# \[1.0.0-rc1\] How to pull image from private registry and execute commands in it

**URL:** <https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665>\
**Category:** Drone Support\
**Created:** [November 23, 2018, 7:18pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665 "2018-11-23T19:18:25Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![yellowmegaman](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/yellowmegaman/32/3786_2.png) [@yellowmegaman](https://drone.discourse.group/u/yellowmegaman)\
**Post date:** [November 23, 2018, 7:18pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/1 "2018-11-23T19:18:25Z")

</div>

Hello!

In drone 0.8.X i was able to pull some image and run commands in it. Like this:

```auto
pipeline:
  build:
    image: gcr.io/my-project-001/sbt:latest
    commands:
      - env | sort
    when:
      event: [push, pull_request, tag]

```

It just needed to have registry credentials added per repo.

How can it be achieved with 1.0.0?  
[https://docs.drone.io/config/pipeline/steps/](https://docs.drone.io/config/pipeline/steps/) states that:

```auto
If the image is private you will need to configure registry credentials.

```

But how?  
Tried to add:

```auto
  settings:
    username:
      from_secret: docker_username
    password:
      from_secret: docker_password

```

and different variations of it to no avail.

Thanks a bunch in advance!

---

<div class="post-metadata">

**Author:** ![flah00](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/flah00/32/5854_2.png) [@flah00](https://drone.discourse.group/u/flah00)\
**Post date:** [November 29, 2018, 8:42pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/2 "2018-11-29T20:42:53Z")

</div>

I’m running into the same problem, but as a service which relies on kubernetes-secrets. My env vars are populated, the settings stanza doesn’t affect my pull tho.

```auto
kind: pipeline
name: default
steps:
  - name: test
    image: clojure
    pull: always
    commands:
      - env
      - ./scripts/test.sh
    environment:
      LEIN_USERNAME:
        from_secret: aws_key_id
      LEIN_PASSPHRASE:
        from_secret: aws_secret

services:
  - name: redis
    image: quay.io/ORG/redis:3.0
    pull: always
    settings:
      username:
        from_secret: ORG_user
      password:
        from_secret: ORG_password
---
kind: secret

external_data:
  aws_key_id:
    path: drone-ORG
    name: aws_key_id_prod
  aws_secret:
    path: drone-ORG
    name: aws_secret_prod
  ORG_user:
    path: drone-ORG
    name: ORG_user
  ORG_password:
    path: drone-ORG
    name: ORG_password

```

---

<div class="post-metadata">

**Author:** ![yellowmegaman](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/yellowmegaman/32/3786_2.png) [@yellowmegaman](https://drone.discourse.group/u/yellowmegaman)\
**Post date:** [November 29, 2018, 9:05pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/3 "2018-11-29T21:05:12Z")

</div>

With 0.8 i was able to solve my issues by just viewing code. Like with autoscaler params. But it isn’t available yet, too ;(

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 3:31pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/4 "2019-03-26T15:31:50Z")

</div>

help me. [drone.io](http://drone.io) 1.0  
image: [xxyyregistry.azurecr.io/ci/yelp:0.0.1](http://xxyyregistry.azurecr.io/ci/yelp:0.0.1)  
settings:  
username:  
from\_secret: registry\_username  
password:  
from\_secret: registry\_password  
commands:  
- ls  
- detect-secrets scan  
when:  
event:  
- push  
branch:  
- develop  
- seguridad

THIS NO WORK!!!  
my keys registry azure: registry\_username, registry\_password  
yaml: line 54: did not find expected key

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [March 26, 2019, 3:33pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/5 "2019-03-26T15:33:56Z")

</div>

the syntax in your example is not valid. To pull a private image see the following thread [How to pull private images with 1.0](http://discuss.harness.io/t/how-to-pull-private-images-with-1-0/3155)

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 3:51pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/6 "2019-03-26T15:51:15Z")

</div>

for example, help me

i´m use [drone.io](http://drone.io) 1.0  
one step of my pipeline

image: [xxyyregistry.azurecr.io/ci/yelp:0.0.1](http://xxyyregistry.azurecr.io/ci/yelp:0.0.1)  
image\_pull\_secrets:

- registry\_username
- registry\_password  
commands:
- echo “start”
- ls
- detect-secrets scan
- echo “the end”  
when:  
event:
- push  
branch:
- develop
- seguridad

THIS NO WORK!!!  
my keys registry azure: registry\_username, registry\_password  
did not find expected key  
i’m not access drone cli, only UI

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [March 26, 2019, 3:53pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/7 "2019-03-26T15:53:05Z")

</div>

the syntax in your second example does not match what was described in [How to pull private images with 1.0](http://discuss.harness.io/t/how-to-pull-private-images-with-1-0/3155). Also note that are expected to store a json string with credentials, not a username and password (this is also described in the link I posted).

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 5:36pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/8 "2019-03-26T17:36:55Z")

</div>

how can i get that token for the json file? (My record is azure).  
In drone version 0.8 in the UI you could register the following Registry Address, Resgistry Username, Registry Password. (Now in version 1.0 this option does not appear)  
I usually access docker login\_server -username registry\_username -password regstry\_passwod

auth value???

