如何在本地部署的Kubernetes集群中访问GCR私有镜像仓库?
Hey there, let's figure out how to get your local Kubernetes cluster pulling images from your private GCR repo without installing gcloud-sdk on every node. The solution relies on Kubernetes' native image pull secrets—here's a step-by-step breakdown that works perfectly for this scenario:
First, you’ll need a service account with permission to pull images from your private GCR repository. If you don’t already have one:
- Head to the GCP Console and create a new service account in your project.
- Assign it the
Storage Object Viewerrole (GCR stores images in Google Cloud Storage buckets under the hood, so this role lets the account read those objects).
Next, on a machine that does have gcloud installed (your local dev machine is ideal), run this command to download the JSON key file for the service account:
gcloud iam service-accounts keys create gcr-key.json --iam-account=your-service-account@your-project-id.iam.gserviceaccount.com
Replace your-service-account and your-project-id with your actual service account name and GCP project ID.
Now we’ll convert that JSON key into a Kubernetes secret that the cluster can use to authenticate with GCR. From your local machine (where you have kubectl configured to access your cluster), run:
kubectl create secret docker-registry gcr-secret \ --docker-server=gcr.io \ --docker-username=_json_key \ --docker-password="$(cat gcr-key.json)" \ --docker-email=any-email@example.com
A quick note here: The --docker-username must be _json_key (this is a special value GCR expects for JSON key authentication), and the email can be any valid address—it’s not actually used for the auth process.
You have two straightforward options to ensure your pods use this secret when pulling images:
Option 1: Attach the Secret to the Default Service Account
If you want all pods in a namespace to automatically use this secret (no need to edit every deployment), patch the default service account in that namespace:
kubectl patch serviceaccount default -p '{"imagePullSecrets": [{"name": "gcr-secret"}]}'
Any pod that uses the default service account (which is all pods unless you specify a different one) will now use the secret to authenticate with GCR.
Option 2: Specify the Secret in Individual Pod/Deployment YAML
For specific workloads, add the imagePullSecrets field directly to your pod or deployment manifest:
apiVersion: apps/v1 kind: Deployment metadata: name: my-private-app spec: replicas: 1 selector: matchLabels: app: my-private-app template: metadata: labels: app: my-private-app spec: containers: - name: app-container image: gcr.io/your-project-id/your-private-image:latest imagePullSecrets: - name: gcr-secret
Just replace the image path with your actual private GCR image reference.
- If you get permission denied errors, double-check that your service account has the
Storage Object Viewerrole assigned correctly in the GCP Console. - Remember that secrets are namespace-specific—if you use multiple namespaces, you’ll need to create the secret in each one, or use a tool like
kubectl cpto copy it across namespaces. - No gcloud-sdk is needed on cluster nodes because the authentication is handled entirely via the Kubernetes secret, which is mounted into the pod’s runtime environment when pulling images.
内容的提问来源于stack exchange,提问作者Sachin Arote

