VectleSkillsINSTALLATION FAILED: failed to perform "FetchReference": unauthorized: authentication required

INSTALLATION FAILED: failed to perform "FetchReference": unauthorized: authentication required

Export

Routes helm OCI chart pull 401s. Use when helm install from an oci:// URL fails with FetchReference unauthorized. Not for unknown chart tags, DNS failures, or non-OCI repos.

The OCI registry hosting the chart needs a login and helm has none cached - usually a private package (GHCR, ACR, ECR). Run helm registry login [registry-host] with a token that has package read permission. For GHCR that is a token with packages read scope. Then re-run the install - the fetch succeeds.

The error

Error: INSTALLATION FAILED: failed to perform "FetchReference" on source: GET "https://ghcr.io/v2/[org]/[chart]/manifests/[tag]": unexpected status code 401: unauthorized: authentication required

What to do

  1. Log in to the registry:
echo [token] | helm registry login ghcr.io -u [username] --password-stdin

Expected: Prints Login Succeeded.

  1. Re-run the install:
helm install [release] oci://ghcr.io/[org]/[chart] --version [tag]

Expected: Install starts instead of the 401.

  1. In CI, grant the job packages read and log in with the job token before install.

Expected: Green run.

When this applies

  • helm install/upgrade/template against oci:// chart URLs
  • the exact FetchReference 401 unauthorized message
  • private GHCR/ACR/ECR chart packages

When it does NOT apply

  • 404 or MANIFEST_UNKNOWN (wrong chart path or tag)
  • classic chart repository 401s (use helm repo add credentials instead)

Works with

helm 3.8+ (OCI GA); any OCI registry

failed to authorize: failed to fetch anonymous token - unexpected status code 401

Same missing-login cause on registries with token auth. Same helm registry login fix.

Why it happens

OCI registries answer 401 to anonymous pulls of private artifacts. Helm keeps registry credentials in ~/.config/helm/registry/config.json - empty on a fresh machine or CI runner, so the pull is anonymous and rejected.

Edge cases

  • helm registry login credentials expire with the token - CI must log in on every run.
  • GHCR fine-grained PATs need the right repository access; a token without package read still 401s after a successful login.

Resolved from

gh:openova-io/openova (preflight CI fix commit) - https://github.com/openova-io/openova/commit/6f9ee43a9d5eb622a5bff930269aab4588d8a5eb

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=INSTALLATION+FAILED%3A+failed+to+perform+%22FetchReference%22%3A+unauthorized%3A+authentication+required&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.