From f6cdeffc40a6e075fbfbcc7237498b635d2d114c Mon Sep 17 00:00:00 2001 From: Nikita Bugrovsky Date: Mon, 28 Sep 2026 12:16:11 +0300 Subject: [PATCH] doc: reference driver.imagePullSecrets Signed-off-by: Nikita Bugrovsky --- .../gpu-operator-with-precompiled-drivers.rst | 25 ++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/openshift/gpu-operator-with-precompiled-drivers.rst b/openshift/gpu-operator-with-precompiled-drivers.rst index 3462b0fe6..83988a371 100644 --- a/openshift/gpu-operator-with-precompiled-drivers.rst +++ b/openshift/gpu-operator-with-precompiled-drivers.rst @@ -33,9 +33,32 @@ To use a Red Hat-provided precompiled driver image, set the ``driver`` fields of "usePrecompiled": true, "repository": "registry.redhat.io/nvidia", "image": "gpu-driver-rhel9", - "version": "580" + "version": "580", + "imagePullSecrets": ["redhat-registry-secret"] } +Because ``registry.redhat.io`` requires authentication, ``driver.imagePullSecrets`` must reference a pull secret in the ``nvidia-gpu-operator`` namespace that contains valid ``registry.redhat.io`` credentials. Refer to `Red Hat Container Registry Authentication `_ for the supported authentication mechanisms: + +.. note:: + + The cluster-wide pull secret, ``openshift-config/pull-secret``, usually already has access to ``registry.redhat.io``. + However, the pull secret is not automatically scoped to the ``nvidia-gpu-operator`` namespace. + You still must create a namespace-scoped secret and reference it in ``driver.imagePullSecrets``. + +* **Customer Portal credentials**: Your individual Red Hat login. Simplest to use, but ties image pulls to a personal account. + +* **Registry Service Account token**: A dedicated username and token generated from the `Registry Service Account Management Application `_, decoupled from any individual account. Recommended for shared systems such as an OpenShift cluster. + +Create the pull secret using either credential type: + +.. code-block:: console + + $ oc create secret docker-registry redhat-registry-secret \ + --docker-server=registry.redhat.io \ + --docker-username= \ + --docker-password= \ + -n nvidia-gpu-operator + *********************************** Limitations and Restrictions ***********************************