Skip to content

CI: pull the Docker images logged in to Docker Hub - #7098

Open
Fedr wants to merge 4 commits into
masterfrom
ci-dockerhub-credentials
Open

Fedr wants to merge 4 commits into
masterfrom
ci-dockerhub-credentials

Conversation

@Fedr

@Fedr Fedr commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

The job containers were pulled from Docker Hub anonymously. On shared GitHub-hosted runner IPs that hits the unauthenticated pull rate limit. In this master run, nine jobs failed in "Initialize containers", and two more failed because they wait for generate-c-bindings:

docker pull meshlib/meshlib-ubuntu22-arm64:latest
Error response from daemon: toomanyrequests: You have reached your unauthenticated pull rate limit.

Every job container now logs in with the meshlib account and the existing DOCKERHUB_TOKEN secret, the one config.yml and prepare-images.yml already use:

container:
  image: meshlib/...
  credentials:
    username: meshlib
    password: ${{ secrets.DOCKERHUB_TOKEN }}

Affected jobs:

  • build-test-ubuntu, build-test-linux-vcpkg, build-test-emscripten (3 jobs), build-test-emscripten-c-bindings
  • generate-c-bindings
  • the manylinux job in pip-build
  • update-docs-manual

The reusable workflows that didn't receive secrets now get secrets: inherit from their callers:

  • build-test-distribute.yml: generate-c-bindings, build-test-emscripten, build-test-emscripten-c-bindings and pip-build
  • pip-build.yml: generate-c-bindings and build-test-emscripten
  • distro-release.yml and update-docs-manual.yml: generate-c-bindings

When the secret is empty, as for fork PRs and Dependabot, the runner skips the login and pulls anonymously as before.

actions-ecosystem/action-get-latest-tag is a Docker action. GitHub builds its image FROM alpine:latest at job start even when the step is skipped, and that anonymous pull failed pip-build's setup job with 429 Too Many Requests (job). In pip-build.yml, release-tests.yml and sign-upload-nuget.yml it is replaced by a new composite action, .github/actions/get-latest-tag. It runs the original action's commands directly: git fetch --tags, unshallow, git describe --abbrev=0 --tags, and a v0.0.0 fallback. It has the same tag output.

The containers that pull public images now log in the same way, because those pulls count against the same anonymous limit:

  • the wheel tests in pip-build
  • the two Linux jobs in test-distribution, which now takes DOCKERHUB_TOKEN as an optional secret from build-test-distribute
  • release-tests, called from pip-build with secrets: inherit
  • pot-auto-update

🤖 Generated with Claude Code

GitHub-hosted runners pulled the job containers anonymously and hit Docker
Hub's unauthenticated pull rate limit ("toomanyrequests"), failing nine
jobs of a master run in "Initialize containers". The container jobs now
pass the meshlib account's DOCKERHUB_TOKEN as container credentials; the
reusable workflows that run them get `secrets: inherit`. Without the
secret (fork PRs) the runner skips the login and pulls anonymously as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Fedr Fedr added test-pip-build Build Python wheels (and discard them) disable-build-windows disable-build-macos labels Oct 9, 2026
Fedr and others added 2 commits October 10, 2026 00:04
actions-ecosystem/action-get-latest-tag is a Docker action: GitHub builds
its image FROM alpine:latest at job start even when the step is skipped,
and that anonymous pull failed pip-build's setup job with 429 Too Many
Requests. The step now runs the action's own commands (git fetch --tags,
unshallow, git describe --abbrev=0 --tags, v0.0.0 fallback) directly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The three workflows that used actions-ecosystem/action-get-latest-tag now
call the local composite .github/actions/get-latest-tag instead of
repeating the shell step.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Fedr Fedr added the upload-binaries Upload built installers and packages to the Releases page label Oct 10, 2026
The wheel tests (pip-build), test-distribution's Linux jobs, release-tests
and pot-auto-update pull public ubuntu/fedora/rockylinux images, which
count against the same anonymous pull limit. They now pass the same
meshlib credentials; test-distribution takes DOCKERHUB_TOKEN as an
optional secret and release-tests gets `secrets: inherit`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Fedr Fedr changed the title CI: pull the meshlib/* Docker images logged in to Docker Hub CI: pull the Docker images logged in to Docker Hub Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

disable-build-macos disable-build-windows test-pip-build Build Python wheels (and discard them) upload-binaries Upload built installers and packages to the Releases page

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant