diff --git a/.github/workflows/promote-image.yml b/.github/workflows/promote-image.yml index c353d2575..d7ba2724b 100644 --- a/.github/workflows/promote-image.yml +++ b/.github/workflows/promote-image.yml @@ -323,8 +323,15 @@ jobs: - name: Log in to ECR Public run: | set -euo pipefail - aws ecr-public get-login-password --region us-east-1 \ - | skopeo login public.ecr.aws -u AWS --password-stdin + # Both credential stores: skopeo reads containers/auth.json, while + # cosign (go-containerregistry) reads ~/.docker/config.json. Without + # the docker login, cosign's signature read goes out ANONYMOUSLY and + # shares ECR Public's per-IP anonymous quota with every other GitHub + # runner — three "Data limit exceeded" failures on 2026-09-30. + TOKEN=$(aws ecr-public get-login-password --region us-east-1) + skopeo login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + docker login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + unset TOKEN - name: Promote ECR Public (shared per-registry rules) uses: ./.github/actions/promote-registry @@ -339,7 +346,7 @@ jobs: if: always() run: | skopeo logout ghcr.io || true - skopeo logout public.ecr.aws || true + skopeo logout public.ecr.aws || true; docker logout public.ecr.aws >/dev/null 2>&1 || true - name: Summarise for the release checklist if: always() diff --git a/.github/workflows/release-dev-image.yml b/.github/workflows/release-dev-image.yml index 104faf176..6b6364fc6 100644 --- a/.github/workflows/release-dev-image.yml +++ b/.github/workflows/release-dev-image.yml @@ -479,8 +479,15 @@ jobs: - name: Log in to ECR Public run: | set -euo pipefail - aws ecr-public get-login-password --region us-east-1 \ - | skopeo login public.ecr.aws -u AWS --password-stdin + # Both credential stores: skopeo reads containers/auth.json, while + # cosign (go-containerregistry) reads ~/.docker/config.json. Without + # the docker login, cosign's signature read goes out ANONYMOUSLY and + # shares ECR Public's per-IP anonymous quota with every other GitHub + # runner — three "Data limit exceeded" failures on 2026-09-30. + TOKEN=$(aws ecr-public get-login-password --region us-east-1) + skopeo login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + docker login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + unset TOKEN - name: Propagate to ECR Public uses: ./.github/actions/promote-registry @@ -495,7 +502,7 @@ jobs: if: always() run: | skopeo logout ghcr.io || true - skopeo logout public.ecr.aws || true + skopeo logout public.ecr.aws || true; docker logout public.ecr.aws >/dev/null 2>&1 || true - name: Summarise if: always()