TL;DR: Either log in (`docker login`) or fix the image name typo. The registry cannot tell 'private repo you lack access to' from 'repo that does not exist', so it reports both. Check `docker pull` spelling first, then authenticate.

## The error

```text
Error response from daemon: pull access denied for myimage, repository does not exist or may require 'docker login': denied: requested access to the resource is denied
```

## Fix it

1. Check the name for typos:
   `echo [image]` and compare against the registry UI.
   Expected: often a wrong namespace or tag.
2. Log in:
   `docker login`
   Expected: `Login Succeeded`.
3. Retry the pull:
   `docker pull [image]`
   Expected: succeeds.

## When this applies
- Private Docker Hub repos, GHCR, ECR, GCR, ACR pulls
- CI jobs missing registry credentials

## When this does NOT apply
- "manifest unknown" (name parsed, tag missing)
- "toomanyrequests" (rate limit, different fix)

## Versions
All Docker versions.

## Why it happens
Registries return 401/403 identically for missing and forbidden repos (to avoid leaking which private repos exist). The daemon surfaces the combined message.

## Edge cases
- Expired tokens produce the same message as never-logged-in; `docker logout` then `docker login` refreshes.
- Credential helpers (docker-credential-desktop) can go stale; if login loops, check the helper (separate skill).
- Multi-arch: the name may be right but the tag only exists for another arch; then you get manifest errors instead.
