_API_KEY nvcr.io
3.3.3.2. Uploading an NVIDIA Container Image onto Your System#
No container images are preloaded onto a DGX system. Instead, containers are available for download from the NGC container registry. NVIDIA has provided a number of containers for download from the NGC container registry. If your organization has provided you with access to any custom containers, you can download those as well.
Before loading an NGC container image, ensure that the following prerequisites are met:
You have read access to the registry space that contains the container image.
You are logged in to
nvcr.io(refer to Accessing the NGC Container Registry).
Tip
To browse the available containers in the NGC container registry, use a web browser to log in to your NGC account on the NGC website.
Run the command to download the container that you want from the registry.
sudo docker pull registry/registry-space/repository:tag
registry: The URL of the container registry, which for the NGC container registry is
nvcr.io.registry-space: The name of the space within the registry that contains the container. For example,
nvidiais the registry space for containers provided by NVIDIA.repository: Repositories are collections of containers of the same name, but distinguished from each other by their tags. This value is the main container name.
tag: A tag that identifies the version of the container.
To confirm that the container was downloaded, list the Docker images on your system.
sudo docker images
The following are several examples of pulling container images.
Example of pulling
tensorflow:18.06-py3from thenvidiaregistry space.
~$ sudo docker pull nvcr.io/nvidia/tensorflow:18.06-py3
Example of pulling a custom container image tagged
v2.0from theacmeorganization registry space.
~$ sudo docker pull nvcr.io/acme/custom-image:v2.0
Example of pulling a custom container image tagged
v2.0from theacme/teamteam registry space.
~$ sudo docker pull nvcr.io/acme/zoom/custom-image:v2.0
3.3.3.3. Tagging and Pushing a Container Image#
You can upload custom images to the registry if you have write access to the registry space. Uploading a container image involves first tagging the image and then pushing the image to the registry space.
In the following examples, you are a member of the Acme (mxa8oi8djw7m) organization and the Zoom team within the Acme organization. Refer to Joining an Org as Org Owner for how to find your org name.
Tagging Example
This example tags a local container image
mycaffein themxa8oi8djw7m/zoomteam space withv1.5.~$ sudo docker tag mycaffe nvcr.io/mxa8oi8djw7m/zoom/mycaffe:v1.5
Pushing Example
This example pushes version
v1.5of themycaffelocal container image to themxa8oi8djw7m/zoomteam space:~$ sudo docker push nvcr.io/mxa8oi8djw7m/zoom/mycaffe:v1.5
3.3.4. Using the Container Registry#
The ngc registry image commands let you access ready-to-use GPU-accelerated container images from the registry.
3.3.4.1. Viewing Container Image Information#
There are several commands for viewing information about available container images.
To list container images:
C:\>ngc registry image list
+-------------+-------------+-------------+------------+---------+------------+
| Name | Repository | Latest Tag | Image Size | Updated | Permission |
| | | | | Date | |
+-------------+-------------+-------------+------------+---------+------------+
| BigDFT | hpc/bigdft | cuda10-ubun | 2.37 GB | Oct 18, | unlocked |
| | | tu1804-ompi | | 2019 | |
| | | 4-mkl | | | |
| CANDLE | hpc/candle | 20180326 | 1.52 GB | Oct 18, | unlocked |
| | | | | 2019 | |
...
“Unlocked” permissions indicate images that do not require an API key to access.
To view detailed information about a specific image, specify the image and the tag.
Example:
C:\>ngc registry image info nvidia/caffe:19.02-py2
--------------------------------------------------
Image Information
Name: nvidia/caffe:19.02-py2
Architecture: amd64
Schema Version: 1
--------------------------------------------------
3.3.4.2. Pulling a Container Image#
With the NGC Registry CLI you can pull (download) images to your system.
To pull an image to your registry space, specify the image and, optionally, the tag.
C:\>ngc registry image pull <image-name>[:<tag>]
If a tag is not specified, then the tag latest is used.
3.3.4.3. Pushing a Container Image#
With the NGC Registry CLI you can push (upload) images to your registry space.
To push an image to your registry space, specify the image and, optionally, the tag.
C:\>ngc registry image push <image-name>[:<tag>]
If a tag is not specified, then the tag latest is used.
3.3.4.4. Removing a Container Image#
With the NGC Registry CLI you can remove images that are no longer needed from your registry space.
To remove all versions of an image, specify the image.
C:\>ngc registry image remove <image-name>
To remove a specific image version, specify the image and tag.
C:\>ngc registry image remove <image-name>:<tag>
3.3.5. Updating Container Metadata#
You can find best practices on how to fill out the metadata for your container in the Product Page Guidelines.
3.3.5.1. Updating Container Metadata Via the NGC Website#
Use the following steps to update the container metadata using the NGC website.
Click the vertical ellipsis in the upper-right corner of your container product page to reveal the entity action menu.
Select Edit Details from the entity action menu.
Update the container description and all other container metadata as needed.
To save your changes, click the vertical ellipsis again to reveal the entity action menu and select Save.
3.3.5.2. Updating Container Metadata Using the NGC CLI#
With the NGC Registry CLI you can update the container description and all the other container metadata.
To update container metadata, use the following command.
ngc registry image update [--ace <name>] [--built-by <name>] [--debug]
[--desc <desc>] [--format_type <fmt>]
[--label <label>] [--logo <url>] [--org <name>]
[--overview <file.md>] [--publisher <publisher>]
[--team <name>] [-h]
<image>[:<tag>]
Specify a named argument (field to update, and values to update the field) as well as a positional argument (name of the container image and, optionally, tag).
Positional Arguments
<image>[:<tag>]: Name of the image repository or tagged image,<image>[:<tag>]
Named Arguments
--debug: Enable debug mode.--format_type: Possible choices: ascii, csv, json. Specify the output format type. Supported formats are: [‘ascii’, ‘csv’, ‘json’]. Only commands that produce tabular data support csv format. Default: ascii.--org: Specify the organization name. Use “–org no-org” to override other sources and specify no org. Default: current configuration.--ace: Specify the ACE name. Use “–ace no-ace” to override other sources and specify no ACE. Default: current configuration.--team: Specify the team name. Use “–team no-team” to override other sources and specify no team. Default: current configuration.--desc: Description for the target image.--overview: Documentation (text or markdown file) for the image.--label: A label to describe the repository. Can be used multiple times.--logo: A URL pointing to the logo for the repository.--publisher: The person or entity publishing the image.--built-by: The person who built the container image. Specify the image and, optionally, the tag.
