# Private dockerhub registry: Failed to pull image

**URL:** <https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191>\
**Category:** Troubleshooting\
**Created:** [July 19, 2018, 2:10pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191 "2018-07-19T14:10:06Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaismacc](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaismacc](https://community.replicated.com/u/kaismacc)\
**Post date:** [July 19, 2018, 2:10pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/1 "2018-07-19T14:10:06Z")

</div>

Hi there:

I set up an external registry named “docker” with endpoint “[docker.com](http://docker.com)” to let the replicated access my containers in dockerhub. In the K8s YAML I’m referencing my images as “COMPANYNAME/IMAGE”. I always get “Failed to pull image” errors.

What might be the problem?

---

<div class="post-metadata">

**Author:** ![dmitriy](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dmitriy/32/16_2.png) [@dmitriy](https://community.replicated.com/u/dmitriy)\
**Post date:** [July 19, 2018, 2:23pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/2 "2018-07-19T14:23:09Z")

</div>

`index.docker.io` should be the correct endpoint for DockerHub registry

---

<div class="post-metadata">

**Author:** ![kaismacc](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaismacc](https://community.replicated.com/u/kaismacc)\
**Post date:** [July 19, 2018, 2:44pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/3 "2018-07-19T14:44:16Z")

</div>

Thanks, I changed it, but I still have the same problem. Do I need to prefix the images with the [docker.io](http://docker.io)?

---

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [July 19, 2018, 2:48pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/4 "2018-07-19T14:48:36Z")

</div>

You’ll also need to make sure you’ve filled out the `images` section as described in [Docker Registries](https://help.replicated.com/docs/kubernetes/getting-started/docker-registries/#referencing-images-from-the-replicated-registry-and-private-registries) and added the `replicatedregistrykey` image pull secret.

---

<div class="post-metadata">

**Author:** ![kaismacc](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaismacc](https://community.replicated.com/u/kaismacc)\
**Post date:** [July 19, 2018, 4:16pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/5 "2018-07-19T16:16:59Z")

</div>

After doing the changes to the images section, I can see the dashboard downloading the images, but the pods still get `Error: ErrImagePull` on the pods.

---

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [July 19, 2018, 4:24pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/6 "2018-07-19T16:24:44Z")

</div>

You’ll need to also ensure that the pods have the registry key set as a secret (also in the doc). An example is something like

```auto
spec:
  containers:
  - name: worker
     image: registry.replicated.com/myapp/worker:1.0.1
  imagePullSecrets:
  - name: replicatedregistrykey

```

---

<div class="post-metadata">

**Author:** ![kaismacc](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaismacc](https://community.replicated.com/u/kaismacc)\
**Post date:** [July 19, 2018, 5:48pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/7 "2018-07-19T17:48:14Z")

</div>

I still cannot get it to work. I try to provide more context:

My external repository is set up as `docker` with `index.docker.io` as endpoint.

After previous help I have changed the replicated section to include:

```auto
images:
- name: smaccio/my-image
  source: docker
  tag: 0.5.0

```

I also made sure to reference the endpoint and secret in the pod section:

```auto
    spec:
      containers:
      - name: my-image
        image: "index.docker.io/smaccio/my-image:0.5.0"
      imagePullSecrets:
        - name: replicatedregistrykey

```

When updating the release, I can see the dasbhoard download the images, but the pods will stay in the state `ImagePullBackOff`. When I look at the `journalctl --unit docker`, I get something similar like this:

```auto
"Handler for GET /v1.24/images/index.docker.io/smaccio/my-image:0.5.0/json returned error: No such image: index.docker.io/smaccio/my-image:0.5.0"

```

Any more ideas?

---

<div class="post-metadata">

**Author:** ![dmitriy](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dmitriy/32/16_2.png) [@dmitriy](https://community.replicated.com/u/dmitriy)\
**Post date:** [July 19, 2018, 6:45pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/8 "2018-07-19T18:45:20Z")

</div>

Can you try removing `index.docker.io` from your spec?

---

<div class="post-metadata">

**Author:** ![kaismacc](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaismacc](https://community.replicated.com/u/kaismacc)\
**Post date:** [July 20, 2018, 12:52pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/9 "2018-07-20T12:52:21Z")

</div>

Nope. Also doesn’t work. Same error. Here is what I found out after doing a `sudo docker images`:

The images are downloaded but they have a strange and non-unique prefix, in the pattern of:

```auto
registry.replicated.com/PRODUCTNAME/xxxxxx.smaccio-my-image
10.32.0.11:9874/smaccio-my-image

```

The first type of prefix is non unique and If I replace that in my manifest.yaml it actually works after doing a manual `kubectl apply -f`

---

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [July 20, 2018, 4:30pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/10 "2018-07-20T16:30:19Z")

</div>

Its a bit of an implementation detail, but in order to deliver your proxied private images, Replicated will rewrite

```auto
"index.docker.io/smaccio/my-image:0.5.0"

```

to

```auto
registry.replicated.com/..../TOKEN.smaccio-my-image:0.5.0

```

you found in your deployments and other workloads. It will also be re-tagged to Replicated’s on-prem registry.

It seems like for some reason replicated is not re-writing the images section in your deployment. You should be able to use the `index.docker.io/smaccio/my-image:0.5.0` without needing to write the [registry.replicated.com](http://registry.replicated.com) version yourself.

---

<div class="post-metadata">

**Author:** ![AJ-Jester](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/aj-jester/32/94_2.png) [@AJ-Jester](https://community.replicated.com/u/AJ-Jester)\
**Post date:** [October 11, 2019, 4:41pm UTC](https://community.replicated.com/t/private-dockerhub-registry-failed-to-pull-image/191/12 "2019-10-11T16:41:45Z")

</div>

TIL another reason this could fail is if the `apiVersion` for `Deployment` is not `apps/v1`. Without going too deep into the implementations details, Replicated only rewrites images to the local registry if `apps/v1` is used.

In the example below when I used `apps/v1beta2` it did not rewrite the image but after I used `apps/v1` it rewrote the image fine.

Does not work

```auto
---
# kind: scheduler-kubernetes
apiVersion: apps/v1beta2
kind: Deployment

```

Works

```auto
---
# kind: scheduler-kubernetes
apiVersion: apps/v1
kind: Deployment

```
