# Okteto not able to use private image as base

**URL:** <https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894>\
**Category:** Help\
**Created:** [July 3, 2023, 11:21am UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894 "2023-07-03T11:21:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![boedy](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/boedy/32/388_2.png) [@boedy](https://community.okteto.com/u/boedy)\
**Post date:** [July 3, 2023, 11:21am UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/1 "2023-07-03T11:21:16Z")

</div>

I can deploy the workloads just fine via `okteto build --wait`, but I get an error when I redeploy the application from within the GUI.

> #4 ERROR: pull access denied, repository does not exist or may require authorization: server message: insufficient\_scope: authorization failed

I have the correct pull secrets installed:

```yaml
apiVersion: v1
data:
  .dockerconfigjson: {"auths":{"index.docker.io":{"password":"<password>","username":"<username>"}}} <-- decoded as example
kind: Secret
metadata:
  name: image-pull-secret
  namespace: okteto
type: kubernetes.io/dockerconfigjson

```

---

<div class="post-metadata">

**Author:** ![boedy](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/boedy/32/388_2.png) [@boedy](https://community.okteto.com/u/boedy)\
**Post date:** [July 3, 2023, 4:53pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/2 "2023-07-03T16:53:44Z")

</div>

I believe @adripedriza ran into the same issue. [Unable to use base image in okteto (requires authorization) - #8 by adripedriza](https://community.okteto.com/t/unable-to-use-base-image-in-okteto-requires-authorization/584/8)

Is there a solution for this?

---

<div class="post-metadata">

**Author:** ![provecho](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/provecho/32/45_2.png) [@provecho](https://community.okteto.com/u/provecho)\
**Post date:** [July 4, 2023, 7:48am UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/3 "2023-07-04T07:48:04Z")

</div>

Hi @boedy,

You may be looking for how to configure private registries in Okteto, so take a look at `privateRegistry` configuration section ([Configuration Settings | Okteto Documentation](https://www.okteto.com/docs/self-hosted/administration/configuration/#privateregistry)).

The process of pulling images from registries in Buildkit doesn’t use Kubernetes’ `imagePullSecrets`, but rather the credentials available in configuration files like `.docker/config.json`. When the deployment request is initiated from within the cluster (e.g., through the UI), that file is generated based on the configuration in the link I provided earlier.

---

<div class="post-metadata">

**Author:** ![boedy](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/boedy/32/388_2.png) [@boedy](https://community.okteto.com/u/boedy)\
**Post date:** [February 16, 2024, 12:54pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/4 "2024-02-16T12:54:21Z")

</div>

Hi @provecho

Almost a year later I’m revisiting this topic. I’m still having issues. When I run `okteto build`, the Buildkit logs:

> #3 ERROR: pull access denied, repository does not exist or may require authorization: server message: insufficient\_scope: authorization failed

The acces token set in okteto-dockerconfig is valid and as you can see based on the Last Used, the key is being used.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/okteto/original/1X/8228508fafd08507aefa16cc2d699fdd72038d25.png)

---

<div class="post-metadata">

**Author:** ![provecho](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/provecho/32/45_2.png) [@provecho](https://community.okteto.com/u/provecho)\
**Post date:** [February 16, 2024, 1:04pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/5 "2024-02-16T13:04:50Z")

</div>

> [@boedy](#):
>
> The acces token set in okteto-dockerconfig

Hi @boedy,

I’d like to remind you that credentials saved in the Kubernetes ImagePullSecrets are not utilized within Okteto Builds. For those, you need to have credentials defined locally or utilize the feature [Private Registries](https://www.okteto.com/docs/self-hosted/manage/custom-resource-definitions/#private-registries) (renewed since 1.14).

If you’re using any of the above and still facing issues, please provide a redacted version of your Dockerfile and your Okteto manifest (`okteto.yaml`). I’m particularly interested in the `FROM` statements. Please also include complete redacted logs.

---

<div class="post-metadata">

**Author:** ![boedy](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/boedy/32/388_2.png) [@boedy](https://community.okteto.com/u/boedy)\
**Post date:** [February 16, 2024, 1:48pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/6 "2024-02-16T13:48:17Z")

</div>

@provecho We are using the privateRegistries

![image](https://us1.discourse-cdn.com/flex019/uploads/okteto/original/1X/8f82ad7d159e7b8b23bf993f7629b705d32a884e.png)

Docker-compose:

```auto
version: "3.2"
services:
  main-api:
    build:
      context: .
      dockerfile: Dockerfile
      args:
        - ENVIRONMENT=development
    command: ["serve"]
    environment:
      - DOPPLER_TOKEN=${DOPPLER_TOKEN}
    ports:
      - "8080:80"

