Providing Credentials for a Private Upstream Registry ​
Create a Kubernetes Secret and reference it in a RegistryCacheConfig resource to enable Registry Cache to authenticate against a private upstream registry.
Context ​
If the upstream registry requires authentication, create a Kubernetes Secret in the same namespace as the RegistryCacheConfig resource and reference it in the spec.secretReferenceName field. The Secret must be immutable and of type generic.
Procedure ​
Set environment variables with the upstream registry credentials.
bashexport USERNAME=<your username> export PASSWORD=<your password>Create the
testnamespace if it doesn't exist.bashkubectl create namespace testTo create the credential Secret, use the procedure that matches your registry type.
For registries other than Google Artifact Registry, create an immutable Secret named
rc-secretin thetestnamespace. The credential Secret must exist in the cluster before applying theRegistryCacheConfigresource.bashkubectl create -f - <<EOF apiVersion: v1 kind: Secret metadata: name: rc-secret namespace: test type: Opaque immutable: true data: username: $(echo -n $USERNAME | base64 | tr -d '\n') password: $(echo -n $PASSWORD | base64 | tr -d '\n') EOFFor Google Artifact Registry, the username is
_json_keyand the password is the service account key in JSON format.Base64-encode the service account key:
bashexport PASSWORD=$(echo -nE $SERVICE_ACCOUNT_KEY_JSON | base64 | tr -d '\n')Create an immutable Secret with the encoded key as the password.
bashkubectl create -f - <<EOF apiVersion: v1 kind: Secret metadata: name: rc-secret namespace: test type: Opaque immutable: true data: username: $(echo -n "_json_key" | base64 | tr -d '\n') password: $PASSWORD EOF
Apply the Registry Cache configuration referencing the created Secret.
bashkubectl create -f - <<EOF apiVersion: core.kyma-project.io/v1beta1 kind: RegistryCacheConfig metadata: name: config2 namespace: test spec: upstream: <protected registry URL> secretReferenceName: rc-secret volume: size: 100Gi EOF
Note: ​
When using a private registry, store the same credentials in the following Kubernetes Secrets:
- The Secret referenced in spec.secretReferenceName, which Registry Cache uses to authenticate against the upstream registry when pulling images to cache.
- An
imagePullSecreton each workload, which containerd uses to authenticate directly against the upstream registry as a fallback when Registry Cache is unavailable.Do not remove the
imagePullSecretfrom your workloads when configuring credentials for Registry Cache. If the cache is unavailable, containerd falls back to the upstream registry and requires the credentials directly.