Prerequisites
- Self-hosting enabled for your team under an enterprise agreement.
- A fish.audio account that is a member of that team.
- Docker, and Helm 3.8 or newer for the OCI chart commands.
The registry host, the artifact references, and the versions available to you
are shown in the dashboard and are specific to your team. This documentation
writes them as placeholders such as
<registry-host> and <chart-reference>.Create a deploy token
1
Open the Deploy Tokens card
On Developer → Self Host, select Create Deploy Token.
2
Name it for where it will be used
Use a name that identifies the consumer, such as
prod-cluster or
ci-mirror. The name appears in the token list alongside the creation date
and last-used time.3
Copy the token immediately
The token value is shown once, at creation. Store it in your secret manager
before closing the dialog. If you lose it, rotate the token to issue a new
one.
Authenticate Docker
Set your values once, then reuse them in the commands below.Login Succeeded. Teams granted the All-in-One form
can also verify a pull with the reference from
All-in-One container; Helm-only teams
verify against the chart in the next section.
Authenticate Helm
Charts are served as OCI artifacts, so Helm authenticates against the same registry host:Create the Kubernetes pull secret
The cluster pulls images with the same credentials, in a pull secret the chart expects to find in the release namespace. The token is fed in on standard input rather than as an argument:--docker-password would put it in the process’s
command line, where anyone else on the host can read it with ps.
create secret docker-registry is a shorthand
that builds this document for you.
Reference it from the release so every workload uses it:
Managing tokens
Recommended practice:
- Issue one token per consumer — production cluster, staging cluster, CI mirror — so a single revocation never takes down more than one of them.
- Store tokens in your secret manager, not in values files or version control.
- Rotate on your normal credential schedule and whenever someone with access to a token leaves the team.

