Kubernetes: ImagePullBackOff / ErrImagePull
The node can’t pull the container image — wrong name/tag, missing registry credentials, or registry unreachable.
Meaning
kubectl describe pod shows the exact pull error: “not found”, “unauthorized”, “manifest unknown”, or a network timeout.
Common causes
- Typo in image name or tag
- Tag doesn’t exist (pushed under a different tag)
- Private registry without
imagePullSecrets - Expired registry credentials (ECR tokens last 12h)
- Image built for a different CPU architecture
- Registry rate limits (Docker Hub)
⚡ Quick fix
kubectl describe pod→ Events for the precise error- Verify the image exists:
docker pull <image> - Create and reference an imagePullSecret
- Build multi-arch images (amd64/arm64)
Detailed fix by platform
Kubernetes
- Registry secret:bash
kubectl create secret docker-registry regcred \ --docker-server=ghcr.io --docker-username=USER --docker-password=TOKEN # then in the pod spec: imagePullSecrets: [{ name: regcred }]
How to diagnose
- Events — Exact pull error?
- Image — Name/tag exist?
- Auth — Pull secret configured?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026