# Private docker repo doesn't work (access forbidden)

**URL:** <https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435>\
**Category:** Rancher 2.0 Tech Preview\
**Created:** [September 27, 2017, 10:54am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435 "2017-09-27T10:54:56Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![magan](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/magan/32/2874_2.png) [@magan](https://forums.suse.com/u/magan)\
**Post date:** [September 27, 2017, 10:54am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/1 "2017-09-27T10:54:56Z")

</div>

I have a problem with pulling docker images from a private registry (hosted using the feature in GitLab).

I added a private registry under Resources -\> Registries and tested that the credentials work with `docker login registry.example.com`. Still, when trying to deploy a container with kubernetes, it doesnt seem to use the credentails at all.

The error I get is:  
`Failed to pull image "registry.example.com/path/name:1.0.0": rpc error: code = 2 desc = Error response from daemon: {"message":"Get https://registry.example.com/v2/path/name/manifests/1.0.0: denied: access forbidden"}`

Any hints on what to check for?  
(Pulling public images like `ubuntu:xenial` works)

It is a newly setup RancherOS v1.1.0 instance with Rancher v2.0.0-alpha6 installed in the local disk.

_note: [registry.example.com](http://registry.example.com) is not the proper URL, of course_ 🙂

---

<div class="post-metadata">

**Author:** ![cjellick](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/cjellick/32/2876_2.png) [@cjellick](https://forums.suse.com/u/cjellick)\
**Post date:** [September 27, 2017, 3:40pm UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/2 "2017-09-27T15:40:58Z")

</div>

I don’t know the exact details, but there might be an issue where the kubelet container needs restarted to pick up the credentials. Can you try doing that?

@joshwget can you provide input on this? Am I right or off base?

---

<div class="post-metadata">

**Author:** ![magan](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/magan/32/2874_2.png) [@magan](https://forums.suse.com/u/magan)\
**Post date:** [September 27, 2017, 3:57pm UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/3 "2017-09-27T15:57:17Z")

</div>

Thank you for responding!

I even restarted the whole server, so I don’t think that is the issue, unfortunately.

---

<div class="post-metadata">

**Author:** ![joshwget](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/joshwget/32/704_2.png) [@joshwget](https://forums.suse.com/u/joshwget)\
**Post date:** [September 27, 2017, 5:14pm UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/4 "2017-09-27T17:14:21Z")

</div>

I don’t think restarting the kubelet should be required for this. There is a known issue around private registries though, and this should be fixed in the next release.

---

<div class="post-metadata">

**Author:** ![cjellick](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/cjellick/32/2876_2.png) [@cjellick](https://forums.suse.com/u/cjellick)\
**Post date:** [September 27, 2017, 7:13pm UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/5 "2017-09-27T19:13:52Z")

</div>

I must have gotten the restart thing confused with something else. (also I didnt notice the 2.0 tag on the issue until just now. I was thinking of something in 1.6)

---

<div class="post-metadata">

**Author:** ![magan](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/magan/32/2874_2.png) [@magan](https://forums.suse.com/u/magan)\
**Post date:** [September 28, 2017, 6:16am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/6 "2017-09-28T06:16:41Z")

</div>

@joshwget I also added the same question/issue to the GitHub issue list. I couldn’t find anything similar for 2.0 there.

@cjellick I think I read something about requiring a restart when changing the default registry in 1.6. It might have been it.

I must say that Rancher 2.0 looks very promising, and I can’t wait until this issue is fixed, and the access management is implemented. 🙂

---

<div class="post-metadata">

**Author:** ![guy](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/guy/32/4932_2.png) [@guy](https://forums.suse.com/u/guy)\
**Post date:** [May 6, 2018, 8:07am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/7 "2018-05-06T08:07:15Z")

</div>

I’ve just deployed a test environment with Rancher 2.0. I’m seeing the same now as well.

If I pull first then I can deploy it, however it will not pull from my gitlab repo on it’s own!

---

<div class="post-metadata">

**Author:** ![josecelano](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/josecelano/32/4490_2.png) [@josecelano](https://forums.suse.com/u/josecelano)\
**Post date:** [September 27, 2018, 11:54am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/8 "2018-09-27T11:54:53Z")

</div>

I have the same problem with Rancher2 and using [gitlab.com](http://gitlab.com) private repo.

---

<div class="post-metadata">

**Author:** ![guy](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/guy/32/4932_2.png) [@guy](https://forums.suse.com/u/guy)\
**Post date:** [March 8, 2019, 8:41am UTC](https://forums.suse.com/t/private-docker-repo-doesnt-work-access-forbidden/7435/9 "2019-03-08T08:41:34Z")

</div>

I’m using rancherOS 1.5.1 and rancher 2.1.7

I have set cloud-config with private registries

registry\_auths:  
“[https://gitlab.local:5005](https://gitlab.local:5005)”:  
auth: “akjhfkjhkjhsdlkjhsadkljhsadf”

I can use docker pull to download the image manually, it’s working fine, however via deploy in rancher it’s failing the authentication.
