# Create ImagePullSecrets for the Proxy Service in multiple namespaces

**URL:** <https://community.replicated.com/t/create-imagepullsecrets-for-the-proxy-service-in-multiple-namespaces/1295>\
**Category:** How do I?\
**Tags:** kots\
**Created:** [September 20, 2023, 2:53pm UTC](https://community.replicated.com/t/create-imagepullsecrets-for-the-proxy-service-in-multiple-namespaces/1295 "2023-09-20T14:53:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lukasz\_Werenkowicz](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/lukasz_werenkowicz/32/694_2.png) [@Lukasz\_Werenkowicz](https://community.replicated.com/u/Lukasz_Werenkowicz)\
**Post date:** [September 20, 2023, 2:53pm UTC](https://community.replicated.com/t/create-imagepullsecrets-for-the-proxy-service-in-multiple-namespaces/1295/1 "2023-09-20T14:53:14Z")

</div>

Hi team!  
Is it possible to parametrise [addtionalNamespaces](https://docs.replicated.com/vendor/operator-defining-additional-namespaces#creating-additional-namespaces) ? I need to have the application image pull secret in proper namespaces. By proper namespaces, I mean namespaces created dynamically (defined within `kots-config.yaml`).  
In theory, I can use the wildcard (`"*"` ) but it may be a problem in restricted environments (eg. access to a single namespace only).  
Or maybe there is an easy way to create a secret with credentials to the proxy service? (I need this guy `replicated-pull-secret` in all my namespaces)  
Something similar to this one:

```auto
apiVersion: v1
kind: Secret
metadata:
  name: myregistrykey
  namespace: awesomeapps
data:
  .dockerconfigjson: '{{repl LocalRegistryImagePullSecret }}'
type: kubernetes.io/dockerconfigjson

```

but for proxy

---

<div class="post-metadata">

**Author:** ![Lukasz\_Werenkowicz](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/lukasz_werenkowicz/32/694_2.png) [@Lukasz\_Werenkowicz](https://community.replicated.com/u/Lukasz_Werenkowicz)\
**Post date:** [September 20, 2023, 3:43pm UTC](https://community.replicated.com/t/create-imagepullsecrets-for-the-proxy-service-in-multiple-namespaces/1295/2 "2023-09-20T15:43:43Z")

</div>

OK, I can partially answer on my question.  
It seems that I can use the above secret, it points on proxy server when deployed in non-airgapped env.

…but it would be nice if kots would do it for me automatically within `additionalNamespaces`

---

<div class="post-metadata">

**Author:** ![jdewinne](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/jdewinne/32/152_2.png) [@jdewinne](https://community.replicated.com/u/jdewinne)\
**Post date:** [September 20, 2023, 4:37pm UTC](https://community.replicated.com/t/create-imagepullsecrets-for-the-proxy-service-in-multiple-namespaces/1295/3 "2023-09-20T16:37:51Z")

</div>

Hi @Lukasz_Werenkowicz

Thanks for already partially answering your question. 🙏  
You are correct The [additionalNamespaces](https://docs.replicated.com/reference/custom-resource-application#additionalnamespaces) at this moment does not support go templating. This means that they have to be `static`, or you use `"*"`.

If you create namespaces in a dynamic way, you’ll have to also ensure the pull secret is created, which is very similar to using [operators](https://docs.replicated.com/vendor/operator-referencing-images#determining-the-imagepullsecret) with kots.

Additionally, you might want to check how to [manage namespaces in a secured environment](https://community.replicated.com/t/managing-custom-namespaces-in-a-secured-environment/922). In many situations you’re not allowed to create additional namespaces, and sometimes everything has to be deployed in a single namespace.