{  
“auths”: {  
“[https://index.docker.io/v1/](https://index.docker.io/v1/)”: {  
“auth”: “YW11cmRhY2E6c3VwZXJzZWNyZXRwYXNzd29yZA==”  
}  
}  
}  
drone 0.8  
 ![image](https://canada1.discourse-cdn.com/flex003/uploads/testdrone/original/2X/f/f202b6d367376dde607638e2f4727e8794020ecb.png)

---

<div class="post-metadata">

**Author:** ![orhanhenrik](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/orhanhenrik/32/4926_2.png) [@orhanhenrik](https://drone.discourse.group/u/orhanhenrik)\
**Post date:** [March 26, 2019, 6:05pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/9 "2019-03-26T18:05:08Z")

</div>

> [@Drone build failing on clone step with Kubernetes runner](https://drone.discourse.group/t/drone-build-failing-on-clone-step-with-kubernetes-runner/3057/8):
>
> how can i get that token for the json file?

You can use the `docker login [registry]` command on a system with docker, then check `~/.docker/config.json` file for the token. docker login will prompt you for username and password.

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [March 26, 2019, 6:08pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/10 "2019-03-26T18:08:22Z")

</div>

> [@Drone build failing on clone step with Kubernetes runner](https://drone.discourse.group/t/drone-build-failing-on-clone-step-with-kubernetes-runner/3057/8):
>
> how can i get that token for the json file?

I think perhaps there is still a misunderstanding … you should upload your json file as a secret, and then reference the named secret in `image_pull_secrets`. Drone expects the full json string as the secret value.

You can find the json file at `~/.docker/config.json` after running `docker login`. I recommend running this command on a linux machine.

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 6:23pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/11 "2019-03-26T18:23:43Z")

</div>

hi, tanks you  
my step pipeline is

- name: secretsecurity  
image: [xxyyregistry.azurecr.io/ci/yelp:0.0.1](http://xxyyregistry.azurecr.io/ci/yelp:0.0.1)  
commands:
  - ls
  - detect-secrets scan  
image\_pull\_secrets:
  - dockerconfigjson  
when:  
event:
  - push  
branch:
  - develop
  - release
  - master
  - seguridad  
my file json is test: dockerconfigjson

{  
“auths”: {  
“[https://xxyyregistry.azurecr.io](https://xxyyregistry.azurecr.io)”: {  
“auth”: “cmVnaXN0cnlfdXNlcm5hbWU6cmVnaXN0cnlfcGFzc3dvcmQK”  
}  
}  
}  
Question:  
What is the path where I must place my json file in drone so that I can take the changes?

---

<div class="post-metadata">

**Author:** ![orhanhenrik](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/orhanhenrik/32/4926_2.png) [@orhanhenrik](https://drone.discourse.group/u/orhanhenrik)\
**Post date:** [March 26, 2019, 6:31pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/12 "2019-03-26T18:31:30Z")

</div>

Create a secret like this

 ![image](https://canada1.discourse-cdn.com/flex003/uploads/testdrone/original/2X/b/bd9007e7cf7769a390e5a03884378b0e12ce5197.png)

Also I think image\_pull\_secrets needs to be outside the step definition. Put it in the bottom of the .drone.yaml file like in the linked post.

```auto
kind: pipeline
name: default

steps:
- name: build
  image: registry.company.com/my/image
  commands:
  - go build
  - go test

image_pull_secrets:
- dockerconfigjson

```

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 8:20pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/13 "2019-03-26T20:20:18Z")

</div>

default: Error response from daemon: Get [https://xxyyregistry.azurecr.io/v2/ci/yelp/manifests/0.0.1:](https://xxyyregistry.azurecr.io/v2/ci/yelp/manifests/0.0.1:) unauthorized: authentication required

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 26, 2019, 9:05pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/14 "2019-03-26T21:05:05Z")

</div>

this no work

diff Create a secret / create registry secret

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [March 26, 2019, 9:21pm UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/15 "2019-03-26T21:21:07Z")

</div>

I can confirm it works when properly configured – we are using this internally. You can audit the source code and unit tests to learn more about how this behaves:

- [https://github.com/drone/drone/blob/master/plugin/registry/static.go](https://github.com/drone/drone/blob/master/plugin/registry/static.go)
- [https://github.com/drone/drone/blob/master/plugin/registry/static\_test.go](https://github.com/drone/drone/blob/master/plugin/registry/static_test.go)

---

<div class="post-metadata">

**Author:** ![asdrubalos](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@asdrubalos](https://drone.discourse.group/u/asdrubalos)\
**Post date:** [March 27, 2019, 1:31am UTC](https://drone.discourse.group/t/1-0-0-rc1-how-to-pull-image-from-private-registry-and-execute-commands-in-it/10665/16 "2019-03-27T01:31:03Z")

</div>

i’m sorry.  
tank’s  
its work now

in end file…  
image\_pull\_secrets:

- dockerconfigjson
