# Using Third Party Registries

**URL:** <https://community.replicated.com/t/using-third-party-registries/45>\
**Category:** Packaging an application\
**Created:** [March 6, 2018, 7:38pm UTC](https://community.replicated.com/t/using-third-party-registries/45 "2018-03-06T19:38:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![marc](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/marc/32/7_2.png) [@marc](https://community.replicated.com/u/marc)\
**Post date:** [March 6, 2018, 7:38pm UTC](https://community.replicated.com/t/using-third-party-registries/45/1 "2018-03-06T19:38:52Z")

</div>

Replicated can integrate with your third party private registry (ie Docker Trusted Registry, [Quay.io](http://Quay.io), ECR, GCR etc). To connect to these external registries you’ll need to connect your vendor account to these accounts on the [app images page](https://vendor.replicated.com/images).

You’ll need to provide us with a reference name, endpoint, username, password and email address (we recommend creating a specific account for Replicated with read-only access to use).

Your credentials will never be shared or used by the customer to pull your images, instead your images will be proxied by us for each installation.

#### KOTS

For delivering private images with KOTS please see the [kots.io/vendor](http://kots.io/vendor) documentation for [using private images with KOTS](https://kots.io/vendor/packaging/private-images/).

#### Native Scheduler

To access these images in your YAML you’ll need to use the reference name as the source & then the image name will need to provide the image name location, along with the version tag.

```yaml
components:
- name: App
  containers:
  - source: mythirdpartyprivateregistry
    image_name: namespace/imagename
    version: 2.0.0

```

#### Swarm and Kubernetes

Swarm and Kubernetes require additional information

```yaml
images:
- source: mythirdpartyprivateregistry
  name: namespace/imagename
  tag: 2.0.0

```

```yaml
---
# kind: scheduler-swarm
version: '3.3'

services:
  my_service:
    image: quay.io/namespace/imagename:2.0.0

```

#### Ship

For delivering images in ship, see [Ship a Private Image](https://help.replicated.com/guides/kubernetes-with-ship/private-image/) in the [Getting Started with Ship](https://help.replicated.com/guides/kubernetes-with-ship/) guide.

---

<div class="post-metadata">

**Author:** ![Mac](https://avatars.discourse-cdn.com/v4/letter/m/cc9497/32.png) [@Mac](https://community.replicated.com/u/Mac)\
**Post date:** [May 4, 2018, 11:10am UTC](https://community.replicated.com/t/using-third-party-registries/45/2 "2018-05-04T11:10:56Z")

</div>

> [@marc](#):
>
> mythirdpartyprivateregistry

From the above, it was clear that the alias defined in the field “Name (Ref)” under Application → Settings needed to be put into the release yaml under ‘components.containers.source’, but it wasn’t clear to me that ‘services.blah.image’ needed to be `quay.io/mycompany/blah:v1` (if I’m using [quay.io](http://quay.io)) and not `mythirdpartyprivateregistry/mycompany/blah:v1`

---

<div class="post-metadata">

**Author:** ![laverya](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/laverya/32/263_2.png) [@laverya](https://community.replicated.com/u/laverya)\
**Post date:** [March 11, 2019, 8:46pm UTC](https://community.replicated.com/t/using-third-party-registries/45/4 "2019-03-11T20:46:45Z")

</div>

To clarify the setup of ECR, since what needs to be provided for each field can be a little unclear:

1. You choose the name
2. The endpoint is of the form `<account id>.dkr.ecr.<region>.amazonaws.com`
3. The username is the AWS access key ID
4. The password is the AWS access token  
And the email does not matter.

 ![image](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/12c346dcf3bd0013d769c4a4e21daeb61f2b8dd1.png)