Example: Changing Description of a Container Image
To view the existing container metadata use the following command.
$ ngc registry image info nvidia/testcontainer
--------------------------------------------------
Image Repository Information
Name: testcontainer
Short Description: Test description.
Built By: Kristina
Publisher: NVIDIA
Logo: www.logo.com/logo.png
Labels: Machine Learning, Classification, Retail
Public: No
Last Updated: May 8, 2020
Latest Image Size: 60.27 MB
Latest Tag: 3.0
Tags:
3.0
2.0
1.0
--------------------------------------------------
Update the container description with the following command.
$ ngc registry image update --desc "A test container image with useful tools." nvidia/testcontainer
--------------------------------------------------
Updating repository metadata
Repository metadata updated.
To confirm that the update succeeded, run the info command again.
$ ngc registry image info nvidia/testcontainer
--------------------------------------------------
Image Repository Information
Name: testcontainer
Short Description: A test container image with useful tools.
Built By: Kristina
Publisher: NVIDIA
Logo: www.logo.com/logo.png
Labels: Machine Learning, Classification, Retail
Public: No
Last Updated: May 8, 2020
Latest Image Size: 60.27 MB
Latest Tag: 3.0
Tags:
3.0
2.0
1.0
--------------------------------------------------
$ ngc registry image update Command Overview
3.3.6. Multi-Architecture Support for NGC Container Images#
When running an image, Docker automatically selects an image variant that matches your OS and architecture.
NGC Container Registry supports Docker multi-architecture images. A single image can contain variants for different architectures, such as ARM, x86, Power, and others, and sometimes for different operating systems, such as Windows.
Manifest Lists and Tags
NGC Container Registry supports the manifest list schema application/vnd.docker.distribution.manifest.list.v2+json, which provides the ability to assign multiple tags per image. For instructions to inspect a manifest list, refer to the Docker manifest V2, Schema 2 specification.
The NGC UI lets you navigate through the supported architectures.
3.3.7. Using OCI 1.1.1 Referrers in NGC Private Registry#
3.3.7.1. Overview#
NGC Private Registry supports Open Container Initiative (OCI) 1.1.1 Referrers on nvcr.io.
Use this feature to attach and discover artifacts such as software bills of materials (SBOMs), Vulnerability Exploitability eXchange (VEX) documents, signatures, provenance, and attestations by image digest.
The registry stores and discovers the artifact.
Use your OCI or security tool to create, attach, discover, and verify it.
For this release, use an open source command-line interface (CLI) that supports the OCI Referrers API, such as OCI Registry As Storage (ORAS) or Cosign, or use the registry API.
Dedicated NGC CLI and UI referrer views are not available.
3.3.7.2. Before You Begin#
Before you begin, ensure that you meet the following requirements.
An NGC account and an active Personal Key or Service Key with access to the target repository.
Repository permission to discover or publish artifacts, as required.
ORAS with OCI 1.1 Referrers support.
For account setup, keys, permissions, and repository naming, refer to Getting Started, NGC API Keys, NGC Registry User Roles, and Tagging and Pushing a Container Image.
3.3.7.3. Authenticate to the NGC Private Registry#
Authenticate with the special username '$oauthtoken' and pass your NGC key through standard input.
export NGC_API_KEY='<your-ngc-api-key>'
printf '%s' "$NGC_API_KEY" | oras login nvcr.io \
--username '$oauthtoken' --password-stdin
Follow your organization’s credential storage policy and remove credentials from shared build agents after use.
3.3.7.3.1. Set the Subject Reference#
Set the subject reference using a tag or digest.
The ORAS attach and discover commands accept both forms.
SUBJECT_REF='nvcr.io/<org>/<team>/<repository>:<tag>'
For an organization-level repository, omit the <team>/ segment.
To target an immutable subject, use a digest-qualified reference such as SUBJECT_REF='nvcr.io/<org>/<team>/<repository>@sha256:<64-hex-character-digest>'.
When using a digest-qualified reference, NGC supports only SHA-256 digests.
3.3.7.6. Use the Referrers API Directly#
Use the HTTP endpoint only for client integration or troubleshooting.
Unlike the ORAS commands, the Referrers API path requires a subject digest.
If you started with a tag, resolve it with oras resolve "$SUBJECT_REF".
Obtain a scoped registry bearer token through the standard authentication challenge.
3.3.7.6.1. Request#
Send a request in the following format.
GET /v2/<org>/<team>/<repository>/referrers/<subject-digest> HTTP/1.1
Host: nvcr.io
Accept: application/vnd.oci.image.index.v1+json
Authorization: Bearer <scoped-registry-token>
To filter by artifact type, use the following request path.
GET /v2/<org>/<team>/<repository>/referrers/<subject-digest>?artifactType=<URL-Encoded Value>
3.3.7.6.2. Response#
A successful request returns 200 OK and an OCI image index.
An empty manifests array is valid.
When you use artifactType, confirm that the OCI-Filters-Applied response header is set.
3.3.7.7. Important Behavior#
Keep the following behavior in mind.
Keep the referrer and subject in the same repository. The ORAS
attachanddiscovercommands can use a tag or digest, and the relationship is recorded against the resolved digest. NGC Private Registry supports only SHA-256 digests. For multi-architecture images, the index and each child manifest have different digests.A native relationship is created only when the referring object is an OCI image manifest or OCI image index with a valid
subjectfield. The referenced subject does not need to exist when the referrer is pushed, so you can push the subject and its referrers in either order.Deleting a subject does not delete its referrers. Deleting a referrer removes it from discovery results.
A subject supports up to 64 distinct referrers. Remove obsolete referrers before retrying at the limit.
Existing valid fallback referrer indexes remain readable and are de-duplicated in discovery results. Use
oras discover "$SUBJECT_REF"with either the subject tag or digest. The direct Referrers API requires the subject digest. Fallback tags cannot be created or updated.Existing tag-based workflows for signing and verifying image signatures (
.sig), attaching and retrieving SBOMs (.sbom), and publishing and retrieving VEX documents (.vex) continue to work, but the Referrers API does not return subjectless artifacts.Use
oras copy -rto copy a subject with its referrers.
3.3.7.8. Troubleshooting the Referrers API#
Use the following table to troubleshoot the Referrers API.
