# Docker login Forbidden

**URL:** <https://forum.gitea.com/t/docker-login-forbidden/6697>\
**Category:** General\
**Created:** [February 10, 2023, 4:46pm UTC](https://forum.gitea.com/t/docker-login-forbidden/6697 "2023-02-10T16:46:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![miberecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/miberecz/32/3440_2.png) [@miberecz](https://forum.gitea.com/u/miberecz)\
**Post date:** [February 10, 2023, 4:46pm UTC](https://forum.gitea.com/t/docker-login-forbidden/6697/1 "2023-02-10T16:46:01Z")

</div>

I’m trying to use the container registry feature of Gitea(1.18.0), but somehow I cannot authenticate on the server.  
Server is running in a docker container.

```auto
[root@server app]# docker login X.26.9.3:3000
Username: myuser
Password:
Error response from daemon: Get "https://X.26.9.3:3000/v2/": Forbidden

```

If I try to push and image, I get similar error:

```auto
[root@server app]# docker image push X.26.9.3:3000/myuser/haproxy/customimage:latest
The push refers to repository [X.26.9.3:3000/myuser/haproxy/customimage]
Get "https://X.26.9.3:3000/v2/": Forbidden

```

What am I doing wrong here?  
In the logs, I do not see any mention of failed authentication.

---

<div class="post-metadata">

**Author:** ![miberecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/miberecz/32/3440_2.png) [@miberecz](https://forum.gitea.com/u/miberecz)\
**Post date:** [February 13, 2023, 2:06pm UTC](https://forum.gitea.com/t/docker-login-forbidden/6697/2 "2023-02-13T14:06:48Z")

</div>

Eventually I figured:  
Since this is an air-gaped system, I had to add a proxy configuration to my docker service like this:

[root@server~]# cat /etc/systemd/system/docker.service.d/http-proxy.conf  
[Service]  
Environment=“HTTP\_PROXY=X.26.9.5:3128”  
Environment=“HTTPS\_PROXY=X.26.9.5:3128”  
Environment=“NO\_PROXY=localhost,127.0.0.1/8,X.26.9.3”

turns out, I had to exclude my local Gitea address from this so Docker could reach it within my network.  
so just had to add one more entry in the NO\_PROXY section.
