---
title: Understanding disconnected installation mirroring
---

# Understanding disconnected installation mirroring {#understanding-disconnected-installation-mirroring}

You can use a mirror registry for disconnected installations and to ensure that your clusters only use container images that satisfy your organization’s controls on external content.

Before you install a cluster on infrastructure that you provision in a disconnected environment, you must mirror the required container images into that environment. To mirror container images, you must have a registry for mirroring.

You can use one of the following procedures to mirror your OpenShift Container Platform image repository to your mirror registry:

- "Mirroring images for a disconnected installation by using the oc-mirror plugin v2"
- "Mirroring images for a disconnected installation"

## About mirroring the OpenShift Container Platform image repository for a disconnected registry {#agent-install-about-mirroring-for-disconnected-registry_understanding-disconnected-installation-mirroring}

To use mirror images for a disconnected installation with the Agent-based Installer, you must modify the `install-config.yaml` file.

You can mirror the release image by using the output of the `oc mirror` command.

> [!IMPORTANT]
> The `oc adm release mirror` command is deprecated as of OpenShift Container Platform 4.22 and will be removed in a future release.
>
> As an alternative, use the oc-mirror plugin v2.

The following example shows the output of the `oc adm release mirror` command.

```terminal
$ oc adm release mirror
```

```terminal {title="Example output"}
To use the new mirrored repository to install, add the following
section to the install-config.yaml:

imageContentSources:

mirrors:
virthost.ostest.test.metalkube.org:5000/localimages/local-release-image
source: quay.io/openshift-release-dev/ocp-v4.0-art-dev
mirrors:
virthost.ostest.test.metalkube.org:5000/localimages/local-release-image
source: registry.ci.openshift.org/ocp/release
```

The following example shows part of the `imageContentSourcePolicy.yaml` file generated by the oc-mirror plugin. The file can be found in the results directory, for example `oc-mirror-workspace/results-1682697932/`.

```yaml {title="Example imageContentSourcePolicy.yaml file"}
spec:
  repositoryDigestMirrors:
  - mirrors:
    - virthost.ostest.test.metalkube.org:5000/openshift/release
    source: quay.io/openshift-release-dev/ocp-v4.0-art-dev
  - mirrors:
    - virthost.ostest.test.metalkube.org:5000/openshift/release-images
    source: quay.io/openshift-release-dev/ocp-release
```

### Configuring the Agent-based Installer to use mirrored images {#agent-install-configuring-for-disconnected-registry_understanding-disconnected-installation-mirroring}

You must use the output of either the `oc adm release mirror` command or the oc-mirror plugin to configure the Agent-based Installer to use mirrored images.

**Procedure**

1. If you used the oc-mirror plugin to mirror your release images:

   1. Open the `imageContentSourcePolicy.yaml` located in the results directory, for example `oc-mirror-workspace/results-1682697932/`.
   2. Copy the text in the `repositoryDigestMirrors` section of the yaml file.
2. If you used the `oc adm release mirror` command to mirror your release images:

   - Copy the text in the `imageContentSources` section of the command output.
3. Paste the copied text into the `imageContentSources` field of the `install-config.yaml` file.
4. Add the certificate file used for the mirror registry to the `additionalTrustBundle` field of the yaml file.

   > [!IMPORTANT]
   > The value must be the contents of the certificate file that you used for your mirror registry. The certificate file can be an existing, trusted certificate authority, or the self-signed certificate that you generated for the mirror registry.

   ```yaml {title="Example install-config.yaml file"}
     additionalTrustBundle: |
       -----BEGIN CERTIFICATE-----
       ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
       -----END CERTIFICATE-----
   ```
5. If you are using GitOps ZTP manifests: add the `registries.conf` and `ca-bundle.crt` files  to the `mirror` path to add the mirror configuration in the agent ISO image.

   > [!NOTE]
   > You can create the `registries.conf` file from the output of either the `oc adm release mirror` command or the `oc mirror` plugin. The format of the `/etc/containers/registries.conf` file has changed. It is now version 2 and in TOML format.

   ```toml {title="Example registries.conf file"}
   [[registry]]
   location = "registry.ci.openshift.org/ocp/release" mirror-by-digest-only = true

   [[registry.mirror]] location = "virthost.ostest.test.metalkube.org:5000/localimages/local-release-image"

   [[registry]]
   location = "quay.io/openshift-release-dev/ocp-v4.0-art-dev" mirror-by-digest-only = true

   [[registry.mirror]] location = "virthost.ostest.test.metalkube.org:5000/localimages/local-release-image"
   ```

**Additional resources**
{._additional-resources}

- [Mirroring images for a disconnected installation by using the oc-mirror plugin v2](/openshift-docs-markdown/disconnected/about-installing-oc-mirror-v2#about-installing-oc-mirror-v2)
- [Mirroring images for a disconnected installation](/openshift-docs-markdown/disconnected/installing-mirroring-installation-images#installing-mirroring-installation-images)
- [Installing an OpenShift Container Platform cluster with the Agent-based Installer](/openshift-docs-markdown/installing/installing_with_agent_based_installer/installing-with-agent-based-installer#installing-with-agent-based-installer)
