The registry v2 API exposes a catalog of repositories and the tags under each. Where the catalog is readable, it hands over the full inventory; even where it is not, known or guessed repository names can be queried for tags and manifests.
REG=https://registry.example.com
curl -s $REG/v2/_catalog | jq . # all repositories, if allowed
curl -s $REG/v2/<repo>/tags/list | jq . # tags for a repository
curl -s $REG/v2/<repo>/manifests/<tag> \
-H 'Accept: application/vnd.docker.distribution.manifest.v2+json' | jq '.config,.layers'
Exploitation notes#
_catalogis often left readable on internal registries; it is the fastest full inventory.- Manifests reference the config and layer digests you then pull for Secrets in image layers.
- Tools like regctl and crane wrap these calls and handle auth token exchange.