# Unauthorized: reqPackageAccess when pushing to container registry

**URL:** <https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002>\
**Category:** Gitea Usages\
**Created:** [November 8, 2024, 12:30pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002 "2024-11-08T12:30:16Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 8, 2024, 12:30pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/1 "2024-11-08T12:30:16Z")

</div>

HI, after succesful login on command line to gitea I tried to push an image as a test (this is my first use)

> docker push [gitea.cnoe.localtest.me:8443/giteaadmin/ubuntu:24.04](http://gitea.cnoe.localtest.me:8443/giteaadmin/ubuntu:24.04)

I get

> a46a5fb872b5: Preparing  
> unauthorized: reqPackageAccess

I understood from thread #31531 on github that we need to create a token with read/write access which I did but not sure how to use it.  
Thanks for your help

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 8, 2024, 3:12pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/2 "2024-11-08T15:12:01Z")

</div>

After updating password for giteaAdmin and doing docker login again I was able to push. However, when I do  
docker ps  
it lists images found on the localhost not inside gitea. So how can I list or where I can see the images list? Thanks

---

<div class="post-metadata">

**Author:** ![phkrl](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/phkrl/32/6028_2.png) [@phkrl](https://forum.gitea.com/u/phkrl)\
**Post date:** [November 9, 2024, 9:10am UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/3 "2024-11-09T09:10:12Z")

</div>

By design, docker ps only shows images local to daemon. If you want to inspect remote registry, you should either browse it directly from web UI or use other tool called skopeo. The latter is specifically designed to work with remote docker/oci registries.

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 9, 2024, 10:19am UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/4 "2024-11-09T10:19:26Z")

</div>

Thanks phkrl does gitea has a web ui to be used? if yes, should we install it? I can access gitea and create project or organization repos.

---

<div class="post-metadata">

**Author:** ![phkrl](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/phkrl/32/6028_2.png) [@phkrl](https://forum.gitea.com/u/phkrl)\
**Post date:** [November 9, 2024, 10:49am UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/5 "2024-11-09T10:49:19Z")

</div>

All containers are under packages tab in organization view. From there you can also link package (container) to repo and access tags from packages tab in project

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 15, 2024, 9:16am UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/6 "2024-11-15T09:16:10Z")

</div>

Thanks phkrl, while I was waiting for your response I needed to regenerate my cluster, I am able to do docker login [gitea.cnoe.localtest.me:8443](http://gitea.cnoe.localtest.me:8443) successfuly but now when I do docker push [gitea.cnoe.localtest.me:8443/giteaAdmin/ubuntu24.04](http://gitea.cnoe.localtest.me:8443/giteaAdmin/ubuntu24.04) I get  
“failed to authorize…” as you can notice in the snapshot

 ![image](https://us1.discourse-cdn.com/flex020/uploads/gitea/original/2X/a/abba427ac1ff357f1319dbcc44cbc97f0835b138.png)

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 17, 2024, 4:05pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/7 "2024-11-17T16:05:48Z")

</div>

Please dont hide as it is a normal reply

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [November 17, 2024, 9:15pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/8 "2024-11-17T21:15:03Z")

</div>

The error displayed that your Gitea’s HTTPS certification is self-signed.

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 18, 2024, 9:56am UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/9 "2024-11-18T09:56:14Z")

</div>

Thanks, I noticed this, So what should I do? It is a dev VM? Is there a flag to make it ignor this?

---

<div class="post-metadata">

**Author:** ![phkrl](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/phkrl/32/6028_2.png) [@phkrl](https://forum.gitea.com/u/phkrl)\
**Post date:** [November 18, 2024, 6:47pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/10 "2024-11-18T18:47:51Z")

</div>

Seems like docker tls options do not affect registries. Maybe you can configure registry to be trusted in daemon json config but you need to consult docker documentation on that.  
I suppose, the simplest way will be to add your gitea certificate to the trusted ones on VM running docker daemon. This procedure is distro-specific but usually you can simply google the solution.