Symptom |
Likely Cause |
What to Do |
|---|---|---|
|
The key is missing, expired, revoked, or incorrectly supplied. |
Log in again with |
|
The identity does not have access to the organization, team, or repository. |
Confirm the selected NGC org and team, and request the required read or write role. |
|
The digest syntax is invalid, or a parameter is malformed. |
Use a SHA-256 digest in the form |
|
No referrers match the subject digest or requested type. |
Resolve the tag again, remove the filter, and compare the subject digest used when the evidence was attached. |
Copied subject has no evidence |
The copy operation did not traverse referrers. |
Use recursive referrer-aware copy, and compare discovery results at the source and destination. |
3.4. NGC Models#
The NGC private registry lets you upload and access deep-learning models.
3.4.1. Creating New NGC Models Using the NGC CLI#
Issue ngc registry model create -h to display a description of available options and command descriptions for creating a model.
This example creates a new model called “Final Review Model” with all required and optional arguments used:
$ ngc registry model create \
--application OBJECT_DETECTION \
--format "cpkt" \
--framework TensorFlow\
--precision FP16 \
--short-desc "A model for object detection using TensorFlow" \
--built-by "My Name" \
--display-name "Final Review Model" \
--label "fast" --label "sparkly" \
--owner-name "MyTeam" \
--overview-filename /path/to/my/overview/file.md \
--publisher "NVIDIA MyTeam" \
--public-dataset-license <license> \
--public-dataset-link "www.example.com" \
--public-dataset-name "200_10x200_images" \
nvidia/myteam/final_review_model
3.4.2. Creating a New Model Using the NGC Website#
To create a new model asset, select Private Registry from the app menu in the top left. Then, select Models from the left navigation menu. Click Create Model on the top right of the page.
The Create Model page walks you through the process of creating a new model asset.
After you complete and submit this form, you have the option of creating a model version. You can skip this step and complete it later. Refer to Uploading an NGC Model Version Using the NGC Website for more information.
Field |
Validation |
Description |
Options |
|---|---|---|---|
Name |
String |
The name of the model |
|
Publisher |
String |
The name of the individual who owns the asset (dropdown) |
|
Description |
String |
Short description of the model |
|
Overview |
Markdown (String) |
A place to share more details/usage instructions for the model |
|
Labels |
String (List) |
Tags to make the asset more discoverable |
|
Use Case |
String |
Intended use case |
Annotation, Automatic Speech Recognition, Image Classification, Image Segmentation, Image Synthesis, Natural Language Processing, Object Detection, Translation |
Framework |
String |
Deep learning framework used to build the model |
Caffe, Clara, NeMo/PyTorch, PyTorch, TensorFlow, TensorRT, Transfer Learning Toolkit |
Model Format |
String |
Output format of the weights file |
caffemodel, HDF5, ONNX, protobuf, PyTorch PTH, SavedModel, TensorFlow CKPT, TensorRT Plan, TLT |
Precision |
String |
Training precision used |
AMP, FP16, FP32, INT8 |
3.4.3. Uploading a New NGC Model Version Using the NGC CLI#
Issue ngc registry model upload-version -h to display a description of available options and command descriptions for uploading a model version. If the command terminates or fails, rerunning the same command automatically resumes from the last checkpoint.
An example using all required and optional arguments to create model version 1 for the model created in the previous section.
$ ngc registry model upload-version \
--accuracy-reached 96.5 \
--batch-size 2000 \
--gpu-model "V100" \
--memory-footprint 4GB \
--num-epochs 100 \
--desc "A new and exciting version: 1" \
--link "www.example.com/model/v1" \
--link-type Other \
--owner-name "My Name" \
--source path/to/my/model/version/dir \
nvidia/myteam/final_review_model:1
Adding Custom Metrics
You can also upload custom metrics tables for each model version. Each table can hold up to 12 key-value attribute pairs. Three tables maximum per model version.
Metrics tables are defined as JSON tables - one table per file. You can add the table to the upload with --metrics-file.
Some example metrics files:
zeppelin_table.json:
{
"name": "ZeppelinTable",
"attributes": [
{"key": "Robert", "value": "Plant"},
{"key": "Jimmy", "value": "Page"},
{"key": "John", "value": "Bonham"},
{"key": "John", "value": "Paul Jones"}
]
}
rhcp_table.json:
{
"name": "RHCPTable",
"attributes": [
{"key": "Anthony", "value": "Keidis"},
{"key": "Michael", "value": "Balzary"},
{"key": "John", "value": "Frusciante"},
{"key": "Chad", "value": "Smith"}
]
}
The above example with custom metrics tables included:
$ ngc registry model upload-version \
--accuracy-reached 95.5 \
--batch-size 2000 \
--gpu-model "SomeGPUModel" \
--memory-footprint 4GB \
--num-epochs 100 \
--desc "A new and exciting version: 1" \
--link "www.example.com/model/v1" \
--link-type Other \
--owner-name "My Name" \
--metrics-file zeppelin_table.json \
--metrics-file rhcp_table.json \
--source path/to/my/model/version/dir \
nvidia/myteam/final_review_model:1
3.4.4. Uploading an NGC Model Version Using the NGC Website#
There are two ways to upload a new version of a model using the NGC website.
From the Model Creation page discussed above
From the Model Details page for any model
From the version creation page, shown below, you can specify all the relevant information about the specific version that you are uploading. You can also upload files directly from your browser.
After you complete the form and upload any relevant files, submitting publishes the new version of the content.
Adding Custom Metrics
As deep learning models evolve, you might also want to convey different information to distinguish between different versions. Using the NGC Model Registry, you can specify up to 36 different metrics to help people find the right versions.
When creating your version, click Add Custom Metrics to create the tables.
Model Name - String - The name of the model for which you want to upload a version
Owner - String - The name of the individual who owns the asset (dropdown)
Version - String - A way of identifying that version (use semantic versioning)
Overview - Markdown - A place to share more details/usage instructions for the model (shared across all versions)
Number of Epochs - String - Number of Epochs trained (or N/A)
Batch Size - String - Training Batch Size (or N/A)
GPU Model - Drop Down - GPU family used for training
Accuracy Reached - String - Accuracy of the model (or N/A)
Memory Footprint - String - Memory Footprint used by the model
Related Resources - You can optionally specify additional resources for your model
Link Text - Drop Down - The text to display for additional resources, such as containers or code samples, to accompany your version.
