# Error response from daemon: unauthorized: reqPackageAccess

**URL:** <https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646>\
**Category:** Gitea Usages\
**Created:** [August 18, 2025, 7:54am UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646 "2025-08-18T07:54:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeremy-bepoix](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/jeremy-bepoix/32/7059_2.png) [@jeremy-bepoix](https://forum.gitea.com/u/jeremy-bepoix)\
**Post date:** [August 18, 2025, 7:54am UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646/1 "2025-08-18T07:54:08Z")

</div>

Hello,

I have a self-hosted Gitea instance that works perfectly, and thank you for your work!  
Until now, I was only using Gitea for code repositories, a few CI/CD for sanity checks, linting, etc.  
I set up a CI/CD for OCI/Docker image builds. Package creation and pushing work fine, But when I want to use the built image in an action workflow, I get an error.

#### Action workflow error

Here is the error I get when setting up the job :

```bash
0d888c570ee0(version:v0.2.12) received task 821 of job release, be triggered by event: push
workflow prepared
evaluating expression 'success()'
expression 'success()' evaluated to 'true'
🚀 Start image=my.domain.com/repo/docker-images:ubuntu-20.04-act
  🐳 docker pull image=my.domain.com/repo/docker-images:ubuntu-20.04-act platform= username= forcePull=true
  🐳 docker pull my.domain.com/repo/docker-images:ubuntu-20.04-act
pulling image 'my.domain.com/repo/docker-images:ubuntu-20.04-act' ()
Error response from daemon: unauthorized: reqPackageAccess

```

#### Workflow

here is the action.yaml test file :

```yaml
name: release
on:
  push:
    branches:
      - main
jobs:
  release:
    runs-on: ubuntu-20.04-act
    strategy:
      matrix:
        python-version: ['3.9']
    concurrency:
      group: ${{ github.workflow }}-release-${{ github.ref_name }}
      cancel-in-progress: false

```

**Important note**

if I log in to another host and do a docker pull of the image

```bash
docker pull my.domain.com/repo/docker-images:ubuntu-20.04-act

```

He asks me for my credentials and I can pull the image.

#### Act Runner

[config.yaml](https://docs.gitea.com/usage/actions/act-runner#configuration) is well set and i can view from “Runners Management” that OCI (labels) are registred.

```yaml
labels:
    - "ubuntu-latest:docker://ghcr.io/catthehacker/ubuntu:act-latest"
    - "ubuntu-latest-slim:docker://node:20-bookworm-slim"
    - "ubuntu-20.04-act:docker://my.domain.com/repo/docker-images:ubuntu-20.04-act"

```

#### Reverse proxy

A few releases ago, I noticed an issue related to reverse proxy and the /v2 route. [I corrected it with docs](https://docs.gitea.com/administration/reverse-proxies#nginx). (_I’m putting it here just in case)_

```yaml
server {
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name gitea.*;

    include /config/nginx/ssl.conf;
    client_max_body_size 512M;

    location / {

        include /config/nginx/resolver.conf;

        set $upstream_app 172.18.37.145;
        set $upstream_port 3000;
        set $upstream_proto http;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;

        # other common HTTP headers, see the "Nginx" config section above
        proxy_set_header Connection $http_connection;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

    }

}

```

#### Credentials

On the credentials side, user can read, write package and use token on cicd.

