Insights · OpenShift practice · Issue I, MMXXVI.

Red Hat Quay registry, licensed where the images actually sit.

Red Hat Quay is the enterprise container image registry that originated with CoreOS. The 2026 line reads against deployment footprint, hosted seat count, or OpenShift Plus bundle membership, and the renewal turns on which of those three postures the buyer signed against.
By The Buyer-Side Desk, an independent advisory practice. 190+ engagements, $180M+ recovered. Published
Abstract

Red Hat Quay registry licensing reads against one of three postures in 2026: a self managed Quay deployment carrying a subscription line that scales with the deployment footprint and capability tier, a Quay.io hosted service line that reads on user seat count and private repository scope, or membership inside the OpenShift Plus bundle where Quay is included on the bundle clusters. The reading at the renewal table turns on which posture the registry footprint actually fits, and on whether the geo replication, repository mirroring, and vulnerability scanning features that the operational team relies on are inside the contracted tier.

§ 1

Quay as the enterprise registry, across three deployment postures.

Red Hat Quay is the productised release of the Quay container image registry, originally built inside CoreOS and acquired by Red Hat in 2018 alongside the broader CoreOS portfolio. The product runs as a self managed registry that can be deployed on OpenShift or on a generic Linux host, or it can be consumed as a hosted service at quay.io, or it can be activated as part of the OpenShift Plus bundle alongside the platform, ACS, ACM, and the data foundation layer1. The three postures sit on the same underlying engine but read differently at the renewal table.

The self managed Quay registry carries a subscription line that scales with the deployment footprint. The registry can be deployed on a single high availability tier or extended with geo replication across multiple regions, with repository mirroring from upstream registries, and with the Clair vulnerability scanning engine that ships with the product. The 2026 subscription reads on the deployment tier and feature scope; a single region high availability deployment reads differently from a multi region geo replicated deployment with active scanning across the full image catalogue.

The Quay.io hosted service reads on user seat count, private repository scope, and storage consumed inside the Red Hat operated environment. The line is sized for organisations that prefer the hosted posture and do not want to operate the registry themselves, and it is the posture most commonly chosen by smaller engineering organisations and by teams that want a separated registry surface outside the production OpenShift fleet.

The OpenShift Plus bundle posture absorbs Quay into the bundle line on the bundle clusters. The buyer who runs OpenShift Plus on a cluster receives Quay as part of the bundle entitlement and runs the registry on that cluster or alongside it. The bundle posture is favourable where Quay sits next to ACM, ACS, and the data foundation layer and unfavourable where the registry is the only OpenShift Plus component the buyer needs.

§ 2

Feature tier inside the line, and the operational reality outside it.

The Red Hat Quay registry ships with three features that often determine the operational value of the deployment: geo replication, repository mirroring, and Clair backed vulnerability scanning2. The features are not separate add ons; they ship with the product across the standard tier. The renewal reading therefore turns less on feature activation and more on the operational scope at which the features run.

Geo replication spreads image content across multiple storage backends in different regions. A buyer who runs Quay in a single region reads against a footprint that captures one set of storage backends. A buyer who runs geo replication across three regions reads against a footprint that captures three. The operational team often turns on geo replication for disaster recovery posture without revisiting the deployment line at the next renewal. The audit then reads the multi region footprint against a single region renewal scope.

Repository mirroring brings upstream image content into the Quay registry on a schedule. A buyer who mirrors a handful of base images reads against a footprint that captures a known set of mirror jobs. A buyer who mirrors the full output of a public registry into Quay reads against a footprint that is materially larger. The mirror configuration is operationally invisible to the contract record unless the buyer explicitly captures it.

Clair backed vulnerability scanning runs against every image pushed into the registry. The scanning footprint is not a feature line in the standard tier but it does drive storage and compute on the Quay deployment. A buyer who scopes the Quay deployment against the image catalogue size at signature and then discovers the catalogue tripled across the term reads the next renewal against a larger deployment than the original line covered.

§ 3

The bundle path, and the standalone path.

The choice between standalone Quay and Quay inside the OpenShift Plus bundle is the central renewal lever for buyers running Quay at scale. The bundle absorbs the Quay line on the bundle clusters and removes the explicit Quay attribution from the renewal arithmetic. The standalone line preserves the explicit Quay attribution and makes the registry footprint visible on its own line. The two postures read differently in concession negotiation and in audit posture.

The bundle posture is favourable where Quay runs alongside ACS, ACM, and the data foundation layer on the same clusters. The bundle list price reads as a single line against the cluster cores and absorbs each of the constituent products. The bundle is unfavourable where Quay is the only OpenShift Plus product the buyer needs. In that case the buyer pays for ACS, ACM, and the data foundation layer entitlements on every bundle cluster even though only the Quay entitlement is in active use.

The standalone posture is favourable where Quay is the only registry surface the buyer needs across an OpenShift estate that does not require ACS or ACM at the same scope. The standalone line reads only against the Quay deployment and the renewal arithmetic captures only the registry footprint. A disciplined subscription assessment in the ninety days before signature produces the bundle versus standalone decomposition that the contract scope needs.

