ci: authenticate cosign's ECR reads - #378
Merged
Merged
Conversation
…gin) skopeo and cosign use different credential stores (containers/auth.json vs ~/.docker/config.json), so in every ECR leg that runs the promote-registry action the skopeo copies were authenticated while the cosign verify read went out anonymously — sharing ECR Public's per-IP anonymous quota with every other GitHub-hosted runner. Three 'TOOMANYREQUESTS: Data limit exceeded' failures on 2026-09-30 (two on the v0.1.13 dev propagation). Log in to both stores from one token.
robinnsc
requested review from
LeeroyHannigan,
amrith,
c33howard,
jcshepherd,
pdf-amzn and
yesyayen
as code owners
September 30, 2026 23:46
jcshepherd
approved these changes
Sep 30, 2026
robinnsc
enabled auto-merge
October 1, 2026 00:26
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
In the two workflows whose ECR legs run
promote-registry(release-dev-image,promote-image), log in to ECR Public withdocker loginas well asskopeo login, from the same token, and log out of both.Why
skopeo and cosign use different credential stores — skopeo reads
containers/auth.json, cosign (go-containerregistry) reads~/.docker/config.json. So every skopeo copy in the ECR leg was authenticated, but thecosign verifyinsidepromote-registrywent out anonymously, sharing ECR Public's per-source-IP anonymous quota with every other GitHub-hosted runner. Result today:TOOMANYREQUESTS: Data limit exceededon the v0.1.13 dev propagation, twice, 90 minutes apart (run 36743883930) — plus the same quota hitting the MongoDB base-image pull this morning. The signature-first ordering held: ECR has the signature and nothing else,latestuntouched, so the fix is followed by a plain re-dispatch.Authenticated pulls use the account's own (far larger) quota.
copy-artifactis unaffected — it is skopeo-only.Testing done
yaml.safe_loadon both workflows..sigtag but no0.1.13; the failing call in the log is the cosign GET.Checklist
ADR / RFC: n/a — CI tooling only.
Breaking changes
None.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache License 2.0 and I agree to the Developer Certificate of Origin (DCO). See CONTRIBUTING.md for details.