ci(eng-prod): mirror the sd shard redis images to ghcr [CLK-1591713] - #7
Merged
Merged
Conversation
|
| Commit | Scanned at | New | Resolved | Net |
|---|---|---|---|---|
36d003a < |
2026-09-30 19:17 UTC | 0 | 0 | 0 |
Last scanned: 36d003a · 2026-09-30 19:17 UTC
|
| Rule | Resource | File |
|---|---|---|
Secrets passed via build-args or envs or copied secret files |
— | docker/ci-scaler/Dockerfile |
Secrets passed via build-args or envs or copied secret files |
— | docker/ci-runner/Dockerfile |
🔶 High · 3 findings
| Rule | Resource | File |
|---|---|---|
| Image user should not be 'root' | — | docker/ci-runner/Dockerfile |
| Image user should not be 'root' | — | docker/ci-scaler/Dockerfile |
| Image user should not be 'root' | — | docker/ci-storage/Dockerfile |
🟡 Medium · 2 findings
| Rule | Resource | File |
|---|---|---|
| 'RUN cd ...' to change directory | — | docker/ci-runner/Dockerfile |
| Port 22 exposed | — | docker/ci-storage/Dockerfile |
🟢 Low · 3 findings
| Rule | Resource | File |
|---|---|---|
| No HEALTHCHECK defined | — | docker/ci-storage/Dockerfile |
| No HEALTHCHECK defined | — | docker/ci-runner/Dockerfile |
| No HEALTHCHECK defined | — | docker/ci-scaler/Dockerfile |
View full analysis in Upwind Console →
Scan completed in 2s
Scan history (1 scan)
| Commit | Scanned at | New | Resolved | Net |
|---|---|---|---|---|
36d003a < |
2026-09-30 19:17 UTC | +10 | 0 | +10 |
Last scanned: 36d003a · 2026-09-30 19:17 UTC
avadhanij
reviewed
Sep 30, 2026
avadhanij
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since https://github.com/time-loop/sd/pull/43863 made every sd test shard start its own Redis, about 14% of shards can't pull the Redis images and fall back to the shared host Redis. In the first day after the merge, 461 of ~3,300 shards fell back, across 135 of 416 runs. One cause is Docker Hub's anonymous pull limit,
toomanyrequests: You have reached your unauthenticated pull rate limit: the whole runner fleet pulls anonymously through one NAT IP. We have no Docker Hub credential, so logging in isn't an option.This PR copies the three images to GHCR once, so runners pull from there instead. We do it by reusing the pattern this repo already uses for
ci-runner,ci-storageandci-scaler:GITHUB_TOKEN(packages: write), no PATmain; on PRs, check onlyNo new secret, no AWS change, and no new way of working with images.
What it does
docker/mirror-images.txtlists each image as<path>:<tag>@<digest>:bitnamilegacy/redis-cluster:6.2.16,bitnamilegacy/redis:6.2.16,library/alpine:3.21..github/workflows/mirror-images.ymlrunsskopeo copy --all --preserve-digestsfrom the pinned digest toghcr.io/time-loop/mirror/<path>:<tag>, then confirms the mirror has the same digest. It runs when either file changes onmain, and on demand. On PRs it only checks that each pinned digest still exists, and warns if a tag has moved upstream.PUBLISH.mddocuments the mirror and lists the three new packages for the one-time switch to public.Rollout
docker logout ghcr.io && docker pull ghcr.io/time-loop/mirror/bitnamilegacy/redis:6.2.16.SHARD_REDIS_IMAGE_PREFIX: ghcr.io/time-loop/mirrorin a separate PR. It must come after step 2: pointing sd at private packages would make every shard fall back.Test plan
Mirror Imagesrun checks all three pinned digests without pushing.mainlogsmirrored … @sha256:…for each image, and the packages appear under the org.