Repository navigation
fix: authenticate private base images before remote build - #60
Merged
Merged
Conversation
A remote build with `--base ghcr.io/<org>/<private>` failed at the
`FROM` step:
failed to fetch anonymous token: ... 401 Unauthorized
> [internal] load metadata for ghcr.io/swarbricklab/gpu-base:...
The remote builder only ran `docker login` *after* the build (and only
on the push path), so the base image was pulled anonymously during
`docker build` and a private GHCR base 401'd. The builder VM's
boot-time `docker login` is the only thing that could authenticate the
pull, and it races with absconda's fixed 30s start wait — so the pull
is effectively unauthenticated.
Authenticate the base image's registry *before* the build when it is on
GHCR (the registry the configured credentials serve), reusing the same
Secret Manager credentials. The push-target login is folded into the
same pre-build step and de-duplicated, since base and push are usually
the same registry. Credentials are logged out at the end as before.
Images on other/public registries (e.g. a public nvidia/cuda base, or
registry-less refs like python:3.11-slim) are left untouched, so builds
that need no auth are unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A remote build using the new
--baseflag with a private GHCR base image fails at theFROMstep:Reproduced with:
Root cause
The remote builder ran
docker loginonly afterdocker build, and only on the push path (remote.py). The base image is pulled duringdocker build(theFROMstep), so a private base was pulled anonymously and the registry returned 401/403.The builder VM's boot-time
docker login(in its startup script) is the only thing that could have authenticated the pull, but it races with absconda's fixedsleep(30)start wait — the observed run started the build ~32s after boot, before the startup script finished logging in. So the pull was effectively unauthenticated.This only surfaced now because
--baseis the first feature to pull a private base image; normal builds use public conda base images.Fix
Authenticate the base image's registry before the build when it's on GHCR (the registry the configured Secret Manager credentials serve), reusing the existing credentials. The push-target login is folded into the same pre-build step and de-duplicated (base and push are usually the same registry). Credentials are logged out at the end as before.
Generated remote command now:
Images on other/public registries (a public
nvidia/cudabase, registry-less refs likepython:3.11-slim) are left untouched via_ghcr_registry(), so builds that need no auth are unaffected. This makes the fix independent of the VM's boot-state race entirely.Changes
remote.py: threadbase_imagethroughbuild_remote_image→execute_build→_run_build; authenticate GHCR before build; add_ghcr_registry()/_docker_login_command()helpers; broaden the auth-failure hint to mentionread:packages(pull) as well aswrite:packages(push).cli.py: passbase_overrideinto the remote build and record it in the manifest.tests/test_remote.py: assert login precedes build for a private base; unit-test_ghcr_registry()matching.Testing
pytest: 111 passed, 2 skipped (Docker-CLI smoke tests, no Docker on host).ruff check+ruff format --checkclean.docker login ghcr.iobeforedocker build.gcp-builder(requires deploying this build to NCI).Follow-up (not in this PR)
The
sleep(30)start wait instart_remote_builderis still a latent race for SSH/Docker readiness; polling/var/lib/absconda/readywould be more robust. This fix makes base-image auth independent of it, so it's no longer on the critical path.🤖 Generated with Claude Code