§ 4

Three counting traps on the Quay line.

Three counting traps produce most of the exposure observed across Quay engagements in the trailing twelve months.

The first trap is the geo replication enabled across regions after the initial deployment scope was signed. The deployment line carried a single region footprint at signature and the operational team enabled geo replication mid term as part of a disaster recovery posture. The audit reads the multi region footprint against a single region renewal. The mitigation at signature is to scope the deployment line against the maximum operationally realistic region count and to refresh the scope annually as part of the renewal cycle.

The second trap is the Quay deployment that runs on an OpenShift Plus cluster and was treated as bundle covered even though the cluster carries the standalone OpenShift platform line rather than the OpenShift Plus bundle line. The Quay deployment sits on a cluster that does not have the bundle entitlement and therefore carries an attributable line of its own. The mitigation is to document the bundle status of every cluster hosting Quay and to surface the explicit Quay line where the bundle is not actually present.

The third trap is the Quay.io hosted account that grew beyond the seat count or repository scope the original signature covered. A buyer who signed against twenty private repositories and three hundred seats may discover at audit that the team grew to six hundred seats and one hundred and twenty repositories. The mid term true up reads against the consumed scope at full list price, and the recovery posture at renewal tends to surface a ten to twenty percent saving against the unstructured posture.

Fig. 4.1 · Quay line readings at renewalRHLA · 2026 Q2
Pattern Frequency Reading
Deployment scope aligned to operational footprint3 of 10Pays
Bundle versus standalone decomposition documented2 of 10Pays
Geo replication enabled after signature2 of 10Traps
Bundle assumed but cluster carried standalone line2 of 10Traps
Quay.io account grew past signature scope1 of 10Traps
Practice observation across ten Quay engagements settled between July 2025 and April 2026. Five of ten paid on aligned deployment posture. Five of ten carried trap patterns concentrated on geo replication scope drift, undocumented bundle posture, and Quay.io growth past signature.
§ 5

Reading Quay against the deployment footprint.

Red Hat Quay registry licensing is read against the deployment footprint, the hosted seat scope, or the bundle posture. The reading at signature should reflect the regions in use, the repository scope, the catalogue size that drives the storage and scanning footprint, and the bundle membership on each cluster hosting the registry. The buyer who signs against the maximum operationally realistic scope reads a renewal arithmetic that holds across the term. The buyer who signs against the initial scope and lets the deployment grow into the contract gap pays the mid term true up at full list.

The discipline at signature sets four protections that hold across the term. The deployment posture is named in the contract record. The regions, the catalogue size band, and the seat scope where applicable are enumerated. The bundle versus standalone decomposition is documented and refreshed annually. A quarterly Quay inventory reconciliation captures region count, repository count, catalogue size band, and scanning footprint so the audit notice arrives against a record the buyer can produce on demand.

For the broader cross product reading, see the OpenShift practice hub, the ACS pricing read for the security tier of the bundle, the ACM pricing read for the governance tier, the Pipelines read for the CI tooling that publishes images into Quay, and the defense audit posture where Quay often carries the regulated artefact attestation. For the engagement protocol, see renewal negotiation and contact.

The Quay deployment had grown from one region to three across the contract term. The defence walked the geo replication state region by region and the renewal scope was rewritten to capture the multi region footprint at a negotiated band rather than the open ended true up. The catalogue size band was named explicitly in the contract record for the new term.
Testimony of record · Head of Platform Engineering · logistics group

Notes & references

  1. 1. Red Hat Quay product page, hosted Quay.io pricing notes, and OpenShift Plus bundle documentation, accessed across 2025 and 2026. Quay originated with the CoreOS acquisition in 2018 and is integrated as the registry tier of the OpenShift portfolio.
  2. 2. Quay ships with geo replication, repository mirroring, and Clair backed vulnerability scanning across the standard tier. The features are not separate add ons; they drive the operational footprint of the deployment.
  3. 3. Quay is sold standalone, inside the OpenShift Plus bundle, or as the Quay.io hosted service. Hybrid postures, where some clusters carry Quay through the bundle and a separate Quay.io account serves smaller teams, are common at scale.
  4. 4. Practice observation across ten Quay engagements settled in the trailing twelve months. The most common exposure pattern is the geo replication scope enabled after signature without a corresponding revision to the deployment line.
  5. 5. Concession bands and trailing twelve month figures refer to the practice observation across signed contracts. The eighty two percent audit exposure reduction in marginalia is the trailing twelve month average across defenses settled.

Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.

§ 6 · Engagement

Read the Quay line against the deployment footprint.

Two analyst calls. No fee. We read the Quay subscription against the registry deployment footprint, distinguish bundle covered clusters from standalone ones, and tell you whether the renewal line reads against the realistic image catalogue, geo replication, and scanning posture the operational team runs.