Skip to content

Publish the Electric image to electricsql/electric-temp and stop using artifacts for digests - #4825

Merged
KyleAMathews merged 4 commits into
mainfrom
publish-images-to-ghcr
Oct 3, 2026
Merged

KyleAMathews merged 4 commits into
mainfrom
publish-images-to-ghcr

Conversation

@KyleAMathews

@KyleAMathews KyleAMathews commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

CI cannot publish the Electric sync service image to electricsql/electric on Docker Hub now. This PR publishes the image to a temporary Docker Hub repository, electricsql/electric-temp, until Docker repairs the original repositories. It also removes a dependency on Actions artifact storage that blocked all image publishing.

Why publishing stopped

Two separate problems stopped image publishing.

Broken Docker Hub repositories. The old CI credentials belonged to a Docker Hub account that someone removed. After the removal, the electricsql/* and electricax/* repositories stay in a broken state:

  • GET /v2/repositories/electricsql/electric/ returns 404, also with org credentials.
  • The registry refuses pulls of electricsql/electric:latest, also for anonymous users.
  • The tag API still lists 185 tags for electricsql/electric.
  • Docker Hub does not let us create the repositories again, because the names "already exist".

Docker support told us that their engineering team must repair the repositories. They did not give a date.

Full artifact storage. The shared workflow docker_multiarch_image.yml builds each platform in a separate job. Each job uploaded its image digest as an Actions artifact for the manifest job. The org artifact storage quota is full, so the upload failed with Artifact storage quota has been hit. This failure occurs for all registries.

What changes

Digests go through job outputs. Each platform job now writes its digest to a job output named digest_<platform_id>. Each matrix leg sets a different output name, so the legs do not overwrite each other. The manifest job writes the outputs to /tmp/digests, and the manifest script stays the same. If the number of digests is not equal to the number of platforms, the manifest job stops with an error. A new platform_id needs a new output in build_and_push_image. This PR also removes the unused artifact_prefix input.

The sync service image goes to electricsql/electric-temp.

Build Before Now
Release electricsql/electric:latest, :<version> electricsql/electric-temp:latest, :<version>
Canary (push to main) electricsql/electric:canary, electricsql/electric-canary:latest, :<sha> electricsql/electric-temp:canary

Canary builds push only :canary. Thus a canary build cannot overwrite the release :latest tag in the shared temporary repository.

The agents-server and Durable Streams Rust server workflows do not change. Their electricax repositories are also broken, and the current token covers only the electricsql organization.

How to go back to electricsql/electric

The original repository names stay in sync_service_dockerhub_image.yml as comments with the prefix # Docker Hub:. When Docker repairs the repositories, uncomment those lines and remove the electric-temp lines. The job-output change stays.

Earlier commits in this branch

The first commit sent the images to the GitHub Container Registry (GHCR). A later commit reverts it, because GHCR also needs org storage and the free storage is too small. The net diff has no GHCR changes.

Known limits

  • The docs, compose files, and skills still refer to electricsql/electric. This PR does not change them.
  • The DOCKERHUB_TOKEN secret now holds an electricsql organization access token with push scope on electricsql/*.

Verification

  • Run 37134261454 built @core/sync-service@1.8.1 from this branch. All jobs passed.
  • An anonymous registry request returns multi-arch manifests for electricsql/electric-temp:latest and :1.8.1, with amd64 and arm64.
  • A local run of the new digest step with sample data wrote both digest files. With one digest missing, the step stopped with exit code 1.

🤖 Generated with Claude Code

The electricsql/* and electricax/* repos on Docker Hub are stuck in a
half-deleted state after the account that owned the CI credentials was
deleted: the repo records 404, pulls are refused, and the names can't be
recreated. Docker support says their engineering team has to fix it.

Until then, publish the sync-service, agents-server and
durable-streams-server-rust images to ghcr.io/electric-sql/* using the
built-in GITHUB_TOKEN. The Docker Hub repo names are left commented out
so switching back is a small edit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
KyleAMathews and others added 3 commits October 3, 2026 09:41
The per-platform digests were handed to the manifest job as Actions
artifacts. When the org's artifact storage quota is full, the upload
fails and no image gets published, whatever the registry. The digests
are a few bytes each, so pass them as matrix job outputs instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Docker Hub's electricsql/electric and electricsql/electric-canary repos
are broken until Docker repairs them. Publish to electricsql/electric-temp
in the meantime and keep the original repo names as comments. Canary
builds push only electric-temp:canary so they never overwrite :latest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@KyleAMathews KyleAMathews changed the title Publish Docker images to GHCR while Docker Hub repos are broken Publish the Electric image to electricsql/electric-temp and stop using artifacts for digests Oct 3, 2026
@KyleAMathews
KyleAMathews merged commit 2362939 into main Oct 3, 2026
18 of 22 checks passed
@KyleAMathews
KyleAMathews deleted the publish-images-to-ghcr branch October 3, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants