Skip to content

Authenticating Kubernetes with GitHub Container Registry (ghcr.io)

GHCR logo

GitHub Container Registry (ghcr.io) allows developers and organizations to store and distribute private container images.

To pull private container images from ghcr.io into a Kubernetes cluster, you must create a kubernetes.io/dockerconfigjson Secret and reference it in your Pod's imagePullSecrets.


Step 1. Generate a GitHub Personal Access Token (PAT)

  1. In GitHub, navigate to Settings → Developer Settings → Personal Access Tokens (Classic).
  2. Generate a token with the read:packages scope.
  3. Save the token securely.

Step 2. Create the docker-registry Secret in Kubernetes

Create the secret directly via kubectl without manual base64 conversions:

kubectl create secret docker-registry ghcr-secret \
  --docker-server=ghcr.io \
  --docker-username=<YOUR_GITHUB_USERNAME> \
  --docker-password=<YOUR_GITHUB_PAT> \
  --docker-email=<YOUR_EMAIL> \
  --namespace=default

Step 3. Reference imagePullSecrets in Your Deployment

deployment.yaml

apiVersion: apps/v1
kind: Deployment
metadata:
  name: demo-app
  namespace: default
spec:
  replicas: 2
  selector:
    matchLabels:
      app: demo-app
  template:
    metadata:
      labels:
        app: demo-app
    spec:
      imagePullSecrets:
        - name: ghcr-secret
      containers:
        - name: web
          image: ghcr.io/vettom/echoserver:2.5
          ports:
            - containerPort: 8080

kubectl apply -f deployment.yaml
kubectl get pods -l app=demo-app