# Unable to push to Google Container Registry

**URL:** <https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792>\
**Category:** Drone Support\
**Created:** [December 4, 2017, 10:25am UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792 "2017-12-04T10:25:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ichiaohsu](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/ichiaohsu/32/3532_2.png) [@ichiaohsu](https://drone.discourse.group/u/ichiaohsu)\
**Post date:** [December 4, 2017, 10:25am UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/1 "2017-12-04T10:25:24Z")

</div>

I’m trying to use image plugins/gcr to build and push docker to [gcr.io](http://gcr.io) for our project. Drone keeps giving me this error:

```bash
Successfully built a30e54b18226
Successfully tagged 115af9cc00fb81d25e903b7246edc0de61426031:latest
+ /usr/local/bin/docker tag 115af9cc00fb81d25e903b7246edc0de61426031 gcr.io/project-id/repo:latest
+ /usr/local/bin/docker push gcr.io/project-id/repo:latest
The push refers to a repository [gcr.io/project-id/repo]
3a67be3257c8: Preparing
f082cd9df19a: Preparing
4e0b03ab20f4: Preparing
3179dff912f9: Preparing
0a6cba3d2445: Preparing
11f8b35f152b: Preparing
6bc5936494e3: Preparing
11f8b35f152b: Waiting
6bc5936494e3: Waiting
time="2017-12-04T09:59:45.851797448Z" level=error msg="Upload failed: denied: Unable to access the repository, please check that you have permission to access it." 
time="2017-12-04T09:59:45.854964304Z" level=info msg="Attempting next endpoint for push after error: denied: Unable to access the repository, please check that you have permission to access it." 
denied: Unable to access the repository, please check that you have permission to access it.
time="2017-12-04T09:59:45Z" level=fatal msg="exit status 1"

```

It seems plugins/gcr use `docker push`, but I can’t use this command for publishing to gcr. Is there any version of plugins using `gcloud docker -- push` command to publish docker to gcr?

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [December 4, 2017, 4:14pm UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/2 "2017-12-04T16:14:04Z")

</div>

The gcr plugin uses the docker push command in conjunction with the \_json\_key as described in the official documentation [1].

This particular plugin does not use the gcloud command. If you need to use the gcloud command line tools to push images, we would recommend that you create your own custom plugin.

[1] [https://cloud.google.com/container-registry/docs/advanced-authentication#using\_a\_json\_key\_file](https://cloud.google.com/container-registry/docs/advanced-authentication#using_a_json_key_file)

---

<div class="post-metadata">

**Author:** ![ichiaohsu](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/ichiaohsu/32/3532_2.png) [@ichiaohsu](https://drone.discourse.group/u/ichiaohsu)\
**Post date:** [December 5, 2017, 6:36am UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/3 "2017-12-05T06:36:19Z")

</div>

Thank you for clarification. I tried to use docker login in simple linux environment and it worked! I think it’s the authentication problem. I use `drone secret add` to inject password to plugins/gcr as below:

```bash
drone secret add \
--repository my-github-account/my-repo \ 
--name google_key \
--value @/absolute/path/to/file/keyfile.json

```

Is this the right way to add new secret to drone server? My gcr setting is like this:

```bash
publish:
    image: plugins/gcr
    repo: gcr-project-id/repo-name
    tag: latest
    previleged: true
    environment:
      - DOCKER_LAUNCH_DEBUG=true
    token: >
      $$GOOGLE_KEY
    storage_driver: vfs
```

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [December 5, 2017, 8:02am UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/4 "2017-12-05T08:02:46Z")

</div>

this is not the correct syntax:

```auto
    token: >
      $$GOOGLE_KEY

```

Please see the following documentation for the correct secret syntax:

- [http://docs.drone.io/manage-secrets/](http://docs.drone.io/manage-secrets/)
- [http://plugins.drone.io/drone-plugins/drone-gcr/](http://plugins.drone.io/drone-plugins/drone-gcr/)

---

<div class="post-metadata">

**Author:** ![ichiaohsu](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/ichiaohsu/32/3532_2.png) [@ichiaohsu](https://drone.discourse.group/u/ichiaohsu)\
**Post date:** [December 5, 2017, 10:20am UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/5 "2017-12-05T10:20:09Z")

</div>

It worked if I use json\_key and directly paste the content of service account json token there like:

```bash
json_key: >
  {
    "type": "service_account",
    ......
    ......
   }

```

But I still couldn’t use the secret I add like this:

```bash
json_key: >
  $$GOOGLE_KEY

```

$$GOOGLE\_KEY are mentioned here:

- [https://github.com/drone-plugins/drone-gcr/blob/master/DOCS.md#json-token](https://github.com/drone-plugins/drone-gcr/blob/master/DOCS.md#json-token)

Is this wrong way to inject secret?

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [December 5, 2017, 3:49pm UTC](https://drone.discourse.group/t/unable-to-push-to-google-container-registry/5792/6 "2017-12-05T15:49:03Z")

</div>

> But I still couldn’t use the secret I add like this:

You cannot add the secret using the `$$GOOGLE_KEY` syntax because it is not the correct syntax. Please see these links which detail how to use secrets and include examples with the correct syntax:

- [http://docs.drone.io/manage-secrets/1](http://docs.drone.io/manage-secrets/1)
- [http://plugins.drone.io/drone-plugins/drone-gcr/1](http://plugins.drone.io/drone-plugins/drone-gcr/1)
