Skip to content

ci: pull base images from Amazon ECR Public instead of Docker Hub - #1720

Closed
brendan-kellam wants to merge 3 commits into
mainfrom
brendan/use-ecr-public-images
Closed

brendan-kellam wants to merge 3 commits into
mainfrom
brendan/use-ecr-public-images

Conversation

@brendan-kellam

@brendan-kellam brendan-kellam commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Why

Since ~20:50 UTC on 2026-10-09, Docker Hub pulls from GitHub-hosted runners have been failing. Runners normally pull with a GitHub-provided Docker Hub credential (account=githubactions) that exempts them from rate limits, but auth.docker.io is timing out / returning 504, so pulls either fail outright or fall back to anonymous and hit the toomanyrequests limit. This blocked the production release (run) in the Prisma migration check, and the image build pulls its base images from Docker Hub too. Many other projects are reporting the same thing (e.g. cleat-team/cleat#3290, openzigs/metis#1028).

What

Pull Docker Official Images from Docker's mirror on Amazon ECR Public (public.ecr.aws/docker/library/...). These are the same images, published by Docker, served without Docker Hub's auth service or rate limits.

  • Dockerfile: node:24-alpine3.23 and golang:1.26-alpine base images
  • .github/actions/check-prisma-migrations/action.yml: postgres:16

Verified all three tags exist on ECR Public.

🤖 Generated with Claude Code


Note

Low Risk
Registry-only renames for the same official image tags; no application, auth, or runtime logic changes.

Overview
Switches CI and image builds off Docker Hub by pointing three official image pulls at Amazon ECR Public (public.ecr.aws/docker/library/...), which mirrors Docker Official Images without Docker Hub auth or rate limits.

The Prisma migration check now starts Postgres with public.ecr.aws/docker/library/postgres:16 instead of postgres:16. The root Dockerfile uses the same ECR paths for the node:24-alpine3.23 and golang:1.26-alpine build stages. Image tags and behavior are unchanged; only the registry hostname changes.

Reviewed by Cursor Bugbot for commit b8602c5. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Build and migration-check environments now use PostgreSQL, Node.js, and Go container images hosted on public ECR instead of Docker Hub.
    • The PostgreSQL version and the application’s build and migration-check behavior remain unchanged.

brendan-kellam and others added 2 commits October 9, 2026 17:47
Docker Hub token requests from GitHub-hosted runners are failing
(auth.docker.io timeouts / 504s, falling back to the anonymous 429 limit),
blocking release builds. Switch the Dockerfile base images and the Prisma
migration check's Postgres image to Docker's official mirrors on
public.ecr.aws/docker/library, which use the same images without depending
on Docker Hub.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: edd34f8d-1bf3-4217-aeb2-e6e613b60cdd

📥 Commits

Reviewing files that changed from the base of the PR and between 15bbb94 and b8602c5.


📒 Files selected for processing (2)
  • .github/actions/check-prisma-migrations/action.yml
  • Dockerfile

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.



Walkthrough

The migration-check action and Docker build stages now use public Amazon ECR Docker Library image references. The image tags remain unchanged.

Changes

Container image registry references

Layer / File(s) Summary
Update container image references
.github/actions/check-prisma-migrations/action.yml, Dockerfile
The PostgreSQL, Node.js, and Go image references now use public.ecr.aws/docker/library. Their tags remain unchanged.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to b8602

The registry changes preserve the expected PostgreSQL, Node, and Go images, and all three tags are publicly pullable for the supported build platforms. No blocking impact is indicated, so the PR is mergeable.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: replacing Docker Hub base-image references with Amazon ECR Public references in CI and the Dockerfile.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant