Skip to content

Kept CI's Docker Hub pulls under the anonymous rate limit - #385

Merged
acburdine merged 1 commit into
next-dockerfrom
claude/festive-lichterman-df062d
Oct 9, 2026
Merged

acburdine merged 1 commit into
next-dockerfrom
claude/festive-lichterman-df062d

Conversation

@acburdine

Copy link
Copy Markdown
Member

Test jobs failed intermittently with Docker Hub's anonymous pull rate limit while building the manager image from its Docker Hub bases (run 37993666771: toomanyrequests: You have reached your unauthenticated pull rate limit). No workflow logged in to Docker Hub.

Every Linux job that pulls now uses a shared composite action, .github/actions/docker-hub, which:

  • has the daemon pull through mirror.gcr.io, falling back to Docker Hub for anything the mirror lacks;
  • logs in with docker/login-action (pinned by SHA, v4.6.0) using a read-only token, when DOCKERHUB_USERNAME and DOCKERHUB_TOKEN reach the job, and otherwise prints a notice and continues, so fork and Dependabot PRs pass.

The mirror applies to every job, not only those without the token. The launcher gives the manager container the daemon's socket but none of the host's credentials, so Compose's pulls of Ghost, MySQL and Caddy are anonymous whatever the host logged in with.

  • test.yml: the eight Linux jobs that run Docker.
  • image.yml: before the build. The buildx docker-container builder ignores the daemon's mirror, so it gets the same mirror through a buildkitd config. Accepts the secrets on workflow_call.
  • launcher.yml: the verify job. Accepts the secrets on workflow_call.
  • release.yml: passes the secrets to both.

mirror.gcr.io serves all three pinned base digests (alpine, node, docker).

Needs an admin

The secrets don't exist yet. Until they do, CI runs on the mirror alone.

  1. Create a read-only Docker Hub access token ("Public Repo Read-only"), preferably on a shared team account.
  2. Add DOCKERHUB_USERNAME and DOCKERHUB_TOKEN as repository secrets, or as organization secrets shared with this repository.

🤖 Generated with Claude Code

Test jobs failed intermittently with Docker Hub's "toomanyrequests: You
have reached your unauthenticated pull rate limit" while building the
manager image from its Docker Hub bases (run 37993666771). No workflow
logged in to Docker Hub.

Every Linux job that pulls now has the daemon pull through mirror.gcr.io
and, when the secrets reach it, logs in with a read-only token
(DOCKERHUB_USERNAME, DOCKERHUB_TOKEN). The mirror is for every job, not
only those without the token: the manager runs Compose in its own
container with the daemon's socket and none of the host's credentials,
so its pulls of Ghost, MySQL and Caddy are anonymous whatever the host
logged in with. Pull requests from forks and Dependabot get no secrets
and run with the mirror alone, rather than failing on a missing login.

- .github/actions/docker-hub/action.yml: the mirror and the login,
  shared by every job, skipping the login when there is no token.
- .github/workflows/test.yml: used by each Linux job that runs Docker.
- .github/workflows/image.yml: used before the build; the buildx builder
  runs in its own container, which ignores the daemon's mirror, so it
  is given the same one. Takes the secrets when called.
- .github/workflows/launcher.yml: used by the job that installs with the
  served launcher. Takes the secrets when called.
- .github/workflows/release.yml: passes the secrets to both.
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 2a45cbb1-9082-4b7b-9a78-17189687653f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@acburdine
acburdine enabled auto-merge (squash) October 9, 2026 22:15
@acburdine
acburdine merged commit b1e900a into next-docker Oct 9, 2026
14 checks passed
@acburdine
acburdine deleted the claude/festive-lichterman-df062d branch October 9, 2026 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant