A registry is what turns a rollback from a redeploy into a pointer move, which is the difference between minutes and an outage.
ConceptWhat it is
A model registry is the record of every model artefact a system can serve: the weights or the provider model id, the configuration that goes with it, the eval results it was promoted on, and its current stage — candidate, serving, retired.
It exists to answer two questions quickly under pressure. What is serving right now? and what do I move to? Without a registry both answers live in somebody's memory of a deploy, which is exactly the resource that is least available during an incident. The registry is a small piece of infrastructure that mostly does nothing, and then does the only thing that matters.
How it worksThe mechanics
Each entry is immutable and carries its own identity, its configuration, and a reference to the eval run that promoted it. Serving does not name an artefact directly — it names an alias, and the alias points at an entry. Promotion moves the alias; rollback moves it back. Nothing is rebuilt and nothing is redeployed.
For hosted models the artefact is a provider model id plus the parameters pinned alongside it, which is a thinner entry and exactly as load-bearing. The registry is also where the honest fields live: what the candidate was measured on, what it was not measured on, and which known weakness it was accepted with. A registry recording only successes cannot support the decision it exists to inform.
At a glanceSee it
Serving names an alias rather than an artefact, so promotion and rollback are both pointer moves rather than deploys.
When to use itWhere it fits
- As soon as more than one model version can serve traffic, which happens earlier than most teams expect.
- Whenever a rollback needs to be fast, since fast rollback is the capability a registry actually buys.
- When several people can change what serves, so the current answer lives somewhere other than a chat log.
- For hosted models too — a pinned provider id plus its parameters is a registry entry.
When NOT to use itLimits & anti-patterns
- As a place to store weights nobody will serve; an artefact store and a registry are different jobs.
- For a single fixed model with no promotion path, where a pinned id in version control is the honest form.
- Recording only what was promoted — the rejected candidates are the record of what was tried.
- As a substitute for evals; a registry records that something was promoted, not that it was better.
Trade-offsAdvantages & costs
Advantages
- Makes rollback a pointer move, which is the shortest path out of a bad release.
- Answers what is serving without a deploy archaeology exercise.
- Ties every serving decision to the evidence it was made on.
- Gives candidates a place to exist before they take traffic.
Trade-offs & costs
- Another system to keep true; a registry that disagrees with reality is worse than none.
- The alias indirection is one more thing to understand when reading the serving path.
- Tempts teams into storing large artefacts where a reference would do.
- Cannot enforce that the promotion evidence was any good.
ExampleIn the real world
A quality complaint arrives an hour after a release. Two questions decide how the next twenty minutes go: which version is serving, and how quickly can that change. With a registry both are one lookup and one alias move, and the investigation continues with traffic already back on the previous version. Without one, the rollback is a rebuild from a commit somebody has to identify first, and the investigation starts after it.
ToolsHow to implement it
- MLflow Model Registrystages, aliases and promotion history, the common default.
- A table plus an aliasentirely adequate when the artefact is a hosted model id.
- The eval run referencethe field that makes a promotion auditable rather than asserted.
- Weights & Biases model registrywhen promotion and experiment history belong in one place.
Cost & effortWhat it takes
Small to build and small to run, especially where entries are provider model ids rather than weights. The real cost is keeping it true: a registry that has drifted from what is actually serving gives a confident wrong answer at the worst possible moment, which is worse than having no registry and knowing it.