How to Fix “Failed To Pull Docker Image” Errors When Deploying Supabase
If you’re setting up Supabase on your own infrastructure or using the Docker images in a CI/CD pipeline, a sudden “Failed to pull Docker image” can feel like a roadblock. It’s often the first symptom of a deeper mismatch between your environment and the Supabase image requirements. In this guide we break down the most common reasons this happens, show you step‑by‑step troubleshooting tips, and give you a checklist to keep future deployments running smoothly.
Why Supabase Images Fail to Pull
The error usually pops up for one of several reasons:
- Authentication Issues – The registry requires credentials you haven’t supplied or your token has expired.
- Wrong Image Tag or Repository – You’re pointing at a non‑existent or outdated tag.
- Network or DNS hiccups that prevent your host from reaching Docker Hub or a private registry.
- Docker version incompatibility—Supabase images sometimes rely on features only present in newer Docker releases.
- Supabase CLI or configuration mismatches that misdirect the pull command.
Step 1: Verify the Image Reference
Supabase publishes official images under supabase/supabase:latest or specific version tags such as supabase/supabase:1.33.0. Double‑check the tag in your docker-compose.yml or deployment script. A common pitfall is an accidental trailing space or a typo like supabase/supabase:latest1.
Run:
docker pull supabase/supabase:latestIf this command fails, the issue is with the image itself, not your configuration.
Step 2: Ensure You’re Logged In
Docker Hub’s public images are free to pull, but private or enterprise registries—common in corporate setups—require authentication. Use:
docker loginEnter your credentials. If you’re using a service account or token, make sure it still has the correct scopes. An expired or revoked token will trigger the same pull error.
Step 3: Check Network Connectivity
Sometimes the problem lies outside Docker: a corporate proxy, firewall, or DNS issue can block access. Test the registry directly:
curl -I https://registry-1.docker.io/v2/A 200 OK means your host can reach Docker Hub. If you see a timeout or a 403, investigate your network settings. Remember that Supabase images might also be stored in region‑specific registries; ensure your DNS resolution matches those regions.
Step 4: Align Docker Engine and Supabase CLI Versions
Supabase’s Docker integration expects Docker Engine 20.10+ and Compose v2. An older Docker Engine can misinterpret image manifests, leading to a pull failure. Update Docker with the vendor’s instructions or use a container‑based Docker (like docker:dind) in CI environments.
For the CLI, run:
supabase --versionMake sure it’s at least 0.28.0 or newer; older CLI versions may generate outdated image references.
Step 5: Clear Docker Cache
Occasionally stale metadata can cause Docker to try pulling an old digest. Clearing the cache forces a fresh download:
docker system prune -aBe careful: this removes unused images and containers. After pruning, run the pull command again.
Step 6: Review Supabase Project Configuration
When you deploy Supabase with the CLI, it writes a .supabase/cli.toml that may include a registry field. If you’ve customized the registry to a private registry, double‑check the URL and credentials. A typo in the registry string will point Docker at a non‑existent endpoint.
Step 7: Look at Docker Logs for Detailed Errors
Run:
docker pull supabase/supabase:latest 2>&1 | tee /tmp/docker-pull.logIn the log, search for manifest for or authentication required. Those lines often reveal whether the issue is a missing digest or a credentials problem.
Common Fixes Summarized
- Correct the image tag.
- Run
docker loginand confirm token validity. - Ensure network paths to Docker Hub or your private registry are open.
- Update Docker Engine and Supabase CLI.
- Clear the Docker cache.
- Validate any custom registry settings in
cli.toml.
Preventing Future Pull Errors
Once you’ve resolved the immediate failure, set up a few safeguards:
- Pin image tags in
docker-compose.ymlrather than usinglatest. - Store registry credentials securely with tools like Docker Secrets or your CI provider’s secret manager.
- Automate
docker system prunein CI pipelines to avoid cache corruption. - Keep your Docker Engine and Supabase CLI under version control or use a container image for the CI environment that matches production.
FAQ
Q: What if the image is still not pulling after I’ve logged in?
A: Verify that the registry you’re pulling from matches the credentials you entered. If you’re behind a corporate proxy, you might need to configure HTTP_PROXY and HTTPS_PROXY environment variables for Docker.
Q: How do I know which Supabase image tag to use?
A: Check the Supabase GitHub releases page or the Docker Hub tags page. Align the tag with the Supabase version your project supports.
Q: Does the error mean the Supabase service is down?
A: Rarely. The error usually reflects a client‑side issue. However, you can confirm by visiting https://status.supabase.com to see if there are any outages.
Q: Can I use a local registry for Supabase images?
A: Yes, but you must mirror the images locally and adjust the registry field in cli.toml accordingly. Ensure your local registry is reachable from the deployment host.
By following these steps, you’ll quickly pinpoint whether a misconfigured tag, missing credentials, or network hiccup is preventing Docker from fetching Supabase images. Once you’ve addressed the root cause, your deployments should run without interruption, allowing you to focus on building great applications on Supabase.