Skip to content

ci: Container Tests builds against Docker Hub anonymously and hits 429 Too Many Requests on shared runners (twice on one PR) #891

Description

@debugmcpdev

container-tests in ci.yml runs docker build -t mcp-debugger:local . with no registry login, so the base-image manifests come from Docker Hub under the anonymous rate limit shared by every GitHub-hosted runner on that egress. Twice on one docs-only PR today (#888, run 37990703352, 2026-10-09):

#7 ERROR: failed to copy: httpReadSeeker: failed open: unexpected status code
   https://registry-1.docker.io/v2/library/node/manifests/sha256:deae974a…: 429 Too Many Requests        (21:01 UTC)
#9 ERROR: ... https://registry-1.docker.io/v2/library/dart/manifests/sha256:8604cbd1…: 429 Too Many Requests   (rerun, 21:12 UTC)

The same job passed on main at e44f1fe four hours earlier, so this is the limit, not the Dockerfile. Pinning by digest does not help: the manifest fetch itself is what gets counted. The PR merged because Container Tests is not a required check, which also means a 429 silently turns Test Summary red on main push runs.

Proposal:

  1. Log in before the build when the secrets are available: a step that sets an output from DOCKER_USERNAME/DOCKER_PASSWORD (already used by release.yml), then docker/login-action guarded by that output. Fork and Dependabot PRs have no secrets and keep building anonymously, so nothing new fails for contributors; authenticated pulls lift the per-IP anonymous limit for everyone else. The release workflow's Docker job already logs in and has not seen this.
  2. Or mirror the two base images (node:26-slim, dart:3.13, both digest-pinned) to GHCR under debugmcp and build from there; more moving parts, no Docker Hub dependency on PRs at all.

Either way a 429 should read as "retry", not as a container failure: the step could retry the build once after a pause when the output contains 429 Too Many Requests.

Activity

  1. debugmcpdev commented on Oct 9, 2026

    @debugmcpdev
    CollaboratorAuthor

    Third time today, now on the main push run for the #888 merge (run 37993031877, 21:23 UTC): node:26-slim manifest, 429 Too Many Requests, so main showed a red Test Summary for a docs-only merge. Reran the failed jobs once; if that passes it confirms the limit is intermittent rather than exhausted for the day.

  2. debugmcpdev commented on Oct 9, 2026

    @debugmcpdev
    CollaboratorAuthor

    Fourth: the rerun at 21:31 UTC failed the same way (node:26-slim manifest, 429). Not retrying further tonight; the anonymous window resets on its own. main at 8b43c38 (docs-only merge) therefore shows a red Test Summary until someone runs gh run rerun 37993031877 --failed later. Two 429s inside 30 minutes on a run that pulls two manifests is the per-IP anonymous limit shared across runners, which is what proposal 1 (login when secrets exist) removes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions