Skip to content

ci: authenticate cosign's ECR reads - #378

Merged
robinnsc merged 1 commit into
mainfrom
ci/ecr-authenticated-cosign-reads
Oct 1, 2026
Merged

robinnsc merged 1 commit into
mainfrom
ci/ecr-authenticated-cosign-reads

Conversation

@robinnsc

Copy link
Copy Markdown
Collaborator

What

In the two workflows whose ECR legs run promote-registry (release-dev-image, promote-image), log in to ECR Public with docker login as well as skopeo login, from the same token, and log out of both.

Why

skopeo and cosign use different credential stores — skopeo reads containers/auth.json, cosign (go-containerregistry) reads ~/.docker/config.json. So every skopeo copy in the ECR leg was authenticated, but the cosign verify inside promote-registry went out anonymously, sharing ECR Public's per-source-IP anonymous quota with every other GitHub-hosted runner. Result today: TOOMANYREQUESTS: Data limit exceeded on the v0.1.13 dev propagation, twice, 90 minutes apart (run 36743883930) — plus the same quota hitting the MongoDB base-image pull this morning. The signature-first ordering held: ECR has the signature and nothing else, latest untouched, so the fix is followed by a plain re-dispatch.

Authenticated pulls use the account's own (far larger) quota. copy-artifact is unaffected — it is skopeo-only.

Testing done

  • yaml.safe_load on both workflows.
  • Diagnosis verified against live state: ECR dev has the .sig tag but no 0.1.13; the failing call in the log is the cosign GET.
  • Not executable pre-merge; the v0.1.13 dev re-dispatch after merge is the live verification.

Checklist

  • Tests / fmt / clippy — not applicable, CI only
  • Documentation — inline comment explains the two-store issue
  • Breaking changes noted below

ADR / RFC: n/a — CI tooling only.

Breaking changes

None.


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache License 2.0 and I agree to the Developer Certificate of Origin (DCO). See CONTRIBUTING.md for details.

…gin)

skopeo and cosign use different credential stores (containers/auth.json
vs ~/.docker/config.json), so in every ECR leg that runs the
promote-registry action the skopeo copies were authenticated while the
cosign verify read went out anonymously — sharing ECR Public's per-IP
anonymous quota with every other GitHub-hosted runner. Three
'TOOMANYREQUESTS: Data limit exceeded' failures on 2026-09-30 (two on
the v0.1.13 dev propagation). Log in to both stores from one token.
@robinnsc
robinnsc enabled auto-merge October 1, 2026 00:26
@robinnsc
robinnsc added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Oct 1, 2026
@robinnsc
robinnsc added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 9bb44a3 Oct 1, 2026
22 checks passed
@robinnsc
robinnsc deleted the ci/ecr-authenticated-cosign-reads branch October 1, 2026 02:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants