From cdc2d0bcbabffaf847c2af8dd32111ace1ddf8e6 Mon Sep 17 00:00:00 2001 From: Scott Robinson Date: Wed, 30 Sep 2026 23:46:07 +0000 Subject: [PATCH] ci: authenticate cosign's ECR reads (docker login alongside skopeo login) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit skopeo and cosign use different credential stores (containers/auth.json vs ~/.docker/config.json), so in every ECR leg that runs the promote-registry action the skopeo copies were authenticated while the cosign verify read went out anonymously — sharing ECR Public's per-IP anonymous quota with every other GitHub-hosted runner. Three 'TOOMANYREQUESTS: Data limit exceeded' failures on 2026-09-30 (two on the v0.1.13 dev propagation). Log in to both stores from one token. --- .github/workflows/promote-image.yml | 13 ++++++++++--- .github/workflows/release-dev-image.yml | 13 ++++++++++--- 2 files changed, 20 insertions(+), 6 deletions(-) diff --git a/.github/workflows/promote-image.yml b/.github/workflows/promote-image.yml index c353d2575..d7ba2724b 100644 --- a/.github/workflows/promote-image.yml +++ b/.github/workflows/promote-image.yml @@ -323,8 +323,15 @@ jobs: - name: Log in to ECR Public run: | set -euo pipefail - aws ecr-public get-login-password --region us-east-1 \ - | skopeo login public.ecr.aws -u AWS --password-stdin + # Both credential stores: skopeo reads containers/auth.json, while + # cosign (go-containerregistry) reads ~/.docker/config.json. Without + # the docker login, cosign's signature read goes out ANONYMOUSLY and + # shares ECR Public's per-IP anonymous quota with every other GitHub + # runner — three "Data limit exceeded" failures on 2026-09-30. + TOKEN=$(aws ecr-public get-login-password --region us-east-1) + skopeo login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + docker login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + unset TOKEN - name: Promote ECR Public (shared per-registry rules) uses: ./.github/actions/promote-registry @@ -339,7 +346,7 @@ jobs: if: always() run: | skopeo logout ghcr.io || true - skopeo logout public.ecr.aws || true + skopeo logout public.ecr.aws || true; docker logout public.ecr.aws >/dev/null 2>&1 || true - name: Summarise for the release checklist if: always() diff --git a/.github/workflows/release-dev-image.yml b/.github/workflows/release-dev-image.yml index 104faf176..6b6364fc6 100644 --- a/.github/workflows/release-dev-image.yml +++ b/.github/workflows/release-dev-image.yml @@ -479,8 +479,15 @@ jobs: - name: Log in to ECR Public run: | set -euo pipefail - aws ecr-public get-login-password --region us-east-1 \ - | skopeo login public.ecr.aws -u AWS --password-stdin + # Both credential stores: skopeo reads containers/auth.json, while + # cosign (go-containerregistry) reads ~/.docker/config.json. Without + # the docker login, cosign's signature read goes out ANONYMOUSLY and + # shares ECR Public's per-IP anonymous quota with every other GitHub + # runner — three "Data limit exceeded" failures on 2026-09-30. + TOKEN=$(aws ecr-public get-login-password --region us-east-1) + skopeo login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + docker login public.ecr.aws -u AWS --password-stdin <<< "$TOKEN" + unset TOKEN - name: Propagate to ECR Public uses: ./.github/actions/promote-registry @@ -495,7 +502,7 @@ jobs: if: always() run: | skopeo logout ghcr.io || true - skopeo logout public.ecr.aws || true + skopeo logout public.ecr.aws || true; docker logout public.ecr.aws >/dev/null 2>&1 || true - name: Summarise if: always()