It would be preferable to stop configuring an insecure registry and default to always using the internal registry, but we need to get mirror auth working for this. Supposedly adding the credentials to the global pull secret can work, but this process needs to be figured out and implemented.