From 23c0277f4d54fe4f3e2101e5db2720214c6f89b5 Mon Sep 17 00:00:00 2001 From: Lucas Vieira Date: Tue, 29 Sep 2026 08:17:03 -0300 Subject: [PATCH] ci(e2e): pull the SG enforcement base image from mirror.gcr.io with retries The EC2 SG enforcement job pulled alpine:3 straight from Docker Hub with no retry; an intermittent auth.docker.io token error failed the whole job before any test ran. Pull the same official image from Google's Docker Hub mirror (as the container-test warm-up already does), tag it as alpine:3, fall back to Docker Hub, and retry. --- .github/workflows/e2e.yml | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 799e9e316..10a717aff 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -361,8 +361,23 @@ jobs: fi echo "bridge-nf-call-iptables=$got (bridge netfilter active)" + # Docker Hub's anonymous pull (and its auth.docker.io token endpoint) + # intermittently fails on shared runner IPs, failing the job before any + # test runs. Pull the same official image from Google's Docker Hub + # mirror and tag it under the name the test uses, falling back to + # Docker Hub, with retries. - name: Pre-pull the instance base image - run: docker pull alpine:3 + run: | + for attempt in 1 2 3; do + if docker pull -q mirror.gcr.io/library/alpine:3 \ + && docker tag mirror.gcr.io/library/alpine:3 alpine:3; then + exit 0 + fi + if docker pull -q alpine:3; then exit 0; fi + sleep $((attempt * 10)) + done + echo "::error::could not pull alpine:3 from mirror.gcr.io or Docker Hub" + exit 1 - name: Build fakecloud + the enforcement test run: |