Repository navigation
Kept CI's Docker Hub pulls under the anonymous rate limit - #385
Merged
Merged
Conversation
Test jobs failed intermittently with Docker Hub's "toomanyrequests: You have reached your unauthenticated pull rate limit" while building the manager image from its Docker Hub bases (run 37993666771). No workflow logged in to Docker Hub. Every Linux job that pulls now has the daemon pull through mirror.gcr.io and, when the secrets reach it, logs in with a read-only token (DOCKERHUB_USERNAME, DOCKERHUB_TOKEN). The mirror is for every job, not only those without the token: the manager runs Compose in its own container with the daemon's socket and none of the host's credentials, so its pulls of Ghost, MySQL and Caddy are anonymous whatever the host logged in with. Pull requests from forks and Dependabot get no secrets and run with the mirror alone, rather than failing on a missing login. - .github/actions/docker-hub/action.yml: the mirror and the login, shared by every job, skipping the login when there is no token. - .github/workflows/test.yml: used by each Linux job that runs Docker. - .github/workflows/image.yml: used before the build; the buildx builder runs in its own container, which ignores the daemon's mirror, so it is given the same one. Takes the secrets when called. - .github/workflows/launcher.yml: used by the job that installs with the served launcher. Takes the secrets when called. - .github/workflows/release.yml: passes the secrets to both.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test jobs failed intermittently with Docker Hub's anonymous pull rate limit while building the manager image from its Docker Hub bases (run 37993666771:
toomanyrequests: You have reached your unauthenticated pull rate limit). No workflow logged in to Docker Hub.Every Linux job that pulls now uses a shared composite action,
.github/actions/docker-hub, which:mirror.gcr.io, falling back to Docker Hub for anything the mirror lacks;docker/login-action(pinned by SHA, v4.6.0) using a read-only token, whenDOCKERHUB_USERNAMEandDOCKERHUB_TOKENreach the job, and otherwise prints a notice and continues, so fork and Dependabot PRs pass.The mirror applies to every job, not only those without the token. The launcher gives the manager container the daemon's socket but none of the host's credentials, so Compose's pulls of Ghost, MySQL and Caddy are anonymous whatever the host logged in with.
test.yml: the eight Linux jobs that run Docker.image.yml: before the build. The buildxdocker-containerbuilder ignores the daemon's mirror, so it gets the same mirror through a buildkitd config. Accepts the secrets onworkflow_call.launcher.yml: theverifyjob. Accepts the secrets onworkflow_call.release.yml: passes the secrets to both.mirror.gcr.ioserves all three pinned base digests (alpine, node, docker).Needs an admin
The secrets don't exist yet. Until they do, CI runs on the mirror alone.
DOCKERHUB_USERNAMEandDOCKERHUB_TOKENas repository secrets, or as organization secrets shared with this repository.🤖 Generated with Claude Code