# How to use a container registry with Quake AI

Source: https://docs.quake.ai/docs/kubernetes/how-to/use-container-registry
Markdown: https://docs.quake.ai/docs/kubernetes/how-to/use-container-registry.md

---

# How to use a container registry with Quake AI

Pull private container images into Quake AI workloads from a third-party registry. Quake AI does not run a managed container registry. Push images to GitHub Container Registry (GHCR), GitLab Container Registry, Docker Hub, Quay, or a self-hosted registry on a Quake AI instance.



Plan where images live before you deploy. Kubernetes clusters need `imagePullSecrets` for private repositories. VMs need `docker login` (or Podman equivalent) before `docker pull`.



## Pick a registry

| Registry | Best for | Note |
|---|---|---|
| [GHCR](https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry) | GitHub-hosted repos | Free private images at modest scale |
| [GitLab Container Registry](https://docs.gitlab.com/ee/user/packages/container_registry/) | GitLab CI pipelines | Integrated with GitLab deploy tokens |
| [Docker Hub](https://docs.docker.com/docker-hub/) | Public images and quick tests | Anonymous pulls are rate-limited |
| Self-hosted Harbor on a VM | Teams that need on-project storage | You operate patching and storage |

## Push an image from your workstation

```bash
echo "$REGISTRY_TOKEN" | docker login ghcr.io -u USERNAME --password-stdin
docker build -t ghcr.io/USERNAME/myapp:1.0.0 .
docker push ghcr.io/USERNAME/myapp:1.0.0
```

On a Quake AI [instance](/docs/compute/how-to/create-instance), run the same `docker login` and `docker pull` commands after you install Docker ([Docker Compose deploy](/docs/compute/how-to/deploy-docker-compose) covers install patterns).

## Pull into Kubernetes

Create a pull secret in the target namespace:

```bash
kubectl create secret docker-registry regcred \
  --docker-server=ghcr.io \
  --docker-username=USERNAME \
  --docker-password="$REGISTRY_TOKEN" \
  --docker-email=admin@example.com \
  -n my-namespace
```

Reference it on the Pod spec:

```yaml
spec:
  imagePullSecrets:
    - name: regcred
  containers:
    - name: myapp
      image: ghcr.io/USERNAME/myapp:1.0.0
```

For CI deploys, see [Deploy to a Quake AI Kubernetes cluster from CI](/docs/kubernetes/how-to/deploy-from-ci).

## See also

- [How to deploy a Helm chart on Magnum](/docs/kubernetes/how-to/deploy-helm-chart)
- [How to deploy a Docker Compose application on a VM](/docs/compute/how-to/deploy-docker-compose)
- [How to deploy to a Quake AI Kubernetes cluster from CI](/docs/kubernetes/how-to/deploy-from-ci)