#### Docker compose stack

```yaml
---

services:
  server:
    image: gitea/gitea:1.24.5
    container_name: gitea
    environment:
      - USER_UID=1000
      - USER_GID=1000
      - GITEA __database__ DB_TYPE=mysql
      - GITEA __database__ HOST=db:3306
      - GITEA __database__ NAME=${DB_NAME}
      - GITEA __database__ USER=${DB_USER}
      - GITEA __database__ PASSWD=${DB_PASSWORD}
    restart: always
    volumes:
      - /mnt/gitea/data/gitea:/data/gitea
      - /mnt/gitea/data/repositories:/data/git/repositories
      - /etc/timezone:/etc/timezone:ro
      - /etc/localtime:/etc/localtime:ro
    ports:
      - "3000:3000"
      - "2443:22"
    depends_on:
      - db
  db:
    image: mysql:8
    restart: always
    container_name: gitea-db
    environment:
      - MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD}
      - MYSQL_USER=${DB_USER}
      - MYSQL_PASSWORD=${DB_PASSWORD}
      - MYSQL_DATABASE=${DB_NAME}
    volumes:
      - ./mysql:/var/lib/mysql

  runner:
    image: gitea/act_runner:0.2.12
    container_name: gitea-runner
    environment:
      CONFIG_FILE: /config.yaml
      GITEA_INSTANCE_URL: "https://my.domain.com"
      GITEA_RUNNER_REGISTRATION_TOKEN:"${RUNNER_TOKEN}"
      GITEA_RUNNER_NAME: "${RUNNER_NAME}"
      GITEA_RUNNER_LABELS: "${RUNNER_LABELS}"
    restart: always
    volumes:
      - ./config.yaml:/config.yaml
      - /mnt/gitea/runner/data:/data
      - /var/run/docker.sock:/var/run/docker.sock

  pages:
      image: ghcr.io/simongregorebner/gitea-pages:0.0.10
      container_name: gitea-pages
      restart: always
      volumes:
        - ./Caddyfile:/etc/caddy/Caddyfile:ro
        - /etc/timezone:/etc/timezone:ro
        - /etc/localtime:/etc/localtime:ro
      ports:
        - "8080:8080/tcp"

```

#### Gitea’s app.ini from environment variables

Only the emails, domain name, and https have been changed.

I hope I have provided all the necessary information. Thank you for your feedback.

---

<div class="post-metadata">

**Author:** ![jeremy-bepoix](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/jeremy-bepoix/32/7059_2.png) [@jeremy-bepoix](https://forum.gitea.com/u/jeremy-bepoix)\
**Post date:** [August 19, 2025, 11:53am UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646/2 "2025-08-19T11:53:16Z")

</div>

Hello,  
Has anyone else encountered this problem? Or the method for using local image in the workflow is incorrect ?

---

<div class="post-metadata">

**Author:** ![alextegel](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/alextegel/32/7063_2.png) [@alextegel](https://forum.gitea.com/u/alextegel)\
**Post date:** [August 21, 2025, 1:31pm UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646/3 "2025-08-21T13:31:22Z")

</div>

Hi Jeremy,

I had the same error with own hosted runner images, but find a solution in adding the credentials for the image to the workflow.

```yaml
jobs:
  release:
    runs-on: ubuntu-20.04-act
      container:
        image: my.domain.com/repo/docker-images:ubuntu-20.04-act
        credentials: 
          username: ${{ secrets.REGISTRY_USERNAME }}
          password: ${{ secrets.REGISTRY_PASSWORD }}

```

Don’t forget to define your credentials as secrets in the repo/org/global 😉

---

<div class="post-metadata">

**Author:** ![jeremy-bepoix](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/jeremy-bepoix/32/7059_2.png) [@jeremy-bepoix](https://forum.gitea.com/u/jeremy-bepoix)\
**Post date:** [August 22, 2025, 12:43pm UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646/4 "2025-08-22T12:43:12Z")

</div>

HA !

All working good now, thank you @alextegel

Edit : i cannot label this post with [SOLVED]

---

<div class="post-metadata">

**Author:** ![flod1](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/flod1/32/7116_2.png) [@flod1](https://forum.gitea.com/u/flod1)\
**Post date:** [October 8, 2025, 9:50am UTC](https://forum.gitea.com/t/error-response-from-daemon-unauthorized-reqpackageaccess/11646/5 "2025-10-08T09:50:55Z")

</div>

i have the same error, and have added the correct secrets.

```auto
  listen-job:
    runs-on: ubuntu-latest
    container:
      image: mygitea/repo/image:0.0.3
    credentials:
      username: ${{ secrets.SRC_REGISTRY_USER }}
      password: ${{ secrets.SRC_REGISTRY_PASS }}

```

the toke have permission to read:packages.

```auto
expression 'success()' evaluated to 'true'
🚀 Start image=mygitea/repo/image:0.0.3
  🐳 docker pull image=mygitea/repo/image:0.0.3 platform= username= forcePull=false
  🐳 docker pull mygitea/repo/image:0.0.3
Image exists? false
pulling image 'mygitea/repo/image:0.0.3' ()
Error response from daemon: unauthorized: reqPackageAccess

```
