Does Podman support automatic expiry or rotation of registry credentials in auth.json?
0 reputation · 01 Mar 2026, 10:03 UTC
Podman stores registry credentials from podman login in a plain-text authfile such as ~/.config/containers/auth.json, and the documented behavior includes no native expiry timestamp or rotation hook for those entries. TLS client-certificate authentication is validated against the configured CA, so an expired client certificate makes pull and push operations fail at connection time rather than being detected beforehand.
The goal is a least-privilege registry setup: short-lived credentials, no standing access, and predictable behavior when they lapse. In rootless mode the user's own authfile applies, so a single expired credential can block that user's image operations, and a CI pipeline that pulls periodically would only surface the problem as an authentication failure mid-job.
Does current Podman provide any documented mechanism for expiring or rotating authfile credentials automatically? What is the expected behavior when a TLS client certificate or stored credential expires between pulls? Is there a supported way to detect an expired credential before an operation fails?