docker · Docker
The message
pull access denied for myapp, repository does not exist or may require 'docker login'
What it means
The registry would not show you that repository, and the important part is that the message covers two causes at once: the name does not exist, or it exists and you are not allowed to see it. You are not logged in for a private repository, or the name is missing its user or organisation (myapp and myorg/myapp are different repositories), or the name is simply wrong. For a private image, docker login against that registry; if it is supposed to be public, re-read the spelling. Registries deliberately do not distinguish "absent" from "forbidden", because the existence of a name is itself information.
The fix
docker login- Printed by
- docker
- Docker
- 12
Docker errors only become readable once you place them in a layer — the client failing to reach the daemon, the registry refusing you, a RUN failing during the build, and a container dying the instant it starts are four different problems — and for the build and run layers the line itself is not the reason: the reason is in the output of the command that was running inside, while the cost of each fix differs by layer too.
Reading an error message
- Read from the first line down. The lower you go the more it is about the tool’s internals; the cause is usually at the top.
- If there is a file and a line number, start there — not the top stack frame, but the topmost line that names a file you wrote.
- Search the message verbatim, but strip your own paths and variable names first; those are what stop the search from matching.
- The same condition is worded differently across tool versions. If results look wrong, add the version number to the query.
- Before pasting a fix, check what it throws away. Some of these cannot be undone.
Common questions
Q. What does “pull access denied for myapp, repository does not exist or may require 'docker login'” mean?
The registry would not show you that repository, and the important part is that the message covers two causes at once: the name does not exist, or it exists and you are not allowed to see it. You are not logged in for a private repository, or the name is missing its user or organisation (myapp and myorg/myapp are different repositories), or the name is simply wrong. For a private image, docker login against that registry; if it is supposed to be public, re-read the spelling. Registries deliberately do not distinguish "absent" from "forbidden", because the existence of a name is itself information.
Q. How do I fix it?
docker login — before running it, check the explanation above for what this command discards.
Q. Which tool prints this?
docker. It sits under Docker, and the message runs to 14 words.