Skip to content

Fix publish workflow failure by removing unauthorized ECR public publish path - #14

Merged
marciogoda merged 2 commits into
mainfrom
copilot/fix-publish-docker-image
Sep 23, 2026
Merged

marciogoda merged 2 commits into
mainfrom
copilot/fix-publish-docker-image

Conversation

Copilot AI commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The Publish docker image Actions job failed during registry auth because the workflow attempted ecr-public:GetAuthorizationToken with a role that does not have that permission. This change removes the failing ECR public path and keeps publish behavior aligned with Docker Hub publishing.

  • Root cause

    • publish.yml included AWS credential setup + ECR public login, then attempted to publish an additional public.ecr.aws/... tag.
    • The assumed deploy role is not authorized for ecr-public:GetAuthorizationToken, causing the job to fail before image push.
  • Workflow changes

    • Removed AWS auth step (aws-actions/configure-aws-credentials@v4).
    • Removed ECR public login step (aws-actions/amazon-ecr-login@v2).
    • Removed ECR public tag from docker/build-push-action tags list.
  • Resulting publish target

    • Publish to Docker Hub now pushes only Docker Hub tags, matching the branch publish workflow’s registry scope.
# .github/workflows/publish.yml (Build and push)
with:
  push: true
  platforms: linux/arm64,linux/amd64
  tags: |
    mergermarket/cdflow2-build-lambda:latest

Co-authored-by: marciogoda <6553007+marciogoda@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix failing GitHub Actions job Publish docker image Fix publish workflow failure by removing unauthorized ECR public publish path Sep 23, 2026
Copilot AI requested a review from marciogoda September 23, 2026 15:33
@marciogoda
marciogoda marked this pull request as ready for review September 23, 2026 15:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The unauthorized ECR path is removed and Docker Hub publishing is preserved.

Review effort: Lite
Findings: None

What changed in this PR

Removes unauthorized AWS ECR Public authentication and publishing while retaining Docker Hub multi-platform publishing.

Changes:

  • Removed AWS credentials and ECR Public login.
  • Removed the ECR Public image tag.
  • Preserved Docker Hub publishing.
File Description
.github/​workflows/​publish.yml Restricts publishing to Docker Hub.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@marciogoda
marciogoda merged commit f16c0d7 into main Sep 23, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants