# Using Private Registries

**URL:** <https://community.replicated.com/t/using-private-registries/453>\
**Category:** Packaging an application\
**Created:** [September 23, 2020, 4:47pm UTC](https://community.replicated.com/t/using-private-registries/453 "2020-09-23T16:47:43Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fernando\_Cremer](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/fernando_cremer/32/436_2.png) [@Fernando\_Cremer](https://community.replicated.com/u/Fernando_Cremer)\
**Post date:** [September 23, 2020, 4:47pm UTC](https://community.replicated.com/t/using-private-registries/453/1 "2020-09-23T16:47:43Z")

</div>

## Using Private Registries With Replicated

As covered in the [documentation](https://kots.io/vendor/packaging/private-images/), Replicated supports private images by configuring a connection to the private registry where they reside.

### General Steps

To configure the connection, go to **Images** and click on **Add External Registry** :

 ![priv-reg-config](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/d7294353e21a99f2345ba48de9fe33dfa94746f9.jpg)

Generally speaking, the endpoint will be the same endpoint you would use to run `docker login`.  
When connecting to a private registry, the syntax to login is:

```shell

$ docker login ADDRESS:PORT

```

And to pull any images, the syntax is:

```shell

$ docker pull [OPTIONS] ADDRESS:PORT[/PATH]/IMAGE_NAME[:TAG]

```

So for example, to login to some private registry I would run something like:

```shell

$ docker login registry.example.com:5000

```

And to pull an image from this registry I would run something like:

```shell

$ docker pull registry.example.com:5000/projects/app-image

```

So in the example above, the endpoint would be `registry.example.com:5000`.

The values for the `username` and `password` fields will depend on the registry.

Below are instructions for some of the most common registries but for those that are not listed, a good rule of thumb is to provide the same values when running `docker login`.

Once Replicated and the Private Registry have been linked, you may need to update any defintion files to now pull images from this registry.

#### Amazon Elastic Container Registry (ECR)

To connect the Replicated Vendor Portal with Amazon ECR, you will need the following:

**Endpoint:** \<aws\_account\_id\>.dkr.ecr..amazonaws.com

**Username:** AWS Access Key ID

**Password:** AWS Secret Key

The `AWS Access Key ID` and `AWS Secret Key` must be from a user with enough permissions to pull the nescessary images.  
If having permissions to pull images from all repositories is OK, then using the Amazon-provided [AmazonEC2ContainerRegistryReadOnly](https://docs.aws.amazon.com/AmazonECR/latest/userguide/ecr_managed_policies.html#AmazonEC2ContainerRegistryReadOnly) policy will suffice.

 ![priv-reg-aws-role](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/76e8415dfb02235f31aef5fba8d32824b31a292b.jpg)

If you’d like to further limit the scope of which images the user is able to pull, please review [this article](http://community.replicated.com/t/what-are-the-minimal-aws-iam-permissions-needed-to-proxy-images-from-elastic-container-registry-ecr/267).

#### Google Container Registry (GCR)

To connect the Replicated Vendor Portal with GCR, you will need the following:

**Endpoint:** [gcr.io/](http://gcr.io/)\<gcp\_project\_id\>

**Username:** `_json_file`

**Password:** `<contents of JSON key file>`

The JSON key file must be from a Service Account that has the [Storage Object Viewer](https://cloud.google.com/storage/docs/access-control/iam-roles) role:

 ![priv-reg-gcp-role](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/92f0f22286375bdc37677377d3fb83e81a6a043d.jpg)

To create the JSON key file, open the user record and select **ADD KEY** as shown below:

 ![priv-reg-gcp-role](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/92f0f22286375bdc37677377d3fb83e81a6a043d.jpg)

Copy the entire contents of the file and paste them into the **Password** field. Set the **Username** field to `_json_file`.

#### Other Registries

For registries not listed here, please refer to the General Steps section.
