You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在本地部署的Kubernetes集群中访问GCR私有镜像仓库?

Hey there, let's figure out how to get your local Kubernetes cluster pulling images from your private GCR repo without installing gcloud-sdk on every node. The solution relies on Kubernetes' native image pull secrets—here's a step-by-step breakdown that works perfectly for this scenario:

Step 1: Generate a GCP Service Account Key

First, you’ll need a service account with permission to pull images from your private GCR repository. If you don’t already have one:

  1. Head to the GCP Console and create a new service account in your project.
  2. Assign it the Storage Object Viewer role (GCR stores images in Google Cloud Storage buckets under the hood, so this role lets the account read those objects).

Next, on a machine that does have gcloud installed (your local dev machine is ideal), run this command to download the JSON key file for the service account:

gcloud iam service-accounts keys create gcr-key.json --iam-account=your-service-account@your-project-id.iam.gserviceaccount.com

Replace your-service-account and your-project-id with your actual service account name and GCP project ID.

Step 2: Create a Kubernetes Image Pull Secret

Now we’ll convert that JSON key into a Kubernetes secret that the cluster can use to authenticate with GCR. From your local machine (where you have kubectl configured to access your cluster), run:

kubectl create secret docker-registry gcr-secret \
  --docker-server=gcr.io \
  --docker-username=_json_key \
  --docker-password="$(cat gcr-key.json)" \
  --docker-email=any-email@example.com

A quick note here: The --docker-username must be _json_key (this is a special value GCR expects for JSON key authentication), and the email can be any valid address—it’s not actually used for the auth process.

Step 3: Make Your Pods Use the Secret

You have two straightforward options to ensure your pods use this secret when pulling images:

Option 1: Attach the Secret to the Default Service Account

If you want all pods in a namespace to automatically use this secret (no need to edit every deployment), patch the default service account in that namespace:

kubectl patch serviceaccount default -p '{"imagePullSecrets": [{"name": "gcr-secret"}]}'

Any pod that uses the default service account (which is all pods unless you specify a different one) will now use the secret to authenticate with GCR.

Option 2: Specify the Secret in Individual Pod/Deployment YAML

For specific workloads, add the imagePullSecrets field directly to your pod or deployment manifest:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-private-app
spec:
  replicas: 1
  selector:
    matchLabels:
      app: my-private-app
  template:
    metadata:
      labels:
        app: my-private-app
    spec:
      containers:
      - name: app-container
        image: gcr.io/your-project-id/your-private-image:latest
      imagePullSecrets:
      - name: gcr-secret

Just replace the image path with your actual private GCR image reference.

Quick Troubleshooting Tips
  • If you get permission denied errors, double-check that your service account has the Storage Object Viewer role assigned correctly in the GCP Console.
  • Remember that secrets are namespace-specific—if you use multiple namespaces, you’ll need to create the secret in each one, or use a tool like kubectl cp to copy it across namespaces.
  • No gcloud-sdk is needed on cluster nodes because the authentication is handled entirely via the Kubernetes secret, which is mounted into the pod’s runtime environment when pulling images.

内容的提问来源于stack exchange,提问作者Sachin Arote

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:44:06