{"record":{"id":"69861d567955f830","repo":"spring-projects/spring-boot","slug":"invalid-docker-registry-configuration-either-t","errorCode":null,"errorMessage":"Invalid Docker {} registry configuration, either token or username/password must be provided","messagePattern":"Invalid Docker (.+?) registry configuration, either token or username/password must be provided","errorType":"exception","errorClass":"GradleException","httpStatus":null,"severity":"error","filePath":"build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/bundling/DockerSpec.java","lineNumber":171,"sourceCode":"\tprivate BuilderDockerConfiguration customizePublishAuthentication(BuilderDockerConfiguration dockerConfiguration) {\n\t\treturn dockerConfiguration\n\t\t\t.withPublishRegistryAuthentication(getRegistryAuthentication(\"publish\", this.publishRegistry,\n\t\t\t\t\tDockerRegistryAuthentication.configuration(DockerRegistryAuthentication.EMPTY_USER)));\n\t}\n\n\tprivate DockerRegistryAuthentication getRegistryAuthentication(String type, @Nullable DockerRegistrySpec registry,\n\t\t\tDockerRegistryAuthentication fallback) {\n\t\tif (registry == null || registry.hasEmptyAuth()) {\n\t\t\treturn fallback;\n\t\t}\n\t\tif (registry.hasTokenAuth() && !registry.hasUserAuth()) {\n\t\t\treturn DockerRegistryAuthentication.token(registry.getToken().get());\n\t\t}\n\t\tif (registry.hasUserAuth() && !registry.hasTokenAuth()) {\n\t\t\treturn DockerRegistryAuthentication.user(registry.getUsername().get(), registry.getPassword().get(),\n\t\t\t\t\tregistry.getUrl().getOrNull(), registry.getEmail().getOrNull());\n\t\t}\n\t\tthrow new GradleException(\"Invalid Docker \" + type\n\t\t\t\t+ \" registry configuration, either token or username/password must be provided\");\n\t}\n\n\t/**\n\t * Encapsulates Docker registry authentication configuration options.\n\t */\n\tpublic abstract static class DockerRegistrySpec {\n\n\t\t/**\n\t\t * Returns the username to use when authenticating to the Docker registry.\n\t\t * @return the registry username\n\t\t */\n\t\t@Input\n\t\t@Optional\n\t\tpublic abstract Property<String> getUsername();\n\n\t\t/**\n\t\t * Returns the password to use when authenticating to the Docker registry.","sourceCodeStart":153,"sourceCodeEnd":189,"githubUrl":"https://github.com/spring-projects/spring-boot/blob/270dfe353fb830fd69b823a8a859287ff103854b/build-plugin/spring-boot-gradle-plugin/src/main/java/org/springframework/boot/gradle/tasks/bundling/DockerSpec.java#L153-L189","documentation":"Thrown by DockerSpec.getRegistryAuthentication when a DockerRegistrySpec is provided (non-null, non-empty-auth) but has neither token-only auth (hasTokenAuth false) nor user/password auth (hasUserAuth false). The method first checks for token auth, then user auth; if neither is fully present, it throws. The 'type' placeholder in the message identifies which registry (e.g. builder or publish).","triggerScenarios":"Configuring docker.builderRegistry or docker.publishRegistry with a partial credentials object: e.g. username set but no password, or password set but no username, and no token either. Also triggered if the registry spec has some fields but neither auth path is complete.","commonSituations":"Setting username but forgetting password (or vice versa) in publishRegistry or builderRegistry. Providing a username/password in one place and a token in another, then removing one partially. Secrets managed via environment/gradle.properties that are not resolved, leaving the spec half-populated.","solutions":["Provide a complete token auth (token set) OR complete user auth (username AND password set) — not both incomplete.","Check that username and password are both non-null when using user/password auth.","If using token auth, ensure only the token is set.","Verify credentials sourced from gradle.properties or environment variables are actually resolving (no typos in property names)."],"exampleFix":"// before\ntasks.bootBuildImage {\n    docker {\n        publishRegistry {\n            username = \"myuser\"\n            // password missing -> throws\n        }\n    }\n}\n// after\ntasks.bootBuildImage {\n    docker {\n        publishRegistry {\n            username = \"myuser\"\n            password = \"secret\"\n        }\n    }\n}","handlingStrategy":"validation","validationCode":"// Validate registry auth completeness before the task runs.\nDockerRegistrySpec reg = dockerSpec.getPublishRegistry();\nif (reg != null && !reg.hasEmptyAuth()) {\n    boolean tokenOk = reg.hasTokenAuth();\n    boolean userOk = reg.hasUserAuth();\n    if (!tokenOk && !userOk) {\n        throw new GradleException(\"Provide either token or username+password for the registry.\");\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Provide complete credentials: token alone, or username AND password together.","Verify gradle.properties / environment variables resolve before the build.","Avoid mixing token and username/password auth in the same registry spec."],"tags":["gradle","validation","build-image","docker","registry","authentication","configuration"],"backgroundTag":null,"analyzedSha":"270dfe353fb830fd69b823a8a859287ff103854b","analyzedAt":"2026-08-11T19:42:06.541Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}