Zot

Zot

OCI-native container registry in a single static binary with RBAC, scanning and replication built in, no external database. Apache-licensed, no paid tier. A younger CNCF Sandbox project than Harbor.

🩺 Vitals

What do these metrics mean?
  • Last active: when code was last pushed, as of our last check. The dot is green when that was recent, grey otherwise. A long gap can mean a tool is finished and stable, not only unmaintained.
  • Latest release: the most recent tagged, packaged version the maintainers published. Not every healthy project tags releases.
  • Open issues: unresolved reports and requests. A high number is normal for a popular project and is not a warning on its own.
  • Stars: how many people bookmarked the project on its forge. A rough popularity signal, not a measure of quality.

πŸ—οΈ Profile

1. The Executive Summary

What is it? Zot is an OCI-native container registry delivered as a single, statically compiled binary. Unlike the reference Distribution registry, it ships with built-in authentication, RBAC, vulnerability scanning and registry-to-registry replication; unlike Harbor or Quay, it provides those without an external database or object store to run. It keeps images in the standard OCI layout directly on the filesystem or S3-compatible storage, which makes both the deployment and the data trivially portable.

The Strategic Verdict:

2. The "Hidden" Costs (TCO Analysis)

Cost Component Docker Hub (SaaS) Zot (Self-Hosted)
Storage & Pulls Metered and rate-limited Your storage, no limits
Data Custody Third-party cloud Your infrastructure
Licensing Paid tiers for private or team use None (Apache 2.0)

3. The "Day 2" Reality Check

πŸš€ Deployment & Operations

πŸ›‘οΈ Security & Governance (Risk Assessment)

4. Market Landscape

🏒 Proprietary Incumbents

🀝 Open Source Ecosystem