Repository navigation
Conversation
GitHub-hosted runners pulled the job containers anonymously and hit Docker
Hub's unauthenticated pull rate limit ("toomanyrequests"), failing nine
jobs of a master run in "Initialize containers". The container jobs now
pass the meshlib account's DOCKERHUB_TOKEN as container credentials; the
reusable workflows that run them get `secrets: inherit`. Without the
secret (fork PRs) the runner skips the login and pulls anonymously as before.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
actions-ecosystem/action-get-latest-tag is a Docker action: GitHub builds its image FROM alpine:latest at job start even when the step is skipped, and that anonymous pull failed pip-build's setup job with 429 Too Many Requests. The step now runs the action's own commands (git fetch --tags, unshallow, git describe --abbrev=0 --tags, v0.0.0 fallback) directly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The three workflows that used actions-ecosystem/action-get-latest-tag now call the local composite .github/actions/get-latest-tag instead of repeating the shell step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The wheel tests (pip-build), test-distribution's Linux jobs, release-tests and pot-auto-update pull public ubuntu/fedora/rockylinux images, which count against the same anonymous pull limit. They now pass the same meshlib credentials; test-distribution takes DOCKERHUB_TOKEN as an optional secret and release-tests gets `secrets: inherit`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The job containers were pulled from Docker Hub anonymously. On shared GitHub-hosted runner IPs that hits the unauthenticated pull rate limit. In this master run, nine jobs failed in "Initialize containers", and two more failed because they wait for
generate-c-bindings:Every job container now logs in with the
meshlibaccount and the existingDOCKERHUB_TOKENsecret, the oneconfig.ymlandprepare-images.ymlalready use:Affected jobs:
build-test-ubuntu,build-test-linux-vcpkg,build-test-emscripten(3 jobs),build-test-emscripten-c-bindingsgenerate-c-bindingspip-buildupdate-docs-manualThe reusable workflows that didn't receive secrets now get
secrets: inheritfrom their callers:build-test-distribute.yml:generate-c-bindings,build-test-emscripten,build-test-emscripten-c-bindingsandpip-buildpip-build.yml:generate-c-bindingsandbuild-test-emscriptendistro-release.ymlandupdate-docs-manual.yml:generate-c-bindingsWhen the secret is empty, as for fork PRs and Dependabot, the runner skips the login and pulls anonymously as before.
actions-ecosystem/action-get-latest-tagis a Docker action. GitHub builds its imageFROM alpine:latestat job start even when the step is skipped, and that anonymous pull failedpip-build'ssetupjob with429 Too Many Requests(job). Inpip-build.yml,release-tests.ymlandsign-upload-nuget.ymlit is replaced by a new composite action,.github/actions/get-latest-tag. It runs the original action's commands directly:git fetch --tags, unshallow,git describe --abbrev=0 --tags, and av0.0.0fallback. It has the sametagoutput.The containers that pull public images now log in the same way, because those pulls count against the same anonymous limit:
pip-buildtest-distribution, which now takesDOCKERHUB_TOKENas an optional secret frombuild-test-distributerelease-tests, called frompip-buildwithsecrets: inheritpot-auto-update🤖 Generated with Claude Code