Docker registry authentication failure
April 30, 2026 ยท View on GitHub
Playbook ID: docker-auth
Category: auth
Severity: high
Tags: docker, registry, auth
What this failure means
CI could not authenticate to the container registry before an image pull or push.
Common log signals
pull access denied
requested access to the resource is denied
unauthorized: authentication required
no basic auth credentials
denied: requested access to the resource is denied
may require 'docker login'
Error response from daemon: Get https://mcr.microsoft.com/v2/: Forbidden
Diagnosis
Docker reached the registry, but the credentials used by CI were missing, expired, or scoped incorrectly for the target image.
Typical causes:
- the login step never ran
- the secret value rotated without the workflow updating
- the token can read one repo but not the image path being used
Fix steps
-
Verify the registry username, token, or password configured in CI secrets.
-
Ensure the registry login step runs before any
docker pullordocker pushcommand. -
Confirm the token has the correct repository scope for the image being accessed.
-
Validate the same credential locally:
docker login <registry>
Validation
- Re-run the registry login step.
- Confirm the pull or push completes without
authentication required. - If you changed secret wiring, run one full CI job after rotating the credential.
Likely files to inspect
Dockerfile.github/workflows/*.yml.github/workflows/*.yamldocker-compose*.yml
Run Faultline
faultline analyze build.log
faultline explain docker-auth
faultline workflow build.log --json --mode agent
Search phrases this page answers
- Docker registry authentication failure
- Auth: docker registry authentication failure
- Error response from daemon: Get https://mcr.microsoft.com/v2/: Forbidden
- faultline explain docker-auth
- Docker docker registry authentication failure
Generated from playbooks/bundled/log/auth/docker-auth.yaml. Do not edit directly โ run make docs-generate.