---
name: codeengine-job-create-cr
title: Creating a job from images in IBM Cloud Container Registry
description: Create your job configuration that uses an image in IBM Cloud&reg; Container Registry. You can create a job from the console or with the CLI.
last-updated: 2026-07-08
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/codeengine?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Creating a job from images in IBM Cloud Container Registry
{: #create-job-crimage}

Create your job configuration that uses an image in IBM Cloud&reg; Container Registry. You can create a job from the console or with the CLI.
{: shortdesc}

Before you begin

- You must have an image in Container Registry. For more information, see [Getting started with Container Registry](https://cloud.ibm.com/docs/Registry?topic=Registry-getting-started&format=markdown#getting-started). Or, you can build an image from [repository source](https://cloud.ibm.com/docs/codeengine?topic=codeengine-run-job-source-code&format=markdown) or from [local source](https://cloud.ibm.com/docs/codeengine?topic=codeengine-job-local-source-code&format=markdown).

- Verify that you can access the registry. See [Setting up authorities for container registries](https://cloud.ibm.com/docs/codeengine?topic=codeengine-add-registry&format=markdown#authorities-registry).


Interested in configuring your project such that all users of the project can store and access images in Container Registry without having to manually create registry secrets? With sufficient permissions, you can configure this default registry access on a per location (region) basis. If you don't have sufficient permissions to perform these actions, you can use this page to help you understand the required permissions. See [Configuring project-wide settings](https://cloud.ibm.com/docs/codeengine?topic=codeengine-project-integrations&format=markdown). 
{: note}


## Creating a job that references an image in Container Registry with the console
{: #create-job-crimage-console}

Create a job configuration that uses an image in Container Registry by using the Code Engine console.
{: shortdesc}

Code Engine can automatically pull images from a Container Registry namespace in your account. To pull images from a different Container Registry account or from a private Docker Hub account, see [Create a job from images in a private registry](https://cloud.ibm.com/docs/codeengine?topic=codeengine-create-job-private&format=markdown).

1. Open the [Code Engine](https://cloud.ibm.com/codeengine/overview){: external} console.
2. Select **Start creating**.
3. Select a project from the list of available projects. You can also [create a new one](https://cloud.ibm.com/docs/codeengine?topic=codeengine-manage-project&format=markdown#create-a-project). Note that you must have a selected project to create a job.
4. Select **Job**.
5. Enter a name for the job; for example, `myjob`.
6. Select **Use an existing container image** and click **Configure image**.
7. Select a container registry location, such as `IBM Registry Dallas`.
8. Select `Code Engine managed secret` for **Registry secret**. Because this example uses an image in a Container Registry namespace in your account, Code Engine can automatically create and manage the registry secret for you.
9. Select an existing namespace and name of the image in the registry for the Code Engine job to reference. For example, select `mynamespace` and select the image `hello_repo` in that namespace.
10. Select a value for **Tag**; for example, `latest`.
11. Click **Done**.
12. Modify any default values for environment variables or runtime settings. For more information about these options, see [Options for creating and running a job](https://cloud.ibm.com/docs/codeengine?topic=codeengine-job-plan&format=markdown#job-options).
13. From the Create job page, click **Create**.
14. After your job is created, the job page for your specific job opens. From your job page, click **Submit job** to submit a job based on the current configuration.

Now that you have created your job and [run your job](https://cloud.ibm.com/docs/codeengine?topic=codeengine-run-job&format=markdown), you can view details about your job configuration and job runs from your job page.  


If you want to add registry access before you create a job, see [Accessing container registries](https://cloud.ibm.com/docs/codeengine?topic=codeengine-add-registry&format=markdown).

## Creating a job with an image in Container Registry with the CLI
{: #create-job-crimage-cli}

Create a job configuration that uses an image in IBM Cloud&reg; Container Registry with the CLI, use the **`job create`** command. For a complete listing of options, see the [**`ibmcloud ce job create`**](https://cloud.ibm.com/docs/codeengine?topic=codeengine-cli&format=markdown#cli-job-create) command.
{: shortdesc}

Before you begin

* Set up your [Code Engine CLI](https://cloud.ibm.com/docs/codeengine?topic=codeengine-install-cli&format=markdown) environment.
* [Create and work with a project](https://cloud.ibm.com/docs/codeengine?topic=codeengine-manage-project&format=markdown).
* Before you can work with a Code Engine job that references an image in Container Registry, you must first add access to the registry so Code Engine can pull the image when the job is run. For information about required permissions for accessing image registries, see [Setting up authorities for image registries](https://cloud.ibm.com/docs/codeengine?topic=codeengine-add-registry&format=markdown#authorities-registry).

