Repository navigation
ci: pull Docker Hub images through mirror.gcr.io - #930
Open
solace-aross wants to merge 2 commits into
Open
solace-aross wants to merge 2 commits into
solace-aross wants to merge 2 commits into
Conversation
Docker Hub rate limits anonymous pulls per address, and GitHub runners share addresses, so CI fails with 429s on postgres, silo and alpine. A local action adds mirror.gcr.io to the Docker daemon's registry mirrors, and the package job's BuildKit builder gets the same mirror. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Andrea Ross <168456375+solace-aross@users.noreply.github.com>
solace-aross
requested review from
sgamelin,
shortishly and
solace-wkourlas
as code owners
October 9, 2026 22:18
reubenjds
previously approved these changes
Oct 10, 2026
reubenjds
left a comment
Collaborator
There was a problem hiding this comment.
LGTM. Two nits inline, neither blocking.
The display line failed the step silently under pipefail when no mirror was set, so the real check never ran. Make the display line non-fatal and have the check print an error. Read the mirror list into a variable before grepping, so grep -q closing the pipe early cannot fail docker info with SIGPIPE. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Andrea Ross <andrea.ross@solace.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI is failing with Docker Hub 429s (
toomanyrequests) when it pulls postgres,pgsty/siloand alpine. Docker Hub allows 100 anonymous pulls per 6 hours per address, GitHub runners share addresses, and one queue run makes about 70 pulls. This blocks every merge.This is a stopgap until an authenticated Docker Hub account is set up. It adds no secret.
What changes
.github/actions/docker-hub-mirror. It mergeshttps://mirror.gcr.iointo/etc/docker/daemon.json(existing settings kept), restarts Docker, and printsdocker infoso the log shows the mirror. It fails the step if the mirror is not in the daemon's config.test,compat-librdkafka,compat-franz-go,package,smoke,smoke-oldest-client, andtest,compat-librdkafka,compat-franz-gointier-c.yml.packagealso setsbuildkitd-config-inlineondocker/setup-buildx-action. BuildKit pulls base images itself and does not use the daemon's mirror, so the alpine pull needs its own setting.Image tags and digest pins are unchanged.
Verified
pgsty/silo(pinned digest); hello-world; apache/kafka 3.7.2, 3.9.2, 4.3.1;moby/buildkit.ubuntu-latestandubuntu-24.04-arm.docker infolisted the mirror, all of those pulls succeeded, and a two-platformbuildx buildof the alpine base fetched its blobs frommirror.gcr.io.Downsides
Not verified
smoke,smoke-oldest-clientandpackagerun only in the merge queue, so they are untested until the first queue run. Theubuntu-24.04-armrestart was exercised only on the throwaway branch.PR #927 edits the same jobs and will need a rebase over this. The change here is one
uses:line per job plus the buildx input.🤖 Generated with Claude Code