How to pull a docker image from Jfrog Artifactory using K8S

Viewed 99

I have a local repository in Jfrog artifactory on EC2. when I try pulling the image using only docker everything goes well, but when I try to pull it using K8S deployment.yaml I get ImagePullBackOff and this is the logs when running the describe on pods. Any Ideas on what might be the problem? Thanks.

Events:
Type     Reason     Age                     From               Message
----     ------     ----                    ----               -------
Normal   Scheduled  8m50s                   default-scheduler  Successfully  assigned default/weatherapp-dep-6f79c6c774-kln95 to ip-172-31-23-92
Normal   Pulling    7m27s (x4 over 8m49s)   kubelet            Pulling image "54.235.13.197:80/moodyslocaldockerhub/weatherappjdka:v1.49"
Warning  Failed     7m27s (x4 over 8m49s)   kubelet            Failed to pull image "54.235.13.197:80/moodyslocaldockerhub/weatherappjdka:v1.49": rpc error: code = Unknown desc = failed to pull and unpack image "54.235.13.197:80/moodyslocaldockerhub/weatherappjdka:v1.49": failed to resolve reference "54.235.13.197:80/moodyslocaldockerhub/weatherappjdka:v1.49": failed to do request: Head https://54.235.13.197:80/v2/moodyslocaldockerhub/weatherappjdka/manifests/v1.49: remote error: tls: alert(112)
Warning  Failed     7m27s (x4 over 8m49s)   kubelet            Error: ErrImagePull
Warning  Failed     7m1s (x6 over 8m48s)    kubelet            Error: ImagePullBackOff
Normal   BackOff    3m44s (x20 over 8m48s)  kubelet            Back-off pulling image "54.235.13.197:80/moodyslocaldockerhub/weatherappjdka:v1.49"
1 Answers

You need to provide the imagePullSecret or a service account with the credentials to the repository.


the manifest looks like this

apiVersion: v1
kind: Secret
metadata:
  name: myregistrykey
  namespace: awesomeapps
data:
  .dockerconfigjson: <base64_of_credentials>
type: kubernetes.io/dockerconfigjson

or alternatively generate it with this command

kubectl create secret docker-registry regcred --docker-server=<your-registry-server> --docker-username=<your-name> --docker-password=<your-pword> --docker-email=<your-email>


Then you mount the secret

apiVersion: v1
kind: Pod
metadata:
  name: private-reg
spec:
  containers:
  - name: private-reg-container
    image: <your-private-image>
  imagePullSecrets:
  - name: regcred
Related