# Rancher 2 Private Docker Registry?

**URL:** <https://forums.suse.com/t/rancher-2-private-docker-registry/12541>\
**Category:** SUSE Rancher Prime\
**Created:** [November 30, 2018, 6:17am UTC](https://forums.suse.com/t/rancher-2-private-docker-registry/12541 "2018-11-30T06:17:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![LucentBakelite](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/lucentbakelite/32/4663_2.png) [@LucentBakelite](https://forums.suse.com/u/LucentBakelite)\
**Post date:** [November 30, 2018, 6:17am UTC](https://forums.suse.com/t/rancher-2-private-docker-registry/12541/1 "2018-11-30T06:17:57Z")

</div>

I’ve been evaluating Rancher 2 for use in my organization. On my Rancher server, pulling images from the Docker Hub registry works fine,  
but I am having an issue using a private Docker Registry.

**My private Docker registry…**

- [vhdocker.hosp.domain.com](http://vhdocker.hosp.domain.com)
- Valid CA-signed certificate for HTTPS
- Listening on TCP 443
- No user authentication for pushing images to, or pulling images from my private registry
- Using Docker I am able to push images to, and pull images from my private registry

**On my Rancher server I have…**

- Ubuntu 16.04.5 LTS
- Docker version 18.06.1-ce, build e68fc7a
- A Docker container running the latest version of Rancher 2, no other containers
- Added the CA-signed certificate for my private Docker Registry to the Rancher server host, but not the Rancher server container.  
`sudo cp vhdocker.hosp.domain.com.crt /usr/local/share/ca-certificates`  
`sudo update-ca-certificates`

**Steps**

1. I add my private Docker Registry to Rancher server
2. Attempt to deploy a workload from an image in my private registry
3. A pod is created on a node  
At his point I receive a minimum availability error and Rancher server appears unable to pull the image from my private Docker Registry. The following cert related errors are displayed:  
`ImagePullBackOff: Back-off pulling image "vhdocker.hosp.domain.com/myapp"`

`ErrImagePull: rpc error: code = Unknown desc = Error response from daemon: Get https://vhdocker.hosp.domain.com/v2/: x509: certificate signed by unknown authority`

When running the Rancher server container with Docker is there a procedure I need to perform to pass the cert for my private Docker Registry to Rancher? Something like:  
`--env REGISTRY_CERTIFICATE=/mnt/certs/vhdocker.hosp.domain.com`

Thanks.

**Screenshots:**

 ![reg1](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/6/6b521817a1f8944d4f837a62000b5a0025bfa67a.png) ![reg2](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/9/9da1e82907380608300824d375a122fc1c86fd3c.png) ![reg3](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/c/c82c2d6a8b0ec676a774c7e0ea54a8edce82d646.png) ![rancher1](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/9/99cd1ba92698f12a2fd5b2040fd942968fb5861c.png) ![rancher2](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/f/f781c5863487058823fc26d0d454ef9e5803ae65.png)

---

<div class="post-metadata">

**Author:** ![LucentBakelite](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/lucentbakelite/32/4663_2.png) [@LucentBakelite](https://forums.suse.com/u/LucentBakelite)\
**Post date:** [November 30, 2018, 8:37pm UTC](https://forums.suse.com/t/rancher-2-private-docker-registry/12541/2 "2018-11-30T20:37:20Z")

</div>

After a week of trial-and-error and some Googling I figured it out.

`ImagePullBackOff:`

To me the above indicated the issue was with Rancher-Kubernetes. Turns out this was actually Docker related.

On the host that will be running the Rancher agent container, prior to pulling the rancher agent image and running it as a container, add the certificate for your private Docker Registry to the trusted certificates on the host; then, this is the crucial part **—restart the Docker daemon.**

`cp /mnt/certs/vhdocker.hosp.domain.com.crt /usr/local/share/ca-certificates/`  
`update-ca-certificates`  
`systemctl restart docker.service`  
`ls /etc/ssl/certs | awk /vhdocker.hosp/`

_(Not sure if it’s necessary, but I also did this on the host that will be running my Rancher server container)_

**Steps**

1. Install private Docker registry cert on host that will run the Rancher server container
2. Restart Docker daemon
3. Run Rancher server image as a container
4. Install private Docker registry cert on host that will run the Rancher client container
5. Restart Docker daemon
6. Run Rancher client image as a container

After this I was able to deploy a workload from an image in my private Docker Registry.

---

<div class="post-metadata">

**Author:** ![john.b.sims](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/john.b.sims/32/3925_2.png) [@john.b.sims](https://forums.suse.com/u/john.b.sims)\
**Post date:** [December 3, 2018, 6:19pm UTC](https://forums.suse.com/t/rancher-2-private-docker-registry/12541/3 "2018-12-03T18:19:05Z")

</div>

We encountered the same issue. Unfortunately, I think this also means anytime you have Rancher create a new node in a cluster, you’ll need to perform those same steps on the newly-created host before you can actually pull from your registry. I think the best practice is to avoid using any sort of self-signed certs so that Docker can recognize the cert on the registry automatically.