URL - String - The URL of the additional resource
After you enter the key/value pairs, select Add Table.
3.4.5. Editing NGC Model Information Using the NGC CLI#
Issue ngc registry model update -h to display a description of available options and command descriptions for editing a model or model version.
An example updating a model’s overview file for a model.
$ ngc registry model update \
--overview-filename "path/to/my/updated/overview/file.md" \
nvidia/myteam/final_review_model
An example updating a model-version’s accuracy reached and memory footprint.
$ ngc registry model update \
--accuracy-reached 96.5 \
--memory-footprint 16GB \
nvidia/myteam/final_review_model:1
Common Model Commands:
ngc registry model info nvidia/model-name- show information about a modelngc registry model info nvidia/model-name:version- show information about a model versionngc registry model list- list available modelsngc registry model download-version nvidia/model-name:version- download the specified model-versionngc registry model remove nvidia/model-name:version- remove a model-versionngc registry model remove nvidia/model-name- remove a model
3.4.6. Editing NGC Model Information Using the NGC Website#
To edit a model’s metadata or overview tab, select Edit from the top right of the model details page.
You can then edit any of the model’s details, or delete the model.
3.4.7. Cloning NGC Model Version Using the NGC Website#
Use the NGC website to create a new version of an existing model by cloning it.
Cloning a model version creates a new version based on an existing one, allowing you to make modifications while preserving the original version. The NGC UI provides two methods to clone a model version:
Method 1: Clone from Entity Creation Page
Navigate to the Entity Creation page.
Select Create Model.
Choose Clone Version from the available options.
Select the model version you want to clone from the list of available models.
Method 2: Clone from Model Details Page
Navigate to the Model Details page.
Select the Version History tab.
Click Clone Version for the desired model version.
On the Clone Version page, you can:
Specify version information and metadata
Remove files from the existing version
Upload new files directly from your browser
After completing the form and uploading any necessary files, click Submit to create the new cloned version of the model.
3.4.8. Creating a New NGC Model Version Using the NGC CLI#
You can create a new version of an existing model using the NGC CLI.
The NGC CLI provides a command-line interface for creating new model versions. This method is useful for automation and batch processing.
Use the upload-version command
The basic syntax for creating a new version is:
ngc registry model upload-version <model-name>:<new-version> --base-version <base-version> --source <source-directory>
Where:
<model-name>is the name of your model (for example,nvidia/hp_test)<new-version>is the version tag for the new version (for example,v2)<base-version>is the version you want to base the new version on (for example,v1)<source-directory>is the path to the directory containing your new version files
Example: Creating version v2 from base version v1
To create a new version v2 based on version v1, using files from the ./src directory:
ngc registry model upload-version nvidia/hp_test:v2 --base-version v1 --source ./src
3.4.9. Customer Managed Keys#
Customer Managed Keys (CMK) provide an additional layer of security for models and containers within the NGC Private Registry.
Although NGC artifacts are already encrypted at rest with unique NGC keys, Customer Managed Keys let you add an additional layer of encryption using your organization’s key for stronger privacy control. With CMKs, you control the cryptographic keys, so if you revoke access to a key, associated models and containers become unreadable.
You can create CMKs using the NGC CLI or the NGC Private Registry UI on the model creation page.
3.4.9.1. Using Customer Managed Keys via the NGC CLI#
This section provides CLI commands to manage and use Customer Managed Keys (CMK) for model encryption in the NGC Private Registry.
Note
Before you begin, ensure that you have NGC CLI (version 4.3.0 or later) installed and configured for your organization.
3.4.9.1.1. Managing Encryption Keys#
You can create an encryption key at the time of model creation to auto-generate a new CMK. You can also list, view, and delete encryption keys within your organization or team namespace.
3.4.9.1.1.1. Create a New Encryption Key#
This command generates a new encryption key at the time of model creation.
Command
$ ngc registry model create <model> --encryption-key-description <key_description> --framework <model_framework> --application <model_application> --format <model_format> --precision <model_precision> --short-desc <model_description>
Example
3.4.9.1.1.2. Link an Existing Encryption Key#
This command links an existing encryption key to a model at creation time.
Command
$ ngc registry model create <model> --encryption-key-id <org_and_team_scoped_key> --framework <model_framework> --application <model_application> --format <model_format> --precision <model_precision> --short-desc <model-description>
3.4.9.1.1.3. List Encryption Keys#
This command lists all available encryption keys in your configured organization and (optionally) team.
Command
$ ngc registry encryption-key list
Example
3.4.9.1.2. Using Encryption Keys with Models#
You can view which models are associated with an encryption key, and how to find the encryption key associated with a model.
3.4.9.1.2.1. View Key and Associated Models#
This command displays information about the encryption key, including its ID, description, and associated models.
Command
$ ngc registry encryption-key info <encryption_key_target>
Example
$ ngc registry encryption-key info my-org/12345678-4321-abcd-efg1-12345abcde67
Output
Encryption Key Details:
Encryption Key: my-org/12345678-4321-abcd-efg1-12345abcde67
Associated Artifacts:
MODEL:
my-org/research/confidential-llm Here is a short description about confidential-llm
3.4.9.1.2.2. View Associated Key for a Model#
This command checks a model’s information to determine which encryption key, if any, is associated with it. The encryption key ID is listed in the output.
Command
$ ngc registry model info <org>/[team/]<model_name>
Example
$ ngc registry model info my-org/research/confidential-llm
Output
Model Information:
Name: confidential-llm
Application: NATURAL_LANGUAGE_PROCESSING
Framework: other
Model Format: other
Precision: other
Short Description: Here is a short description about confidential-llm
Display Name:
Logo:
Org: my-org
Team: research
Built By:
Publisher:
Created Date: 2025-09-19T23:20:24.674Z
Updated Date: 2025-09-19T23:20:24.674Z
Has Signed Version: False
Access Type:
Associated Products:
Labels
Latest Version ID:
Latest Version Size (bytes): 0
Public Dataset Used
Name:
Link:
License:
Encryption Key
ID: 12345678-4321-abcd-efg1-12345abcde67
3.4.9.1.3. Revoking Access to Models#
To revoke access, either disassociate the encryption key from a specific model or delete the key to remove access from all associated models. Both actions are irreversible and run asynchronously.
3.4.9.1.3.1. Disassociate Key from Model#
This command revokes access to all versions of a single model by removing the model’s association with its encryption key. This is a one-time, irreversible action. You must create a new model and associate a new or existing CMK to restore access. For more information, refer to Managing Encryption Keys.
