Public images (Docker Hub, GHCR, Quay…) work with no setup. For private images, store your registry credentials once:
svl registry login ghcr.io -u my-user # prompts for a password or token
echo "$TOKEN" | svl registry login registry.example.com -u ci --password-stdin
svl registry ls
serverless.au picks the credentials that match the image's registry when it pulls — ghcr.io/acme/app:1 uses ghcr.io, acme/app:1 uses Docker Hub. Credentials are encrypted at rest, used only to pull your images and never written to disk on the nodes.
Registry credentials belong to the account, so everyone on a team can pull its private images. Only admins and owners can change them.
If a pull fails (wrong token, missing image), the pod ends as failed with the registry's error as the reason.