# Creating docker-registry secret using a YAML file

**URL:** <https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042>\
**Category:** General Discussions\
**Tags:** development\
**Created:** [July 4, 2019, 2:35pm UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042 "2019-07-04T14:35:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bgarcial](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/bgarcial/32/2438_2.png) [@bgarcial](https://discuss.kubernetes.io/u/bgarcial)\
**Post date:** [July 4, 2019, 2:35pm UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/1 "2019-07-04T14:35:55Z")

</div>

Hi Kubernauts

How can I create a docker-registry secret using a yaml file?

I’ve already created from CLI using `kubectl` of this way:

```auto
kubectl create secret docker-registry regcred --docker-server=my-container-registry-url --docker-username=my-username --docker-password=my-password --docker-email=my-email 

```

But my idea is create it from a `YAML` file, because I want to automate this secret creation process from Helm as a pre-install process.  
So that I am trying to create it of this way from this file …

```auto
apiVersion: v1
kind: Secret
metadata:
  annotations:
    "helm.sh/hook": pre-install
    "helm.sh/hook-delete-policy": "before-hook-creation"
  name: regcred
type: kubernetes.io/dockercfg
data:
  dockerRegistry: my-container-registry-url
  dockerId: my-username
  dockerPassword: my-password

```

But I have the following output:

```auto
2019-07-04T14:23:42.1614520Z ##[error]Error: Secret "regcred" is invalid: data[.dockercfg]: Required value

```

How can I create it, I mean what `type` attribute should I include instead of `type: kubernetes.io/dockercfg` ?

---

<div class="post-metadata">

**Author:** ![rata](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/rata/32/18244_2.png) [@rata](https://discuss.kubernetes.io/u/rata)\
**Post date:** [July 4, 2019, 4:39pm UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/2 "2019-07-04T16:39:09Z")

</div>

I honestly don’t remember.

But, I think you can you create it from the command line, as you shown, and then do kubectl get secret to see them and then kubectl get secret -o yaml to show the yaml you can use to create it 🙂

---

<div class="post-metadata">

**Author:** ![macintoshprime](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/macintoshprime/32/7121_2.png) [@macintoshprime](https://discuss.kubernetes.io/u/macintoshprime)\
**Post date:** [July 4, 2019, 4:41pm UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/3 "2019-07-04T16:41:47Z")

</div>

You’ll have to generate a docker `config.json` behind the scenes I think. There are some docs that show the secret format [here](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/). Once you have the `config.json` you encode that and put that into the secret.

```auto
apiVersion: v1
kind: Secret
metadata:
  name: myregistrykey
  namespace: awesomeapps
data:
  .dockerconfigjson: UmVhbGx5IHJlYWxseSByZWVlZWVlZWVlZWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGx5eXl5eXl5eXl5eXl5eXl5eXl5eSBsbGxsbGxsbGxsbGxsbG9vb29vb29vb29vb29vb29vb29vb29vb29vb25ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubmdnZ2dnZ2dnZ2dnZ2dnZ2dnZ2cgYXV0aCBrZXlzCg==
type: kubernetes.io/dockerconfigjson

```

---

<div class="post-metadata">

**Author:** ![Olivier\_Refalo](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/olivier_refalo/32/5010_2.png) [@Olivier\_Refalo](https://discuss.kubernetes.io/u/Olivier_Refalo)\
**Post date:** [April 26, 2020, 9:29am UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/4 "2020-04-26T09:29:43Z")

</div>

It’s all detailed here. [https://blog.cloudhelix.io/using-a-private-docker-registry-with-kubernetes-f8d5f6b8f646](https://blog.cloudhelix.io/using-a-private-docker-registry-with-kubernetes-f8d5f6b8f646)

---

<div class="post-metadata">

**Author:** ![ebaum](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/ebaum/32/5808_2.png) [@ebaum](https://discuss.kubernetes.io/u/ebaum)\
**Post date:** [September 2, 2020, 11:11pm UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/5 "2020-09-02T23:11:42Z")

</div>

Hi, but it’s possible enable an insecure registry and pull image? I have a docker-registry in my private network, i made the certificate with openssl, but when i try to create a pod gave me the error x509?  
Any sugestions?

---

<div class="post-metadata">

**Author:** ![Pratima](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@Pratima](https://discuss.kubernetes.io/u/Pratima)\
**Post date:** [December 4, 2023, 11:19am UTC](https://discuss.kubernetes.io/t/creating-docker-registry-secret-using-a-yaml-file/7042/6 "2023-12-04T11:19:28Z")

</div>

Hi ,  
You can try this command to get yaml file (file-name.yaml)

kubectl create secret docker-registry regcred --docker-server=my-container-registry-url --docker-username=my-username --docker-password=my-password --docker-email=my-email -o yaml --dry-run=client \> file-name.yaml