Command
$ ngc registry encryption-key disassociate --model <org>/[team/]<model_name> --no-wait
Example
$ ngc registry encryption-key disassociate --model my-org/research/confidential-llm --no-wait
The --no-wait flag initiates the background task and immediately returns a status URL.
Output
Are you sure you would like to remove model my-org/research/confidential-llm? [y/n]y
+---------------+--------------------+-----------+------------------------+---------+
| Artifact Type | Artifact Name | Status | Status URL | Message |
+---------------+--------------------+-----------+------------------------+---------+
| model | my-org/research/ | completed | /v2/artifact-registry/ | |
| |confidential-llmm | | org/m8sc4demnvoe/workf | |
| | | | lows/org-my-org-team- | |
| | | | research-12345678-4321 | |
| | | | -abcd-efg1-12345abcde | |
| | | | 67-model-confidential- | |
| | | | llm-disassociate | |
+---------------+--------------------+-----------+------------------------+---------+
3.4.9.1.3.2. Delete an Encryption Key#
This command deletes an encryption key and revokes access to all associated models.
Warning
This is a destructive and irreversible action. Deleting a key revokes access to all associated models; they are permanently deleted within 24 hours.
Command
$ ngc registry encryption-key remove <key_id> --no-wait
Example
$ ngc registry encryption-key remove my-org/12345678-4321-abcd-efg1-12345abcde67 --no-wait
Output
+-----------------------------+-----------+------------------------------+---------+
| Encryption Key | Status | Status URL | Message |
+-----------------------------+-----------+------------------------------+---------+
| my-org/12345678-4321- | completed | /v2/artifact-registry/org/my | |
| abcd-efg1-12345abcde67 | | -org/workflows/org-my-org | |
| | | -12345678-4321-abcd-efg1- | |
| | | 12345abcde67-delete | |
+-----------------------------+-----------+------------------------------+---------+
3.4.9.1.3.3. Check Operation Status#
Since disassociation and deletion are asynchronous, you can use the status URL returned by the commands to check the progress of the workflow. The command will return a status of IN_PROGRESS, COMPLETED, or FAILED.
Command
$ ngc registry encryption-key status <status_url>
Example
$ ngc registry encryption-key status "/v2/artifact-registry/org/my-org/workflows/org-my-org-MODEL-4b7c04a4-delete"
3.4.9.2. Using Customer Managed Keys via the Private Registry UI#
3.4.9.2.1. Creating an Encryption Key#
You can add a CMK to a new model using the Entity Creation Hub UI.
Ensure your organization is enabled for Customer Managed Keys.
Sign in to the Private Registry. On the Entity Creation Hub page, select Create Model under Create a Model.
Fill in the required fields on the Create Model form. In the Encryption Key section, select the Link Customer Managed Encryption Key option.
Choose one of the following options to add a CMK to the model:
Existing key: Select an existing customer-managed encryption key.
New key: Create a new customer-managed encryption key.
If you choose to create a new key, select Create a new Customer Managed Encryption Key and add a short description.
After creating the model, the encryption key appears in the left details pane on the model page.
If you choose to add an existing encryption key, select a key from the list of available keys.
After creating the model, the selected key appears in the left details pane on the model page.
3.4.9.2.2. Unlinking the Encryption Key#
You can remove the association between an encryption key and a model from the Private Registry models page. Removing an encryption key from a model deletes the associated model. This action is irreversible.
There are two ways to unlink an encryption key from a model:
Unlink the key from a model on the model details page.
Unlink the key from the Models > Customer Managed Encryption Keys list page to remove it from the associated model.
3.4.9.2.2.1. Unlink a Key from a Model (Model Details Page)#
On the model details page, select Unlink Key from the … (ellipsis) action menu.
A confirmation dialog appears similar to the following.
Confirm the unlink action by selecting the checkbox and clicking Unlink Key & Delete Model.
A message appears in the left pane indicating that the unlink operation is in progress. Wait for the operation to complete.
After the operation completes, the key is unlinked from the model and the model is deleted.
3.4.9.2.2.2. Unlink a Key from a Model (Encryption Key List)#
All your encryption keys are listed in the Models > Customer Managed Encryption Keys tab.
Click a key to view all linked models.
Each key can be linked to multiple models or none at all.
On the Customer Managed Encryption Keys list page, select the … (ellipsis) action menu for the associated model and choose Unlink Key.
A confirmation dialog appears similar to the following.
Confirm the unlink action by selecting the checkbox and clicking Unlink Key & Delete Model.
A message appears indicating that the unlink operation is in progress. Wait for the operation to complete.
After the operation completes, the key is unlinked from the model and the model is deleted.
3.4.9.2.3. Revoking the Encryption Key#
You can revoke access to an encryption key and all associated models by deleting the key.
Warning
Revoking an encryption key deletes the key and all associated models. This action is irreversible.
In the Models > Customer Managed Encryption Keys tab, select the … (ellipsis) action menu for the key and choose Revoke Key.
A confirmation dialog appears similar to the following.
Confirm the revoke action by selecting the checkbox and clicking Revoke Key & Delete Models.
A message appears next to the key indicating that the revoke operation is in progress. Wait for the operation to complete.
After the operation completes, the models and the key (in this example,
Test-key) are deleted.
3.5. NGC Resources#
The NGC private registry lets you upload and access resources for deep-learning models.
3.5.1. Before You Begin#
With the NGC Registry CLI you can update the container description and all the other container metadata.
Confirm your context, or which org and team you are logged in to. This determines which registry space your model is uploaded to. You can do this by entering the following:
$ ngc config current
If you intend to upload a model to a different registry space, or if no team is reported and you intend to upload to a team space, then you can either:
Use ngc config set to switch to another org or team:
$ ngc config set [--org <new org>][--team <new team>]
or
Set the context at each command, using the same --org or --team options.
3.5.2. Uploading a Resource#
The following is the general process for uploading a resource to the model script registry.
Create a resource in the registry. This is a placeholder for your model and contains metadata about the resource.
Example of creating resource “cmr_gnmt”.
$ ngc registry resource create nvidia/cmr_gnmt
To display a complete list of required and optional arguments, enter the following.
$ ngc registry resource create -h
Upload your resource files.
Each time you upload files to the same resource, the upload becomes a unique version of the resource. You can specify the version when you upload, or let the CLI increment the version automatically.
