# One machine and a registry, which is the smallest scenario that can exercise a container. # # A sealed machine cannot reach a registry and an image placed from an archive cannot keep its # digest (novox/hq 04-ISSUES/009), so the lab raises one inside the scenario and serves the # images below from it. What a declaration pins is reported when this is raised — the digest # belongs to this registry, not to the one the image came from. scenario: bootstrap-with-registry segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } inbound: allow images: - alpine:3.20 place: all: [host, runtime]