Authenticating Kubernetes with GitHub Container Registry (ghcr.io)

GitHub Container Registry (ghcr.io) allows developers and organizations to store and distribute private container images.
To pull private container images from ghcr.io into a Kubernetes cluster, you must create a kubernetes.io/dockerconfigjson Secret and reference it in your Pod's imagePullSecrets.
Step 1. Generate a GitHub Personal Access Token (PAT)
- In GitHub, navigate to Settings → Developer Settings → Personal Access Tokens (Classic).
- Generate a token with the
read:packagesscope. - Save the token securely.
Step 2. Create the docker-registry Secret in Kubernetes
Create the secret directly via kubectl without manual base64 conversions:
kubectl create secret docker-registry ghcr-secret \
--docker-server=ghcr.io \
--docker-username=<YOUR_GITHUB_USERNAME> \
--docker-password=<YOUR_GITHUB_PAT> \
--docker-email=<YOUR_EMAIL> \
--namespace=default
Step 3. Reference imagePullSecrets in Your Deployment
deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: demo-app
namespace: default
spec:
replicas: 2
selector:
matchLabels:
app: demo-app
template:
metadata:
labels:
app: demo-app
spec:
imagePullSecrets:
- name: ghcr-secret
containers:
- name: web
image: ghcr.io/vettom/echoserver:2.5
ports:
- containerPort: 8080