1. To add access to Container Registry, [create an IAM API key](https://cloud.ibm.com/docs/codeengine?topic=codeengine-add-registry&format=markdown#images-your-account-api-key). To create an IBM Cloud IAM API key from the CLI, run the [**`iam api-key-create`**](https://cloud.ibm.com/docs/iam?topic=iam-ibmcloud_commands_iam&format=markdown#ibmcloud_iam_api_key_create) command. For example, to create an API key called `cliapikey` with a description of `My CLI API key` and save it to a file called `key_file`, run the following command:

    ```txt
    ibmcloud iam api-key-create cliapikey -d "My CLI API key" --file key_file
    ```
    {: pre}

    If you choose to not save your key to a file, you must record the API key that is displayed when you create it. You cannot retrieve it later.
    {: important}

2. After you create your API key, add registry access to Code Engine. To add access to Container Registry with the CLI, use the [**`ibmcloud ce secret create --format registry`**](https://cloud.ibm.com/docs/codeengine?topic=codeengine-cli&format=markdown#cli-secret-create) command to create a registry secret. For example, the following command creates registry access to a Container Registry instance called `myregistry`. Note, even though the `--server` and `--username` options are specified in the example command, the default value for the `--server` option is `us.icr.io` and the `--username` option defaults to `iamapikey` when the server is `us.icr.io`.

    ```txt
    ibmcloud ce secret create --format registry --name myregistry --server us.icr.io --username iamapikey --password APIKEY
    ```
    {: pre}

    Example output

    ```txt
    Creating registry secret 'myregistry'...
    OK
    ```
    {: screen}

3. Create your job configuration and reference the `hello_repo` image in Container Registry. For example, the following **`job create`** command creates the `myhellojob` job to reference the `us.icr.io/mynamespace/hello_repo` by using the `myregistry` access information.

    ```txt
    ibmcloud ce job create --name myhellojob --image us.icr.io/mynamespace/hello_repo --registry-secret myregistry
    ```
    {: pre}

    The format of the name of the image for this job is `REGISTRY/NAMESPACE/REPOSITORY:TAG` where `REGISTRY` and `TAG` are optional. If `REGISTRY` is not specified, the default is `docker.io`. If `TAG` is not specified, the default is `latest`.
    {: note}


## Next steps
{: #nextsteps-jobcreatecr}

* After you create your job, submit the job to run it. See [Run a job](https://cloud.ibm.com/docs/codeengine?topic=codeengine-run-job&format=markdown). You can run your job multiple times. 

* After you [run your job](https://cloud.ibm.com/docs/codeengine?topic=codeengine-run-job&format=markdown), to view details of your job and job runs, see [access job details](https://cloud.ibm.com/docs/codeengine?topic=codeengine-access-job-details&format=markdown).

* Now that your job is created, consider making your jobs event-driven. By using event subscriptions, you can trigger your jobs by [periodic schedules](https://cloud.ibm.com/docs/codeengine?topic=codeengine-subscribe-cron&format=markdown#eventing-cron-job) or set your job to react to events like [file uploads](https://cloud.ibm.com/docs/codeengine?topic=codeengine-eventing-cosevent-producer&format=markdown#obstorage_ev_job).

* You can [update your job](https://cloud.ibm.com/docs/codeengine?topic=codeengine-update-job&format=markdown) and its referenced code in *any* of the following ways, independent of how you created or previously updated your job.

    - If you have a container image, per the [Open Container Initiative (OCI) standard](https://opencontainers.org/){: external}, then you need to provide only a reference to the image, which points to the location of your container registry when you create (or update) your job. You can create (or update) your job from images in a [public registry](https://cloud.ibm.com/docs/codeengine?topic=codeengine-create-job&format=markdown) or [private registry](https://cloud.ibm.com/docs/codeengine?topic=codeengine-create-job-private&format=markdown) and then access the referenced image from your job run.

        If you created your job by using the **`job create`** command and you specified the `--build-source` option to build the container image from local or repository source, and you want to change your job to point to a different container image, you must first remove the association of the build from your job. For example, run `ibmcloud ce job update -n JOB_NAME --build-clear`. After you remove the association of the build from your job, you can update the job to reference a different image. 
        {: important}


    - If you are starting with source code that resides in a Git repository, you can choose to let Code Engine take care of building the image from your source and creating (or updating) the job with a **single** operation. In this scenario, Code Engine uploads your image to IBM Cloud&reg; Container Registry. To learn more, see [Creating a job from repository source code](https://cloud.ibm.com/docs/codeengine?topic=codeengine-run-job-source-code&format=markdown). If you want more control over the build of your image, then you can choose to [build the image](https://cloud.ibm.com/docs/codeengine?topic=codeengine-plan-build&format=markdown) with Code Engine before you create (or update) your job and run the job.  

    - If you are starting with source code that resides on a local workstation, you can choose to let Code Engine take care of building the image from your source and creating the job with a **single** CLI command. In this scenario, Code Engine uploads your image to IBM Cloud&reg; Container Registry. To learn more, see [Creating your job from local source code with the CLI](https://cloud.ibm.com/docs/codeengine?topic=codeengine-job-local-source-code&format=markdown). If you want more control over the build of your image, then you can choose to [build the image](https://cloud.ibm.com/docs/codeengine?topic=codeengine-plan-build&format=markdown) with Code Engine before you create (or update) your job and run the job.

    For example, you might choose to let Code Engine handle the build of your local source while you evolve the development of your source for the job. Then, after the image is matured, you can update the job to reference the specific image that you want. You can repeat this process as needed.

    When you run your updated job, the latest version of your referenced container image is used for the job run, unless a tag is specified for the image. If a tag is specified for the image, then the tagged image is used for the job run. 





Looking for more code examples? Check out the [Samples for IBM Cloud Code Engine GitHub repo](https://github.com/IBM/CodeEngine){: external}.
{: tip}