# How to pull private images with 1.0

**URL:** <https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329>\
**Category:** Drone FAQ\
**Created:** [December 6, 2018, 7:56pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329 "2018-12-06T19:56:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [December 6, 2018, 7:56pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/1 "2018-12-06T19:56:52Z")

</div>

I have not had time to document this yet, so I figured I would write a quick post. If you are coming from Drone 0.8 you may be wondering how to configure credentials required to pull private images defined in your yaml, for example:

```nohighlight
kind: pipeline
name: default

steps:
- name: build
  image: registry.company.com/my/image
  commands:
  - go build
  - go test

```

In the above example, `registry.company.com/my/image` is a private registry and requires username and password to pull the image. To provide Drone with the credentials you need to create a secret named `dockerconfigjson`, where the secret value is valid docker configuration file with your authentication credentials.

NOTE _when you add the registry credentials as a secret you probably need to enable the secret for pull requests. I am pretty sure this is required, but I might be wrong. So for the moment, assume this is required._

The docker configuration file should look something like this:

```auto
{
	"auths": {
		"https://index.docker.io/v1/": {
			"auth": "YW11cmRhY2E6c3VwZXJzZWNyZXRwYXNzd29yZA=="
		}
	}
}

```

You can then reference this secret in your yaml

```nohighlight
kind: pipeline
name: default

steps:
- name: build
  image: registry.company.com/my/image
  commands:
  - go build
  - go test

image_pull_secrets:
- dockerconfigjson

```

If you are unfamiliar with this file please consult the official Docker documentation. Do not try to construct this file by hand. There is also a nice article about the config file format here: [https://www.projectatomic.io/blog/2016/03/docker-credentials-store/](https://www.projectatomic.io/blog/2016/03/docker-credentials-store/)

**Troubleshooting**  
If you are having difficulty with registry secrets please provide the following:

1. version of Drone you are using
2. a copy of your yaml configuration file.
3. the output of `drone secret info <repo> --name=<secret>` for your secret
4. the output of `drone build info <repo> <build>` for your build
5. the output of your Drone runner logs with trace logging enabled
6. the output of your Docker daemon logs
7. if the build is a pull request, check to make sure the secret is enabled for pull requests.
8. if your registry is insecure, make sure the docker daemon is configured properly. [https://docs.docker.com/registry/insecure/](https://docs.docker.com/registry/insecure/)

* * *

## Option 2

The second option would be to pass this file to the agent. This will make the credentials available globally to all builds and all repositories. First you would mount the config file into your agent container:

```nohighlight
docker run \
-v /root/.docker/config.json:/root/.docker/config.json

```

Then you need to pass the agent the path of the mounted file:

```nohighlight
docker run \
-e DRONE_DOCKER_CONFIG=/root/.docker/config.json

```

---

<div class="post-metadata">

**Author:** ![mhumeSF](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mhumesf/32/3632_2.png) [@mhumeSF](https://drone.discourse.group/u/mhumeSF)\
**Post date:** [January 25, 2019, 11:08pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/3 "2019-01-25T23:08:27Z")

</div>

@bradrydzewski Per option 2, this is just going forward with 1.0? This doesn’t working with 0.8 currently, yea?

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [January 25, 2019, 11:09pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/4 "2019-01-25T23:09:54Z")

</div>

correct, this thread is only applicable for 1.0

---

<div class="post-metadata">

**Author:** ![offroff](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/offroff/32/6018_2.png) [@offroff](https://drone.discourse.group/u/offroff)\
**Post date:** [January 29, 2019, 7:37am UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/5 "2019-01-29T07:37:22Z")

</div>

Are you sure about the name of the secret? .dockerconfigjson starts with a dot and that’s not allowed for docker secrets nor kubernetes secrets.

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [January 29, 2019, 3:30pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/6 "2019-01-29T15:30:00Z")

</div>

yes, I am sure this is the correct secret name in Drone.

---

<div class="post-metadata">

**Author:** ![myers](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/myers/32/4881_2.png) [@myers](https://drone.discourse.group/u/myers)\
**Post date:** [February 1, 2019, 3:02pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/7 "2019-02-01T15:02:49Z")

</div>

I was able to get this to work on my drone projects. Thanks for this, since global registry creds with k8s are currently undocumented I was having to pull the private base images by hand.

---

<div class="post-metadata">

**Author:** ![benwilson512](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/benwilson512/32/4491_2.png) [@benwilson512](https://drone.discourse.group/u/benwilson512)\
**Post date:** [February 2, 2019, 2:50pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/8 "2019-02-02T14:50:58Z")

</div>

I’d be curious to see a version of this that worked with something like AWS ECR that requires regularly refreshing the token.

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [February 2, 2019, 4:41pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/9 "2019-02-02T16:41:45Z")

</div>

AWS ECR does not work using the methods described in this thread, because as you mentioned, it requires special logic to periodically generate docker credentials. You therefore need to use a plugin for this. There is a thread that discusses this in depth:  
[http://discuss.harness.io/t/drone-1-0-and-aws-ecr-going-forward/3071](http://discuss.harness.io/t/drone-1-0-and-aws-ecr-going-forward/3071)

And in one of the comments a community-member posts a plugin they created:  
[https://github.com/davidbyttow/drone-ecr-registry-plugin](https://github.com/davidbyttow/drone-ecr-registry-plugin)

---

<div class="post-metadata">

**Author:** ![developerdino](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/developerdino/32/4462_2.png) [@developerdino](https://drone.discourse.group/u/developerdino)\
**Post date:** [March 25, 2019, 5:00am UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/10 "2019-03-25T05:00:14Z")

</div>

Posting this here as a reminder for myself and incase anyone else hits this issue.

