Publish the Electric image to electricsql/electric-temp and stop using artifacts for digests - #4825
Merged
Merged
Conversation
The electricsql/* and electricax/* repos on Docker Hub are stuck in a half-deleted state after the account that owned the CI credentials was deleted: the repo records 404, pulls are refused, and the names can't be recreated. Docker support says their engineering team has to fix it. Until then, publish the sync-service, agents-server and durable-streams-server-rust images to ghcr.io/electric-sql/* using the built-in GITHUB_TOKEN. The Docker Hub repo names are left commented out so switching back is a small edit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
KyleAMathews
requested review from
alco,
balegas,
icehaunter,
kevin-dp,
magnetised,
msfstef,
paulharter,
robacourt,
samwillis and
thruflo
as code owners
October 3, 2026 04:38
This reverts commit f2b68a4.
The per-platform digests were handed to the manifest job as Actions artifacts. When the org's artifact storage quota is full, the upload fails and no image gets published, whatever the registry. The digests are a few bytes each, so pass them as matrix job outputs instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Docker Hub's electricsql/electric and electricsql/electric-canary repos are broken until Docker repairs them. Publish to electricsql/electric-temp in the meantime and keep the original repo names as comments. Canary builds push only electric-temp:canary so they never overwrite :latest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
balegas
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI cannot publish the Electric sync service image to
electricsql/electricon Docker Hub now. This PR publishes the image to a temporary Docker Hub repository,electricsql/electric-temp, until Docker repairs the original repositories. It also removes a dependency on Actions artifact storage that blocked all image publishing.Why publishing stopped
Two separate problems stopped image publishing.
Broken Docker Hub repositories. The old CI credentials belonged to a Docker Hub account that someone removed. After the removal, the
electricsql/*andelectricax/*repositories stay in a broken state:GET /v2/repositories/electricsql/electric/returns 404, also with org credentials.electricsql/electric:latest, also for anonymous users.electricsql/electric.Docker support told us that their engineering team must repair the repositories. They did not give a date.
Full artifact storage. The shared workflow
docker_multiarch_image.ymlbuilds each platform in a separate job. Each job uploaded its image digest as an Actions artifact for the manifest job. The org artifact storage quota is full, so the upload failed withArtifact storage quota has been hit. This failure occurs for all registries.What changes
Digests go through job outputs. Each platform job now writes its digest to a job output named
digest_<platform_id>. Each matrix leg sets a different output name, so the legs do not overwrite each other. The manifest job writes the outputs to/tmp/digests, and the manifest script stays the same. If the number of digests is not equal to the number of platforms, the manifest job stops with an error. A newplatform_idneeds a new output inbuild_and_push_image. This PR also removes the unusedartifact_prefixinput.The sync service image goes to
electricsql/electric-temp.electricsql/electric:latest,:<version>electricsql/electric-temp:latest,:<version>main)electricsql/electric:canary,electricsql/electric-canary:latest,:<sha>electricsql/electric-temp:canaryCanary builds push only
:canary. Thus a canary build cannot overwrite the release:latesttag in the shared temporary repository.The agents-server and Durable Streams Rust server workflows do not change. Their
electricaxrepositories are also broken, and the current token covers only theelectricsqlorganization.How to go back to
electricsql/electricThe original repository names stay in
sync_service_dockerhub_image.ymlas comments with the prefix# Docker Hub:. When Docker repairs the repositories, uncomment those lines and remove theelectric-templines. The job-output change stays.Earlier commits in this branch
The first commit sent the images to the GitHub Container Registry (GHCR). A later commit reverts it, because GHCR also needs org storage and the free storage is too small. The net diff has no GHCR changes.
Known limits
electricsql/electric. This PR does not change them.DOCKERHUB_TOKENsecret now holds anelectricsqlorganization access token with push scope onelectricsql/*.Verification
@core/sync-service@1.8.1from this branch. All jobs passed.electricsql/electric-temp:latestand:1.8.1, withamd64andarm64.🤖 Generated with Claude Code