# Private registry not working

**URL:** <https://forums.suse.com/t/private-registry-not-working/10535>\
**Category:** SUSE Rancher Prime\
**Created:** [May 23, 2018, 11:18am UTC](https://forums.suse.com/t/private-registry-not-working/10535 "2018-05-23T11:18:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicolas\_Pepinster](https://avatars.discourse-cdn.com/v4/letter/n/c67d28/32.png) [@Nicolas\_Pepinster](https://forums.suse.com/u/Nicolas_Pepinster)\
**Post date:** [May 23, 2018, 11:18am UTC](https://forums.suse.com/t/private-registry-not-working/10535/1 "2018-05-23T11:18:35Z")

</div>

I’m trying to configure registry in my fresh rancher 2.0 installation.  
I created a cluster and in Default \>\> Resources \>\> Registries, I added my private registry with scope “Available to all namespaces in this project”.

The registry is a Nexus where I created the kubernetes user. When I try to deploy a pod using this registry, I got :

> 3s 18s 2 spring-cloud-config-c9dddbd6c-4dsnv.15313e7861d9f8a5 Pod spec.containers{spring-cloud-config} Warning Failed kubelet, cebesvc-ba5tit8 Failed to pull image “[myregistry.com:5000/spring-cloud-config:0.1](http://myregistry.com:5000/spring-cloud-config:0.1)”: rpc error: code = Unknown desc = Error: image spring-cloud-config:0.1 not found

I have the impression that the configuration I did in the UI is not really good configured at the cluster level.

Note : I logged in ssh on one of my node, I did a docker login [myregistry.com:5000](http://myregistry.com:5000) with the same user than which used in the rancher registries config and I pulled my image successfully.  
Note 2 : I still have a rancher 1.6 cluster and it’s working there.

Did I missed something in my configuration in rancher 2.0 ?

---

<div class="post-metadata">

**Author:** ![Neil\_Carpenter](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/neil_carpenter/32/4088_2.png) [@Neil\_Carpenter](https://forums.suse.com/u/Neil_Carpenter)\
**Post date:** [May 23, 2018, 9:00pm UTC](https://forums.suse.com/t/private-registry-not-working/10535/2 "2018-05-23T21:00:10Z")

</div>

I had the same issue. In the short term, I manually edited the YAML for the deployment to include:

```
  imagePullSecrets:
  - name: myregistry.com

```

Under the covers, Rancher is creating a k8s secret for the registry credentials and this causes k8s to pull the secret & use it.

I’m not sure how this is supposed to work. I couldn’t find any documentation.

---

<div class="post-metadata">

**Author:** ![Nicolas\_Pepinster](https://avatars.discourse-cdn.com/v4/letter/n/c67d28/32.png) [@Nicolas\_Pepinster](https://forums.suse.com/u/Nicolas_Pepinster)\
**Post date:** [May 24, 2018, 8:53am UTC](https://forums.suse.com/t/private-registry-not-working/10535/3 "2018-05-24T08:53:48Z")

</div>

Do you see a secret “[myregistry.com](http://myregistry.com)” when you type :

> kubectl get secrets --all-namespaces

Because on my side, I don’t see anything so it means maybe that this secret is not created well.

---

<div class="post-metadata">

**Author:** ![Neil\_Carpenter](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/neil_carpenter/32/4088_2.png) [@Neil\_Carpenter](https://forums.suse.com/u/Neil_Carpenter)\
**Post date:** [May 24, 2018, 2:05pm UTC](https://forums.suse.com/t/private-registry-not-working/10535/4 "2018-05-24T14:05:41Z")

</div>

In my case, I do see the Registry secret:

registry default-token-44nhc [kubernetes.io/service-account-token](http://kubernetes.io/service-account-token) 3 1d  
registry myregistrysecret [kubernetes.io/dockerconfigjson](http://kubernetes.io/dockerconfigjson) 1 1d

(Renamed the secret because the forum thinks I want to send spammy links to myregistry dot com…)

---

<div class="post-metadata">

**Author:** ![etlweather](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/etlweather/32/419_2.png) [@etlweather](https://forums.suse.com/u/etlweather)\
**Post date:** [May 28, 2018, 2:23am UTC](https://forums.suse.com/t/private-registry-not-working/10535/5 "2018-05-28T02:23:22Z")

</div>

Not sure how you created a registry with a name like `myregistry.com` - for me it refused the `.` - so my registry is just called `myregistry`.

The solution of `imagePullSecrets` solved it for me, as last for now. I would think it’s not necessary to put this in, but at the same time, it’s not illogical because you could have different teams I guess with different access.

---

<div class="post-metadata">

**Author:** ![Neil\_Carpenter](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/neil_carpenter/32/4088_2.png) [@Neil\_Carpenter](https://forums.suse.com/u/Neil_Carpenter)\
**Post date:** [May 28, 2018, 3:43pm UTC](https://forums.suse.com/t/private-registry-not-working/10535/6 "2018-05-28T15:43:41Z")

</div>

That’s not actually the name of my registry secret – I just changed it to that in this thread.

---

<div class="post-metadata">

**Author:** ![shuckepco](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/shuckepco/32/4610_2.png) [@shuckepco](https://forums.suse.com/u/shuckepco)\
**Post date:** [August 6, 2018, 1:36pm UTC](https://forums.suse.com/t/private-registry-not-working/10535/7 "2018-08-06T13:36:43Z")

</div>

Same with us using an AWS ECR private registry.

Seems to be related to this issue:

> <https://github.com/rancher/rancher/issues/13339>
>
> \*\*Rancher versions:\*\*
> rancher/rancher:master
> 
> Currently using private registr…y with basic authentication will succeed for deploying k8s components but will fail for deploying the pods because kubelet has no idea what credentials are being used and it fails to pull the pause image and pods images.

The issue is currently assigned to the September milestone. Hopefully, it will get fixed then. Only workaround so far is to manually add “imagePullSecrets:…” to each workload YAML definition.

---

<div class="post-metadata">

**Author:** ![govindbmc](https://avatars.discourse-cdn.com/v4/letter/g/ee59a6/32.png) [@govindbmc](https://forums.suse.com/u/govindbmc)\
**Post date:** [April 28, 2020, 6:35am UTC](https://forums.suse.com/t/private-registry-not-working/10535/8 "2020-04-28T06:35:57Z")

</div>

Hi, I am also getting below error while trying to pull image from private registry

ErrImagePull: rpc error: code = Unknown desc = repository [docker.io/XXXXXXXX/XXXXXX](http://docker.io/XXXXXXXX/XXXXXX)  
service not found: does not exist or no pull access
