Skip to main content
Version: Next 🚧

Hauler Store Copy

Overview​

hauler store copy pushes the entire contents of the store to another location.

It's the command you use to "unload" a store into your real infrastructure on the airgapped side - typically seeding an existing OCI registry with every image, chart, file, directory, and git repository at once, rather than running Hauler's built-in registry long-term. Unlike hauler store serve registry, which keeps a process running, copy performs a one-time transfer and exits. It can also extract the store's files, charts, directories, and git repositories straight to a directory. The target is given as a single argument prefixed with the destination type:

PrefixBehavior
registry://, reg://, oci://Pushes the store (images, charts, files, directories, git repositories, and cosign metadata) to an OCI registry
directory://, dir://Extracts the store's files, charts, directories, and git repositories to a local directory (container images and cosign metadata are skipped)

An example with available flags...

# push the store to an OCI registry
hauler store copy registry://<registry-url>

# extract the store to a local directory
hauler store copy dir://<directory-path>

# only copy image references containing a given string
hauler store copy registry://<registry-url> --only <substring>

Command Overview​

Usage:
hauler store copy [flags]

Examples:
# supported copy target prefixes
registry:// | reg:// | oci:// - Pushes the store to an OCI registry
directory:// | dir:// - Extracts the store to a directory

Flags:
--ca-file string (Optional) Location of CA Bundle to enable certification verification
-h, --help help for copy
--insecure (Optional) Allow insecure connections
-o, --only string (Optional) Custom string array to only copy specific 'image' items
--plain-http (Optional) Allow plain HTTP connections
--type string (EXPERIMENTAL) (Optional) Filter on content type (image | chart | file | directory | git | sigs | atts | sbom | referrer) (default "all")

Global Flags:
--audit-level string Set the audit logging level (none, standard, verbose) (defaults standard)
--blob-concurrency int (Optional) Override the maximum number of concurrent blob writes (0 auto-derives from --concurrency where set, otherwise defaults to 16)
-d, --haulerdir string Set the location of the hauler directory (default $HOME/.hauler)
--ignore-errors Warn and continue instead of failing on errors, including storing images that failed verification (defaults false)
-l, --log-level string Set the logging level (i.e. info, debug, warn) (defaults info)
-r, --retries int Set the number of retries for operations (0 uses HAULER_RETRIES, otherwise defaults to 3)
-s, --store string Set the directory to use for the content store
-t, --tempdir string (Optional) Override the default temporary directory determined by the OS
-w, --work-dir string (Optional) Set the directory for output that commands would otherwise write to the current directory (default: current directory)

Filtering with --only​

The --only flag restricts the copy to artifacts whose reference contains the given substring. For example, to push only images from a particular repository:

hauler store copy registry://<registry-url> --only rancher

Filtering with --type​

The --type flag restricts the copy to a single content type. Supported values are image, chart, file, directory, git, sigs, atts, sbom, and referrer; it defaults to all. Combine it with --only to further narrow the copy to specific references within that type. This feature is experimental.

# only copy charts
hauler store copy registry://<registry-url> --type chart

# only copy images matching a substring
hauler store copy registry://<registry-url> --type image --only rancher

Configuring TLS for Registry Targets​

--ca-file and --insecure only affect registry:// targets. Use --ca-file to trust a private or internal CA, or --insecure to skip certificate verification entirely.

# push to a registry with a private ca
hauler store copy registry://<registry-url> --ca-file /path/to/ca.pem

# push to a registry with a self-signed or otherwise unverifiable certificate
hauler store copy registry://<registry-url> --insecure

Note: Avoid setting --ca-file and --insecure together - if both are set, --insecure takes precedence and the CA file is not read. When neither is set, the system's default CA bundle is used.

Authentication​

To push to a registry that requires authentication, log in first with hauler login:

hauler login <registry-url> --username <username> --password <password>
hauler store copy registry://<registry-url>

Note: The --username and --password flags on hauler store copy are deprecated in favor of hauler login.