Example: Uploading version 1 of the resource ‘cmr_gnmt’ (required arguments omitted for simplicity).
$ ngc registry resource upload-version nvidia/cmr_gnmt:first-upload [--source .<directory or file path for the model contents>] ---------------------------------------------------- Transfer id: cmr_gnmt[version=first-upload] Upload status: Completed. Uploaded local path: C:\resource Total files uploaded: 26 Total uploaded size: 134.48 KB Started at: 2019-03-15 17:18:09.083000 Completed at: 2019-03-15 17:18:21.698000 Duration taken: 12s seconds ----------------------------------------------------
3.5.3. Updating a Resource#
You can update or revise information for a resource or resource version.
The following is the basic command.
$ ngc registry resource update <org>/[<team>/]<resource-name[:version]>
To update information, use the optional arguments to specify the information to change. To display the list of arguments, run:
$ ngc registry resource update -h
3.5.4. Resource Commands#
The full list of optional commands for NGC resources are listed below.
--accuracy-reached <accuracy>Accuracy reached with target version.
--ace <name>Specify the ACE name. Use
--ace no-aceto override other sources and specify no ACE. Default: current configuration
--advanced-filename <path>Advanced guide. Provide the path to a file that contains the “Advanced Guide” for the resource.
--application <app>Target model application. Allowed values: CLASSIFICATION, OBJECT_DETECTION, SEGMENTATION, TRANSLATION, TEXT_TO_SPEECH, RECOMMENDER, SENTIMENT, NLP, KUBEFLOW_PIPELINE, OTHER.
--batch-size <size>The batch size of the target version.
--built-by <name>Builder of the target model.
--debugEnable debug mode.
--desc <desc>Full description of target version.
--display-name <name>Display name.
--format <fmt>Format of the target model.
--format_type <fmt>Specify the output format type. Supported formats are: ascii, csv, json. Only commands that produce tabular data support csv format. Default: ascii
--framework <fwk>Framework used to train the target model. Allowed values: TensorFlow, Caffe2, CNTK, Torch, PyTorch, MXNet, Keras, Other.
--gpu-model <model>The GPU used to train the target version.
--label <label>Label for the resource. To specify more than one label, use multiple
--labelarguments.
--logo <url>URL for the resource logo image.
--memory-footprint <footprint>The memory footprint of the target version.
--num-epochs <num>The number of epochs for the target version.
--org <name>Specify the organization name. Use
--org no-orgto override other sources and specify no org. Default: current configuration
--overview-filename <path>Overview. Provide the path to a file that contains the overview for the resource.
--performance-filename <path>Performance data. Provide the path to a file that contains the performance data for the resource.
--precision <prec>Precision the target model was trained with. Allowed Values: FP16, FP32, INT8, FPBOTH, OTHER.
--public-dataset-license <lcs>License for public dataset used in the target model.
--public-dataset-link <url>Link to public dataset used in the target model.
--public-dataset-name <name>Name of public dataset used in the target model.
--publisher <name>Publisher of the target model.
--quick-start-guide-filename <path>Quick start information. Provide the path to a file that contains the “Quick Start Guide” information for the resource.
--release-notes-filename <path>Release notes. Provide the path to a file that contains the release notes for the resource.
--setup-filename <path>Setup instructions. Provide the path to a file that contains the setup instructions for the resource.
--short-desc <desc>Short description.
--team <name>Specify the team name. Use
--team no-teamto override other sources and specify no team. Default: current configuration
3.5.5. Deleting a Resource#
Only admins and creators of the model can delete a model.
Confirm that the context is set appropriately for the resource you want to delete. For example, if you want to delete a model that you created in the team_A space, then set the context as --team team_A.
To remove the resource, including all versions of the resource, enter the following.
$ ngc registry resource remove <org>/[<team>/]<resource>
To remove only a specific version of the resource, enter the following.
$ ngc registry resource remove <org>/[<team>/]<resource:version>
3.6. NGC Helm Charts#
This guide describes how to use the NGC registry to manage Helm charts.
3.6.1. Introduction to NGC and Helm Charts#
Helm is an application package manager running on top of Kubernetes. It lets you create Helm charts where you can define, install, and upgrade Kubernetes applications.
This guide describes how to share Helm charts with others in your org or team using the NGC registry.
Prerequisites
These instructions assume the following prerequisites are met.
Helm v3.x installed
This is only required if you are creating or packaging Helm charts yourself. It is not needed otherwise.
NGC organization account
Refer to the section Getting Started for instructions.
Note
The asset ngcdocstest referenced below was created for example purposes only. It is intended merely as a guide and is not a requirement for publishing Helm assets to NGC.
3.6.2. Creating and Packaging a Helm Chart#
This section describes how to package a Helm chart for publishing to NGC.
You do not need to deploy the Helm chart to publish your chart to NGC. A .tgz file of the chart can be published to an org in NGC without being deployed first to the GPU infrastructure.
Create a Helm chart template by issuing the following.
$ helm create <chart-name>
Where
<chart-name>is the name of your choosing.Example:
$ helm create ngcdocstest
Modify the contents of the template with your Helm chart data. Use the following convention:
Chart names: must be lowercase or uppercase alphanumeric characters, and must start with a letter. Words can be separated with hyphens (
-) or underscores (_). Dots (.) are not allowed.Versions: must be a valid semantic versioning (SemVer 2.0.0) string.
Package the Helm chart by issuing the following.
$ helm package <chart-name>
Example:
$ helm package ngcdocstest
This example creates the tar package
ngcdocstest-0.1.0.tgz.
3.6.3. Manage Helm Charts Using the NGC Web UI#
3.6.3.1. Viewing the List of Helm Charts and Getting Fetch Commands#
From the NGC website you can:
View the contents of the Helm chart repository.
Get the fetch command for a specific Helm chart in the repository.
From a browser, log in to the NGC website.
If you are a member of more than one org, select the one that contains the Helm charts that you are interested in, then click Sign In.
Click Helm Charts from the left-side navigation pane.
The page presents cards for each available Helm chart.
Select one of the Helm chart cards. The page for each Helm chart provides information about the chart.
Click the Fetch Version dropdown menu from the upper right corner to copy the fetch command to the clipboard.
3.6.3.2. Adding Helm Charts Using the NGC Web UI#
Note
Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry User” or “Registry Admin”. For details, refer to NGC Registry User Roles.
