Why do I get "Error response from daemon: denied" when trying to pull an image from ghcr.io

Viewed 284

I have two repositories. A and B.

Inside A, I have a docker image. Let's say it's name is ghcr.io/org/a

Inside B, I have an action that wants to use this package. Both repos are private.

Here's my action code:

    - name: Log in to GitHub Container Repository
    run: |
      echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u ${{ github.actor }} --password-stdin
    - name: Pull the image
    run: |
      docker pull ghcr.io/org/a:latest    

As you can see first I log into ghcr.io and I get the Login succeeded message. Then I want to pull the image from my other repo.

But I get this error:

Error response from daemon: denied

However, when I login into ghcr.io from my own machine, I have access to both repositories and I can pull any image from any private repository of mine.

Why GitHub Action from B can not pull image from A in spite of being logged in?

2 Answers

Did you give repo B explicit access to the package?

https://github.com/orgs/<ORG_NAME>/packages/container/<PACKAGE_NAME>/settings

I encountered this same problem, but the following worked for me:

First, as @SalTorre suggests, I needed to give org/b explicit access to the package via the interface at

https://github.com/orgs/org/packages/container/a/settings

Next, in the image repository (org/a in your case), I needed to specifically grant permission to each user (or a set of teams containing said users) who need to initiate the workflow(s) in GHA that use the image. This is because authentication uses the credentials of ${{ github.actor }}, which is the specific GitHub Actions user who initiated the workflow.

The URL for doing this is here:

https://github.com/org/a/settings/access

With these two permissions set, my workflows were able to use my custom-built containers.

Related