# Authenticated Local Container Registry Support in ECK

**URL:** <https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [July 10, 2020, 2:51pm UTC](https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717 "2020-07-10T14:51:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SeanPlacchetti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanplacchetti/32/51652_2.png) [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Post date:** [July 10, 2020, 2:51pm UTC](https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717/1 "2020-07-10T14:51:25Z")

</div>

Our elastic deployment will eventually be on air-gapped networks without internet access where the container registries have authentication. I see we can set the registry by CLI when we deploy the operator, but authentication seems to still happen on the PodTemplate level. Are there plans to raise this to the CLI? Or is it set up this way on purpose?

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [July 14, 2020, 11:30am UTC](https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717/2 "2020-07-14T11:30:46Z")

</div>

We currently do not have any concrete plans to change the current behaviour. The [official k8s docs](https://kubernetes.io/docs/concepts/containers/images/#using-a-private-registry) list a few alternatives to specifying `imagePullSecrets` on every Pod like authenticating the k8s nodes against the Docker registry. Or you could allow unauthenticated access to the registry only from within the k8s cluster. I wonder if one of them would be an option for you?

---

<div class="post-metadata">

**Author:** ![SeanPlacchetti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanplacchetti/32/51652_2.png) [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Post date:** [July 14, 2020, 12:54pm UTC](https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717/3 "2020-07-14T12:54:11Z")

</div>

@pebrc we can check those out, thanks for the heads up on the operator plans, we didn't want to kludge around only to have y'all implement that functionality. Thanks again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:05am UTC](https://discuss.elastic.co/t/authenticated-local-container-registry-support-in-eck/240717/4 "2022-11-04T08:05:51Z")

</div>


