docker push: "Requested Access to the Resource Is Denied"

You're authenticated, but as the wrong user or against the wrong repo path. The tag name must match the registry/repo you own — most denials are a missing namespace or username typo in the tag.

What you'll see

Root causes

Tag doesn't include your namespace

docker push myapp:latest defaults to docker.io/library/myapp — the official namespace you don't own. It must be docker push <username>/myapp:latest.

Logged in as a different account than the repo owner

docker login with a personal account but pushing to an org repo you lack write access to. Check: docker system info | grep Username.

ECR/other registries: auth or repo-creation semantics

ECR requires the full registry path (aws_account.dkr.ecr.region.amazonaws.com/repo:tag) and the repo policy grants push. GCR/ghcr have their own path formats and token scopes.

Fix it

  1. See who you actually are and where you're pushing
    docker system info | grep -i username ; docker image ls | grep <image>
  2. Retag with the correct namespace
    docker tag myapp:latest <username>/myapp:latest && docker push <username>/myapp:latest
  3. ECR: authenticate per-registry and push the full path
    aws ecr get-login-password --region <r> | docker login --password-stdin <acct>.dkr.ecr.<r>.amazonaws.com && docker push <acct>.dkr.ecr.<r>.amazonaws.com/myrepo:tag
  4. ghcr.io: PAT with write:packages scope
    echo $GITHUB_TOKEN | docker login ghcr.io -u <user> --password-stdin && docker push ghcr.io/<owner>/myapp:tag

Field note

docker login can hold different creds per registry host simultaneously — check which one applies to the exact registry in your tag. Renamed Docker Hub repos: old local tags still reference the old path; retag before push.

Common questions

I logged in successfully but push says denied. Why?

Login proves identity; push needs the tag path to match a repo you (or your org) can write. Most common miss: pushing 'myapp' instead of '<username>/myapp' — the implicit library/ namespace is not yours.

How do I push to an organization's repo?

Be a member with write access (org settings), log in with an account that has it, and tag with the org name as namespace: org/myapp:tag. Personal logins can't push by default.

Ship it right the first time

A production-shaped compose stack: healthchecks, resource limits, log rotation. Never debug a boot race again.

Docker Production Starter — $19 →

One-time. Yours to modify. Instant download from the NinjaOps template store.