Pull an Image From a Private Registry
Pull environment images from a private registry by passing an imagePullSecret to fission environment create with –imagepullsecret.
With 1.7.0+, you can specify which credential kubelet uses to pull images from a private registry.
First, follow the kubernetes guide to create the secret.
The secret must be created in the namespace where the function pods run. By default this is the namespace where your Fission resources live (for example,default); confirm withkubectl get pods -l environmentName=<env>to see where the pods are scheduled.
Then, specify the secret when creating the environment.
For example, this creates a nodejs environment using secret docker-secret as credential.
$ fission environment create --name nodejs --image ghcr.io/fission/node-env \
--imagepullsecret "docker-secret"
You should see imagePullSecrets in the environment deployment, like the following.
$ kubectl -n fission-function get deploy -l environmentName=nodejs -o yaml
apiVersion: v1
items:
- apiVersion: extensions/v1beta1
kind: Deployment
metadata:
name: poolmgr-nodejs-default-217063
namespace: fission-function
...
spec:
...
template:
...
spec:
...
imagePullSecrets:
- name: docker-secret
Fission won’t check that the secret exists, nor verify that the setting works.
Check the pod status yourself to ensure everything works as expected.