```

Dockerfile:

```auto
FROM composer:2.1.6 as vendor

WORKDIR /tmp/

COPY composer.json composer.json
COPY composer.lock composer.lock
COPY database database
COPY tests tests

RUN composer install \
      --ignore-platform-reqs \
      --no-interaction \
      --no-plugins \
      --no-scripts \
      --prefer-dist

FROM **redacted** /example:base

WORKDIR /app
ARG ENVIRONMENT=production
COPY --from=composer /usr/bin/composer /usr/bin/composer

COPY . .

COPY docker-config/install.sh install.sh
RUN chmod u+x install.sh && ./install.sh

COPY --from=vendor /tmp/vendor vendor

```

Build logs:

```auto
Run
"Building service main-api"
1 hr ago
#1 [internal] load build definition from buildkit-498420913
#1 transferring dockerfile:
#1 transferring dockerfile: 1.38kB 1.0s done
#1 DONE 1.0s
#2 [internal] load .dockerignore
#2 transferring context: 440B 1.0s done
#2 DONE 1.0s
#3 [internal] load metadata for docker.io/ **redacted** /example:base
#3 ...
#4 [internal] load metadata for docker.io/library/composer:latest
#4 DONE 1.2s#5 [internal] load metadata for docker.io/library/composer:2.1.6
#5 DONE 1.4s#3 [internal] load metadata for docker.io/ **redacted** /example:base
#3 ERROR: pull access denied, repository does not exist or may require authorization: server message: insufficient_scope: authorization failed

```

---

<div class="post-metadata">

**Author:** ![provecho](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/provecho/32/45_2.png) [@provecho](https://community.okteto.com/u/provecho)\
**Post date:** [February 16, 2024, 6:07pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/7 "2024-02-16T18:07:35Z")

</div>

Hi @boedy,

Thank you for providing your manifests and configuration.

I’ll pose additional questions to better understand your setup:

1. Which version of Okteto Self Hosted are you running?
2. Which version of the Okteto CLI are you using?
3. Could you specify the action or command that triggers the error? I understand it occurs during the build phase, but I’m uncertain if you’re executing it from the web UI, locally with `okteto build`, or through another `okteto` command.

> [@boedy](#):
>
> We are using the privateRegistries

Regarding your mention of privateRegistries:

Since version 1.14, the notation displayed in the screenshot is no longer utilized. We have implemented a migration to ensure a smooth transition, but depending on your setup, your configuration might have been missed. The following article contains more information regarding the upgrade process and manual alternatives:

[https://www.okteto.com/docs/self-hosted/manage/upgrade/#upgrading-to-okteto-114x](https://www.okteto.com/docs/self-hosted/manage/upgrade/#upgrading-to-okteto-114x)

Lastly, if you have already reviewed the documentation provided and are executing `okteto build` or an equivalent locally, please attempt the following steps:

1. Execute `docker logout` (for the default Docker Hub registry) or `docker logout <registry>` for any other registry.
2. Retry your Okteto CLI command.

The rationale behind this suggestion is that Okteto prioritizes your local credentials over Okteto Self Hosted Private Registries when the CLI runs locally. Therefore, you may encounter the error due to outdated or expired local credentials.

I look forward to your response.

---

<div class="post-metadata">

**Author:** ![boedy](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/boedy/32/388_2.png) [@boedy](https://community.okteto.com/u/boedy)\
**Post date:** [February 19, 2024, 5:22pm UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/8 "2024-02-19T17:22:16Z")

</div>

Hey @provecho

Thanks for the follow up. We are still on version 1.8 it seems

![image](https://us1.discourse-cdn.com/flex019/uploads/okteto/original/1X/f6e90d6553e05a9c8a462090e6c71853c7f42543.png)

But I just tried you last suggestion and that worked! I apparently was not logged in, or maybe i was logged in as a different user. I’m a bit surprised that the local docker credentials override the remote ones. Is there a way to disable this?

---

<div class="post-metadata">

**Author:** ![provecho](https://sea1.discourse-cdn.com/flex019/user_avatar/community.okteto.com/provecho/32/45_2.png) [@provecho](https://community.okteto.com/u/provecho)\
**Post date:** [February 20, 2024, 10:32am UTC](https://community.okteto.com/t/okteto-not-able-to-use-private-image-as-base/894/9 "2024-02-20T10:32:20Z")

</div>

> [@boedy](#):
>
> I’m a bit surprised that the local docker credentials override the remote ones. Is there a way to disable this?

Hi @boedy,

Currently, there isn’t a way to disable the override of remote credentials by local Docker credentials. I’ll bring up your concern to the product team, and I’ll keep you informed of any developments or updates regarding this matter.