Before a chart can be uploaded to your organization’s registry, you must first create a record containing the basic information about the chart.
Click Entity Creation Hub under the Private Registry section of the left side menu.
Click Create Helm Chart.
Fill in information about your Helm chart.
Click Create Helm Chart.
To push (upload) a Helm chart to your org space, use the NGC CLI.
Example:
$ ngc registry chart push nvidian/ngcdocstest:0.1.0
Refer to Pushing a Helm Chart for details.
3.6.3.3. Updating the Helm Chart Page From the Website#
To update the fields in the NGC Helm Chart page for a specific Helm chart, click Edit Details.
Edit each field as needed, then click Save.
3.6.3.4. Removing Helm Charts from the Web UI#
Note
Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry Admin”. For details, refer to NGC Registry User Roles.
To delete a Helm chart, click Edit Details from the details page of the Helm chart to delete.
Click Delete to remove the Helm chart.
Click Delete at the confirmation dialog.
3.6.4. Manage Helm Charts Using the NGC CLI#
3.6.4.1. Searching for Available Helm Charts in an Org#
The NGC CLI supports wildcard searches, using standard Unix shell-style wildcards. For example, to display a list of all available Chart packages in your org, run the following command.
$ ngc registry chart list "*<org_name>*"
Example:
$ ngc registry chart list "*nvidian*"
That command returns all charts with ‘nvidian’ anywhere in the name.
Name |
Repository |
Version |
Size |
Created By |
Description |
Created Date |
Last Modified |
|---|---|---|---|---|---|---|---|
fluentd-elasti csearch |
nvidian/fluen ntd-elasticse arch |
4.8.1 |
245.61 KB |
stg-3emmf14t83v d0s5v81qasfi479 |
Changed sho rt descript ion |
Nov 15, 2019 |
Dec 17, 2019 |
clara |
nvidian/repo1 /clara |
0.0.1 |
65.66 KB |
stg-p6urlvepnjb q06qfis28l5m6a4 |
Feb 07, 2020 |
Mar 12, 2021 |
3.6.4.2. Fetching Helm Charts#
To download (or “pull”) a Chart package, run the following command.
Note
If no version is specified, the most recent version is pulled.
$ ngc registry chart pull org/[team/]chart[:version]
Example:
$ ngc registry chart pull nvidian/nginx-ingress:1.2.3 (pulls version 1.2.3)
$ ngc registry chart pull nvidian/nginx-ingress (pulls the latest version)
3.6.4.3. Adding Helm Charts to a Private Registry#
Note
Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry User” or “Registry Admin”. For details, refer to NGC Registry User Roles.
Creating a Chart
Before a chart can be uploaded to your organization’s registry, you must first create a record containing the basic information about the chart. There are several values you can specify (issue ngc registry chart create --help to view all of them), but you must at least provide a short description of the chart.
$ ngc registry chart create <org>/[<team>/]<chart_name> --short-desc <description>
Example:
$ ngc registry chart create nvidian/ngcdocstest --short-desc "Doc testing chart"
Successfully created chart 'nvidian/ngcdocstest'.
--------------------------------------------------
Chart Information
Name: ngcdocstest
Short Description: Doc testing chart
Display Name:
Team:
Publisher:
Built By:
Labels:
Logo:
Created Date: 2021-03-22 18:48:36 UTC
Updated Date: 2021-03-22 18:48:36 UTC
Read Only: False
Latest Version ID:
Latest Version Size (bytes):
Overview:
--------------------------------------------------
Updating a Chart
You can update the metadata about a chart after it has been created with the update command.
$ ngc registry chart update <org>/[<team>/]<chart_name> --<property> <value>
Example:
$ ngc registry chart update nvidian/ngcdocstest --publisher "test account" --display-name "Helm Demo Chart" --built-by "my team"
Successfully updated chart 'nvidian/ngcdocstest'.
--------------------------------------------------
Chart Information
Name: ngcdocstest
Short Description: Doc testing chart
Display Name: Helm Demo Chart
Team:
Publisher: test account
Built By: my team
Labels:
Logo:
Created Date: 2021-03-22 18:48:36 UTC
Updated Date: 2021-03-22 18:52:01 UTC
Read Only: False
Latest Version ID: 0.1.0
Latest Version Size (bytes): 10664
Overview:
--------------------------------------------------
3.6.4.4. Getting Information About a Helm Chart#
You can view the information about a chart at any time by running the info command:
Example:
$ ngc registry chart info nvidian/ngcdocstest
--------------------------------------------------
Chart Information
Name: ngcdocstest
Short Description: Doc testing chart
Display Name: Helm Demo Chart
Team:
Publisher: test account
Built By: my team
Labels:
Logo:
Created Date: 2021-03-22 18:48:36 UTC
Updated Date: 2021-03-22 18:54:44 UTC
Read Only: False
Latest Version ID: 0.1.0
Latest Version Size (bytes): 10664
Overview:
--------------------------------------------------
3.6.4.5. Pushing a Helm Chart#
To push (upload) a Helm chart to your org space, issue the following.
$ ngc registry chart push <org>/[<team>/]<chart_name>:<version>
Example:
This example expects the packaged chart file ngcdocstest-0.1.0.tgz to
be present in the current directory.
$ ngc registry chart push nvidian/ngcdocstest:0.1.0
Looking for chart ngcdocstest-0.1.0.tgz
Successfully pushed chart version 'ngcdocstest:0.1.0'.
--------------------------------------------------
Chart Version Information
Created Date: 2021-03-22 18:54:44 UTC
Updated Date: 2021-03-22 18:54:44 UTC
Version ID: 0.1.0
Total File Count: 11
Total Size: 10.41 KB
Status: UPLOAD_COMPLETE
--------------------------------------------------
3.6.4.6. Listing Helm Chart Versions#
To display a list of all available versions for a chart, specify the chart name.
Example:
$ ngc registry chart list nvidian/nginx-ingress
+---------+------------+-----------+--------------+
| Version | File Count | File Size | Created Date |
+=========+============+===========+==============+
| 0.8.0 | 27 | 181.94 KB | Mar 12, 2021 |
| 1.0.0 | 25 | 149.51 KB | Oct 02, 2020 |
| 0.0.6 | 25 | 149.51 KB | Oct 02, 2020 |
| 0.0.5 | 25 | 149.51 KB | Oct 02, 2020 |
| 0.6.0 | 25 | 149.51 KB | Sep 17, 2020 |
| 0.6.1 | 25 | 149.51 KB | Sep 17, 2020 |
| 1.26.2 | 68 | 109.19 KB | Feb 08, 2020 |
+---------+------------+-----------+--------------+
3.6.4.7. Removing Helm Charts from a Private Registry#
Note
Confirm that you have the right permissions to create Helm charts in your organization or team. You need to have the user role “Registry Admin”. For details, refer to NGC Registry User Roles.