---

<div class="post-metadata">

**Author:** ![illbreakurcode](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/illbreakurcode/32/6452_2.png) [@illbreakurcode](https://forum.gitea.com/u/illbreakurcode)\
**Post date:** [November 23, 2024, 2:01pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/11 "2024-11-23T14:01:31Z")

</div>

> [@salam](#):
>
> After updating password for giteaAdmin and doing docker login again I was able to push.

Hello i have the exact same problem and nothing works… what do you mean by giteaAdmin? because I use a Personal token to push it and everytime i get that exact error

UPDATE:  
gitea | 2024/11/23 14:14:50 …eb/routing/logger.go:102:func1() [I] router: completed POST /v2/soundbot/soundbot/python/blobs/uploads/ for HERE-WAS-MY-IP:5381, 401 Unauthorized in 2.9ms @ packages/api.go:714(packages.ContainerRoutes.func2.2)  
gitea | 2024/11/23 14:14:50 …eb/routing/logger.go:102:func1() [I] router: completed POST /v2/soundbot/soundbot/python/blobs/uploads/ for HERE-WAS-MY-IP:5407, 401 Unauthorized in 4.8ms @ packages/api.go:714(packages.ContainerRoutes.func2.2)  
gitea | 2024/11/23 14:14:50 …eb/routing/logger.go:102:func1() [I] router: completed POST /v2/soundbot/soundbot/python/blobs/uploads/ for HERE-WAS-MY-IP:5500, 401 Unauthorized in 3.2ms @ packages/api.go:714(packages.ContainerRoutes.func2.2)  
gitea | 2024/11/23 14:14:50 …eb/routing/logger.go:102:func1() [I] router: completed POST /v2/soundbot/soundbot/python/blobs/uploads/ for HERE-WAS-MY-IP:5483, 401 Unauthorized in 16.7ms @ packages/api.go:714(packages.ContainerRoutes.func2.2)  
gitea | 2024/11/23 14:14:50 …eb/routing/logger.go:102:func1() [I] router: completed POST /v2/soundbot/soundbot/python/blobs/uploads/ for HERE-WAS-MY-IP:5398, 401 Unauthorized in 22.2ms @ packages/api.go:714(packages.ContainerRoutes.func2.2)

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 23, 2024, 4:41pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/12 "2024-11-23T16:41:24Z")

</div>

How do you use the personal token?

---

<div class="post-metadata">

**Author:** ![illbreakurcode](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/illbreakurcode/32/6452_2.png) [@illbreakurcode](https://forum.gitea.com/u/illbreakurcode)\
**Post date:** [November 25, 2024, 5:56pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/13 "2024-11-25T17:56:45Z")

</div>

i go to my gitea user settings then make an application with just everything on read & write put in a name and copy the token in the blue box… then I run docker login type in my username/the application name (I have tryed both) and then with password i put in the token i got and it says success… but the logs say 401 unauthorized when i try to push and on my end in the console it gives the title of this thread

---

<div class="post-metadata">

**Author:** ![salam](https://avatars.discourse-cdn.com/v4/letter/s/8491ac/32.png) [@salam](https://forum.gitea.com/u/salam)\
**Post date:** [November 25, 2024, 6:54pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/14 "2024-11-25T18:54:08Z")

</div>

Hi, in fact, I stopped using docker push as it seems there is no way to use a flag such as -tlsverify = false, so as I have podman on another VM, I used podman eith the tls flag and it worked a like a charm

---

<div class="post-metadata">

**Author:** ![illbreakurcode](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/illbreakurcode/32/6452_2.png) [@illbreakurcode](https://forum.gitea.com/u/illbreakurcode)\
**Post date:** [November 26, 2024, 5:02pm UTC](https://forum.gitea.com/t/unauthorized-reqpackageaccess-when-pushing-to-container-registry/10002/15 "2024-11-26T17:02:45Z")

</div>

it worked… thank you
