On the machine running depot build, run docker login against the private registry first, then build; Depot picks up those credentials automatically. If it still fails, verify with a plain docker pull of the base image to separate credential problems from build problems. In CI, add a docker/login-action step before the Depot build step so the remote builder inherits the credentials for FROM pulls.

Context: Official Depot docs (Access private registries how-to): documents the auth gotcha that trips agents when a Dockerfile FROM references a private registry. The remote builder has no credentials of its own, so the pull fails. The depot CLI automatically reuses your local Docker credential store, which makes the fix a local login, not a Depot setting.