fix(ecs,lambda): pull fakecloud's ECR registry over plain HTTP under podman - #2595
Merged
Merged
Conversation
…podman fakecloud rewrites an AWS ECR image URI to its own OCI registry at 127.0.0.1:<port>, which serves plain HTTP. Docker treats a loopback registry as insecure on its own, but podman insists on TLS for every registry, so ECS tasks and image-based Lambda functions failed to pull with "server gave HTTP response to HTTPS client" (#2585). - container_image::pull_image takes a RegistryTransport; a pull of a rewritten ECR reference is PlainHttp, and podman then gets --tls-verify=false. Upstream registries keep TLS; docker is unchanged (its pull has no such flag). - ECS task launch and the Lambda docker backend (start + prepull) pass the transport from whether the URI was rewritten. - New ecs_podman_ecr e2e pushes to fakecloud ECR and runs an ECS task under podman; routed to the podman E2E partition. - ECS docs note the podman behavior. Closes #2585
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #2585.
When an ECS task or Lambda function uses an AWS ECR image URI, fakecloud rewrites it to its own OCI registry at
127.0.0.1:<port>(or the sibling host), and that registry serves plain HTTP. Docker treats a loopback registry as insecure automatically. Podman doesn't: it requires TLS for every registry. So under the podman backend the pull failed withserver gave HTTP response to HTTPS client.container_image::pull_imagenow takes aRegistryTransport. A pull of a rewritten ECR reference isPlainHttp, and podman then gets--tls-verify=false. Upstream registries keep TLS verification. Docker's arguments don't change, sincedocker pullhas no such flag.DOCKER_CONFIG, which I verified: an empty config getsauthentication requiredand a filled one pulls. So the existing isolated registry auth keeps working, and TLS was the only thing missing.Surfaces checked: there's no new API, introspection endpoint, flag or count, so the SDKs, README, parity, counts and repo description don't change. Only the ECS service doc needed an update.
Test plan
fakecloud-corecontainer_image): podman plus plain HTTP gets--tls-verify=false, podman plus HTTPS doesn't, docker plus plain HTTP doesn't, and the transport is derived from the rewrite.ecs_podman_ecr: pushes an image to fakecloud ECR, runs an ECS task that references the AWS URI underFAKECLOUD_CONTAINER_CLI=podman, and checks the task's logs and exit code 0. It runs in the podman E2E partition, which already installs podman, ande2e_nextest_partitions checkpasses.image pull failed ... HTTPS client). With the patched binary, the task reaches RUNNING and the container prints its output.-D warnings) and fmt are clean.Summary by cubic
Fixes ECS tasks and image-based Lambda functions failing to pull images from fakecloud's ECR registry under the podman backend with
server gave HTTP response to HTTPS client(closes #2585).RegistryTransporttocontainer_image::pull_image; pulls of rewritten ECR references use plain HTTP, so podman gets--tls-verify=false, while upstream registries keep TLS verification.ecs_podman_ecre2e test that pushes to fakecloud ECR and runs an ECS task under podman, routed to the podman E2E partition.Written for commit 7940137. Summary will update on new commits.