# How do I add private GCP Google Container Registry (GCR) images in my application?

**URL:** <https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125>\
**Category:** Packaging an application\
**Created:** [April 25, 2018, 8:51pm UTC](https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125 "2018-04-25T20:51:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethanm](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/ethanm/32/11_2.png) [@ethanm](https://community.replicated.com/u/ethanm)\
**Post date:** [April 25, 2018, 8:51pm UTC](https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125/1 "2018-04-25T20:51:15Z")

</div>

GCR doesn’t support basic authentication like other registries that conform to the Docker registry spec? How can I add credentials to the Vendor Portal for GCR?

---

<div class="post-metadata">

**Author:** ![ethanm](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/ethanm/32/11_2.png) [@ethanm](https://community.replicated.com/u/ethanm)\
**Post date:** [April 25, 2018, 10:57pm UTC](https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125/2 "2018-04-25T22:57:58Z")

</div>

Replicated allows for integration with the Google Container Registry (GCR) through the [JSON Key](https://cloud.google.com/container-registry/docs/advanced-authentication#using_a_json_key_file) authentication mechanism.

In Google Cloud Platform you must first set up a Service Account with permissions to [pull from the GCR repo](https://cloud.google.com/container-registry/docs/access-control) by giving that account the “Storage Object Viewer” role.

 ![gcr_create_sa](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/9d86353085633037cef99f5cfd6885bdfa3e5ba2.png)

You can then create a JSON key from that Service Account. When prompted for key type, make sure to select “JSON” before creating. After clicking create, a JSON file will be downloaded in your browser. This file will be used in the next step.

 ![gcr_create_json_key](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/4d9a107531f6ab7cc01ce65b9e3d2db11f2fce0b.png)

Under your application in the Replicated Vendor Portal, you will have the option of adding external registries. Under Username you must specify “\_json\_key”. Use the contents of the key file, omitting line breaks, in the field Password. Email Address in this case is ignored. Please note that GCR has [multiple hostnames](https://cloud.google.com/container-registry/docs/pushing-and-pulling#choosing_a_registry_name) which are not interchangeable, so be sure to add the correct one to the Endpoint field.

 ![gcr_add_reg](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/58f9582ea68716ccd38a9bdf997ccbd80eabd54f.png)

Once you have added GCR as an external registry you can use the image in your Kubernetes manifests.

---

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [January 21, 2020, 1:08pm UTC](https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125/3 "2020-01-21T13:08:08Z")

</div>

I’ll add for removing whitespace from the JSON Key file, `jq` is quite handy:

```auto
cat ~/downloads/replicated-1321312asa.json | jq -r -c -M . | pbcopy  

```

---

<div class="post-metadata">

**Author:** ![Dan\_Peleg](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dan_peleg/32/185_2.png) [@Dan\_Peleg](https://community.replicated.com/u/Dan_Peleg)\
**Post date:** [August 15, 2021, 3:56pm UTC](https://community.replicated.com/t/how-do-i-add-private-gcp-google-container-registry-gcr-images-in-my-application/125/4 "2021-08-15T15:56:23Z")

</div>

How should it look on the yaml file?

```auto
images:
- source: replicated
  name: api
  tag: v2.28.0

# kind: scheduler-kubernetes
apiVersion: apps/v1
kind: Deployment
spec:
      imagePullSecrets:
      - name: replicatedregistrykey
      containers:
        - name: globekeeper-api
          image: gcr.io/globekeeper-production/api:v2.28.0

```

Gives me the following error:

```auto
Failed to pull registry.replicated.com/globekeeper/api:v2.28.0: API error (404): {"message":"manifest for registry.replicated.com/globekeeper/api:v2.28.0 not found: manifest unknown: Manifest not found"}

```