If you are an admin, you can delete a specific version of a chart running the following command:
$ ngc registry chart remove <org>/[<team>/]<chart_name>:<version>
The following example removes just version 0.1.0:
$ ngc registry chart remove nvidian/ngcdocstest:0.1.0
The following example removes all versions and data about the chart:
$ ngc registry chart remove nvidian/ngcdocstest
If you do not specify a version, every version of the chart, as well as the chart metadata, is deleted.
Example:
$ ngc registry chart remove nvidia/ngcdocstest
Are you sure you would like to remove nvidia/ngcdocstest? [y/n]y
Successfully removed chart version 'nvidia/ngcdocstest:0.1.0'.
Successfully removed chart 'nvidia/ngcdocstest'.
3.6.5. Manage Helm Charts Using the NGC API#
3.6.5.1. Updating Information on the Helm Chart Page#
The NGC API lets you specify information about your Helm chart. Use the NGC API Explorer page for updating artifact in an org to build the JSON file for use in a CURL command.
The following page elements can be edited.
Page Element |
JSON Field |
Description |
|---|---|---|
Helm Chart name |
displayName |
The name of the Helm chart appearing in the title on the tile and Helm chart page |
Publisher |
publisher |
The organization/entity responsible for creating the asset |
Logo |
logo |
URL of the image to use as the logo for the asset |
Description |
shortDescription |
A short description for the Helm chart |
Labels |
labels |
Tags to enhance search results |
Overview tab |
description |
Content of the “Overview” tab which can provide publishers to convey additional |
The JSON column shows the corresponding JSON fields to use when updating the page using the NGC API.
The following shows the relevant fields in the JSON file.
{
"attributes": [
{
"key": "string",
"value": "string"
}
],
"builtBy": "string",
"description": "string",
"displayName": "string",
"labels": [
"string"
],
"logo": "string",
"publisher": "string",
"shortDescription": "string"
}
Example
The following shows example JSON values.
{
"builtBy": "NVIDIA",
"description": "#NGC Docs Chart",
"displayName": "NGC DOCS CHART TEST",
"labels": [
"Helm Chart",
"Documentation"
],
"shortDescription": "This charts is for the docs!"
}
The following is an example CURL command.
curl -X PATCH --header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer <<BEARER_TOKEN>>' \
-d '{ "builtBy": "NVIDIA", "description": "#Le Chart", "displayName": "NGC DOCS TEST", "labels": [ "Helm Chart", "Documentation" ], "shortDescription": "This chart is for the docs!" }' \
'https://api.ngc.nvidia.com/v2/org/nvidian/helm-charts/ngcdocstest'
3.6.5.2. Deleting Helm Charts Using the NGC API#
Refer to Delete artifact in an org for a description of the relevant API.
To delete a Helm chart from an org space, issue the following:
$ curl -X DELETE --header 'Accept: application/json' --header 'Authorization: Bearer <Bearer Token>' 'https://api.ngc.nvidia.com/v2/org/<org-name>/helm-charts/<chart-name>'
To delete a Helm chart from a team space, issue the following:
$ curl -X DELETE --header 'Accept: application/json' --header 'Authorization: Bearer <Bearer Token>' 'https://api.ngc.nvidia.com/v2/org/<org-name>/team/<team-name>/helm-charts/<chart-name>'
3.6.6. Manage Helm Charts Using the Helm CLI#
3.6.6.1. Setting Up an NGC Helm Repository#
Obtain an NGC API Key. Refer to Generating NGC API Keys for instructions.
Export the API Key for use in commands.
$ export NGC_API_KEY=<your-api-key>
Add the NGC org to your Helm repository.
$ helm repo add <repo-name> https://helm.ngc.nvidia.com/<org-name> --username=\$oauthtoken --password=$NGC_API_KEY
Where
<repo-name>is a name of your choosing by which you reference the repository.
3.6.6.2. Updating the Local Helm Repository#
To reconcile your local Helm repository with the remote NGC Helm registry, run the following. This refreshes the local cache so you can discover new charts and charts that have been removed since the repo was last added or refreshed.
$ helm repo update <repo-name>
3.6.6.3. Searching for Available Helm Charts#
To view a list of available Chart packages in your org, issue the following.
$ helm search repo <repo-name>
3.6.6.4. Fetching Helm Charts#
To download (or “fetch”) a Helm chart package from the repo, issue the following.
$ helm pull <repo-name>/<chart-name>
3.6.6.5. Adding Helm Charts to a Private NGC Org/Team#
These instructions assume the Helm push plug-in is installed. To install the plug-in, issue the following.
$ helm plugin install https://github.com/chartmuseum/helm-push
To push (upload) a Helm chart to your org space, issue the following.
$ helm cm-push <chart-name>.tgz <repo-name>
Then update the local Helm cache to view the new chart.
$ helm repo update <repo-name>
3.6.6.6. Removing Helm Charts from a Private NGC Org/Team#
To remove Helm charts from your org or team, you must use the NGC CLI, NGC Web UI, or NGC API.
3.7. Private Registry Quotas and Limits#
The following size limits apply to the Private Registry:
Description |
Limit |
Note |
|---|---|---|
Single image layer size |
10 GB |
Size limit per layer for Docker images (recommended). |
Total image size |
1 TB |
Size limit for all Docker images stored in the registry (recommended). |
Total model/resource size |
5 TB |
Size limit for all models or resources stored in the registry (enforced). |
Chart file size |
5 MB |
Configurable; default per-file limit for Helm charts. |
Compressed chart size |
100 MB |
Configurable; default. Current maximum is 19 MB. |
Files per chart |
10,000 |
Maximum number of files in a single Helm chart. |
Note
Avoid creating an unbound number of Helm chart versions.
3.8. Getting Support for NGC Container and Helm Chart Registries#
For additional information on using the NGC container registry or the NGC Helm chart registry, or for help if you encounter issues with either, send an email to enterprisesupport@nvidia.com with a description of your issue. A ticket is created for you.