When using option 1 to authenticate make sure you paste the contents of your `dockerconfigjson` file into the Drone `settings` -\> `secrets` for you application and not the kubernetes configuration secrets.

This seems obvious to me now but I wasted several hours trying to work this out. Hopefully it saves someone else some time.

---

<div class="post-metadata">

**Author:** ![kody-abe](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/kody-abe/32/3037_2.png) [@kody-abe](https://drone.discourse.group/u/kody-abe)\
**Post date:** [April 4, 2019, 3:47am UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/11 "2019-04-04T03:47:27Z")

</div>

@bradrydzewski Is there an official drone way to pull and use AWS ECR images for steps for 1.0? Or do you have a recommendation for that given the AWS login credential fun I can’t just use dockerconfigjson.

Any ideas?

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [April 4, 2019, 1:02pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/12 "2019-04-04T13:02:34Z")

</div>

you can use a registry plugin to provide the agent with ecr credentials:

> **[GitHub - davidbyttow/drone-ecr-registry-plugin](https://github.com/davidbyttow/drone-ecr-registry-plugin)**
>
> Contribute to davidbyttow/drone-ecr-registry-plugin development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![kody-abe](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/kody-abe/32/3037_2.png) [@kody-abe](https://drone.discourse.group/u/kody-abe)\
**Post date:** [April 4, 2019, 3:13pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/13 "2019-04-04T15:13:55Z")

</div>

I forgot to mention I am running on Kubernetes native, so I think that complicates things a bit right? Thanks for your quick response on this!

---

<div class="post-metadata">

**Author:** ![kody-abe](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/kody-abe/32/3037_2.png) [@kody-abe](https://drone.discourse.group/u/kody-abe)\
**Post date:** [April 4, 2019, 3:21pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/14 "2019-04-04T15:21:23Z")

</div>

Actually, it looks like since our Kubernetes cluster already has permissions to our AWS ECR, I can just reference the image normally and it pulls it without any issue. Wish I would have just tried that first 😂

---

<div class="post-metadata">

**Author:** ![kody-abe](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/kody-abe/32/3037_2.png) [@kody-abe](https://drone.discourse.group/u/kody-abe)\
**Post date:** [April 4, 2019, 3:39pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/15 "2019-04-04T15:39:38Z")

</div>

Side note @bradrydzewski - Looks like on kubernetes native when `pull: true` is set is is still using an old version of the image, is this a known issue or am I missing something?

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [April 4, 2019, 3:45pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/16 "2019-04-04T15:45:05Z")

</div>

> [@On another topic](https://drone.discourse.group/t/3155/15):
>
> is this a known issue or am I missing something?

`pull: true` is not valid syntax for 1.0 (it was for 0.8). Instead you should use one of the following values:

```auto
pull: always
pull: if-not-exists
pull: never

```

_Reference:_ [https://docs.drone.io/pipeline/docker/syntax/steps/](https://docs.drone.io/user-guide/pipeline/steps/#pull)

---

<div class="post-metadata">

**Author:** ![kody-abe](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/kody-abe/32/3037_2.png) [@kody-abe](https://drone.discourse.group/u/kody-abe)\
**Post date:** [April 4, 2019, 3:46pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/17 "2019-04-04T15:46:32Z")

</div>

Welp, it must be too early for me or something. Thanks again!

---

<div class="post-metadata">

**Author:** ![andrexus](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/andrexus/32/4812_2.png) [@andrexus](https://drone.discourse.group/u/andrexus)\
**Post date:** [April 10, 2019, 3:48pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/18 "2019-04-10T15:48:37Z")

</div>

The first option doesn’t seem to work with kubernetes scheduler

---

<div class="post-metadata">

**Author:** ![madsonic](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/madsonic/32/6115_2.png) [@madsonic](https://drone.discourse.group/u/madsonic)\
**Post date:** [April 19, 2019, 5:44pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/19 "2019-04-19T17:44:37Z")

</div>

For those with default credential store enabled, in order to get the config file bradrydzewski mentioned

1. logout of docker
2. remove credStore
3. login to docker again

```auto
docker logout
# locate your docker config file. path should be ~/.docker/config.json
# and remove "credsStore": "xyz",
docker login --username # will prompt for password
# open ~/.docker/config.json again
# make a secret on drone with the content of the file, using only the auth part mentioned above

```

And for those rebellious enough, you can skip the hassle above by base64 encoding your credentials

```auto
cat <<EOF >> dockerconfigjson
{
	"auths": {
		"https://index.docker.io/v1/": {
			"auth": "$(base64 --input=credfile)"
		}
	}
}
EOF

```

```auto
# credfile content
username:password

```

---

<div class="post-metadata">

**Author:** ![john36711](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/john36711/32/5131_2.png) [@john36711](https://drone.discourse.group/u/john36711)\
**Post date:** [April 29, 2019, 7:34am UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/20 "2019-04-29T07:34:04Z")

</div>

Excuse me! I add the dockerconfigjson’s value to drone -\> setting -\> secrets but when i push my git ,my private image still pull error ,my drone server image version is 1 ,if you can help me i will very thankful !!

---

<div class="post-metadata">

**Author:** ![Phibedy](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@Phibedy](https://drone.discourse.group/u/Phibedy)\
**Post date:** [May 4, 2019, 10:23pm UTC](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329/21 "2019-05-04T22:23:25Z")

</div>

What is the best way to pull from aws ecr?  
Is there no useful plugin like the drone-ecr?  
I came up with a rather complicated cron-job version gathering the login data.

There is no DRONE\_DOCKER\_CONFIG: [https://docs.drone.io/reference/server/](https://docs.drone.io/reference/server/)

[Next page](https://drone.discourse.group/t/how-to-pull-private-images-with-1-0/11329.md?page=2)
