# Air-Gap-Systems: Running with private docker registry?

**URL:** <https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [June 19, 2019, 7:10am UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392 "2019-06-19T07:10:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [June 19, 2019, 7:10am UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/1 "2019-06-19T07:10:16Z")

</div>

Hi,

can I configure ECK to use a private docker registry? Target infrastructure will be a bare-metal kubernetes cluster which is air-gap, so the elastic registry will not be available for me.

Thanks,  
Andreas

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [June 20, 2019, 2:39pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/2 "2019-06-20T14:39:32Z")

</div>

Hi Andreas,

In principle what is written in the Kubernetes documentation applies also to ECK  
[https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/).

For ECK 0.8.0 we don't support a full podTemplate yet which means you cannot unfortunately specify the necessary `imagePullSecrets`. It is fixed in the master branch and will be available in the next release.

---

<div class="post-metadata">

**Author:** ![wags007](https://avatars.discourse-cdn.com/v4/letter/w/ba8739/32.png) [@wags007](https://discuss.elastic.co/u/wags007)\
**Post date:** [February 6, 2020, 6:04pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/3 "2020-02-06T18:04:01Z")

</div>

Hello All,  
We air-gap our systems to make sure that everything is scanned for insecure images and other potential problems. If the systems are pulling from our internal repo they don't need to authenticate. It appears though that there is no way to change where the images are pulled from at a hostname level. So this means we can't use the ECK correct? Seems like an easily fixable problem. Plus you can also set the authentication at the Docker on the host/node level so that wouldn't require imagePullSecrets.

Am I correct? Is there no way to use any other Repo?  
Thanks,  
Brian

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [February 7, 2020, 9:30am UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/4 "2020-02-07T09:30:13Z")

</div>

If your internal repo does not require authentication, you can simply set the `spec.image` field to the full image name. See [https://github.com/elastic/cloud-on-k8s/issues/2129#issuecomment-555080991](https://github.com/elastic/cloud-on-k8s/issues/2129#issuecomment-555080991)

---

<div class="post-metadata">

**Author:** ![wags007](https://avatars.discourse-cdn.com/v4/letter/w/ba8739/32.png) [@wags007](https://discuss.elastic.co/u/wags007)\
**Post date:** [February 7, 2020, 12:47pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/5 "2020-02-07T12:47:35Z")

</div>

That is exactly what I would like to do. How can I do it with the ECK operator? The operator is providing no method I can see to change that. When we do the initial deploy of the CRD we can change where the operator comes from but once deployed the operator defaults back to [docker.elasti.co](http://docker.elasti.co). which our servers cannot reach to deploy all of the rest of the ELK Stack.  
Thanks,  
Brian

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [February 7, 2020, 1:20pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/6 "2020-02-07T13:20:33Z")

</div>

I am not sure I understand your question correctly. If you want to use your internal registry to deploy the operator itself, you can do so by first downloading the deployment manifest, editing the `elastic-operator` StatefulSet definition to point to the internal image and then applying that modified manifest to deploy ECK.

Once ECK is up and running, for every Elasticsearch, Kibana or APM resource you want to deploy, you have to explicitly set the `spec.image` field to the internal image URL as pointed out in my previous reply.

We have an [open issue](https://github.com/elastic/cloud-on-k8s/issues/2223) about letting users specify the default container registry as an operator flag so that they don't need to worry about setting `spec.image` every time. Unfortunately it is not yet implemented.

I hope that answers your question.

---

<div class="post-metadata">

**Author:** ![wags007](https://avatars.discourse-cdn.com/v4/letter/w/ba8739/32.png) [@wags007](https://discuss.elastic.co/u/wags007)\
**Post date:** [February 7, 2020, 1:45pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/7 "2020-02-07T13:45:48Z")

</div>

The open issue is more what I was looking for. One of the biggest benefits of ECK is that Elastic just configures all the matched and tested pieces for me. I don't have to think about it just do it.  
Thanks,  
Brian

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [February 10, 2020, 2:51pm UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/8 "2020-02-10T14:51:44Z")

</div>

A PR to support overriding the default container registry has been merged to master: [https://github.com/elastic/cloud-on-k8s/pull/2537](https://github.com/elastic/cloud-on-k8s/pull/2537).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:12am UTC](https://discuss.elastic.co/t/air-gap-systems-running-with-private-docker-registry/186392/9 "2022-11-04T07:12:54Z")

</div>


