Skip to content

NO-ISSUE: use ghcr.io registry image to avoid Docker Hub rate limits - #1566

Queued
redhat-chai-bot wants to merge 1 commit into
osac-project:mainfrom
redhat-chai-bot:fix/docker-hub-ratelimit
Queued

redhat-chai-bot wants to merge 1 commit into
osac-project:mainfrom
redhat-chai-bot:fix/docker-hub-ratelimit

Conversation

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

Summary

Swap the Docker Hub registry:2 image reference in the osac-aap integration test setup to ghcr.io/distribution/distribution:2 — the same upstream CNCF Distribution image, hosted on GitHub Container Registry.

Problem

CI runners share IP addresses and hit Docker Hub's unauthenticated pull rate limit (100 pulls per 6 hours per IP), causing integration test failures:

docker: Error response from daemon: toomanyrequests: You have reached your unauthenticated pull rate limit.

Fix

Replace the unqualified registry:2 (which resolves to docker.io/library/registry:2) with the equivalent ghcr.io/distribution/distribution:2. This avoids Docker Hub rate limits entirely without requiring any secrets or workflow changes.

This is consistent with the existing mirror pattern in the repo (see .github/workflows/mirror-envoy.yaml).


AI-generated. Review for accuracy.

@ygalblum requested from Slack

@openshift-ci-robot

Copy link
Copy Markdown

@redhat-chai-bot: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

Swap the Docker Hub registry:2 image reference in the osac-aap integration test setup to ghcr.io/distribution/distribution:2 — the same upstream CNCF Distribution image, hosted on GitHub Container Registry.

Problem

CI runners share IP addresses and hit Docker Hub's unauthenticated pull rate limit (100 pulls per 6 hours per IP), causing integration test failures:

docker: Error response from daemon: toomanyrequests: You have reached your unauthenticated pull rate limit.

Fix

Replace the unqualified registry:2 (which resolves to docker.io/library/registry:2) with the equivalent ghcr.io/distribution/distribution:2. This avoids Docker Hub rate limits entirely without requiring any secrets or workflow changes.

This is consistent with the existing mirror pattern in the repo (see .github/workflows/mirror-envoy.yaml).


AI-generated. Review for accuracy.

@ygalblum requested from Slack

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@osac-ai

osac-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

ℹ️ E2E CaaS Full Install -- Skipped

This suite never reached the point of actually running -- see the run for why (e.g. the e2e-readiness gate wasn't met, or this suite wasn't needed for what changed).

ℹ️ E2E BMaaS Full Install -- Skipped

This suite never reached the point of actually running -- see the run for why (e.g. the e2e-readiness gate wasn't met, or this suite wasn't needed for what changed).

ℹ️ E2E VMaaS Full Install -- Skipped

This suite never reached the point of actually running -- see the run for why (e.g. the e2e-readiness gate wasn't met, or this suite wasn't needed for what changed).

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: d3535543-5f67-4786-8783-8d9e405f674e

📥 Commits

Reviewing files that changed from the base of the PR and between abe80e8 and ba3d117.


📒 Files selected for processing (1)
  • osac-aap/tests/integration/setup_test_env.sh

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review.



⚠️ A high-level summary could not be generated for this review. CodeRabbit will regenerate it on the next update, or you can request a refresh with @coderabbitai summary.

Walkthrough

The integration test setup now starts the local TLS OCI registry from ghcr.io/distribution/distribution:3 instead of registry:2. Other registry setup and readiness behavior is unchanged.

Changes

Integration registry setup

Layer / File(s) Summary
Update registry container image
osac-aap/tests/integration/setup_test_env.sh
The local TLS OCI registry now uses ghcr.io/distribution/distribution:3. Other setup and readiness behavior is unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Suggested reviewers: wgordon17

Merge Risk: ⚪ Minimal · up to ba3d1

The integration setup uses the GHCR registry image and retains its existing TLS and chart-push flow. No merge-blocking failure is established.

Pre-merge checks | Passed 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly identifies the main change: replacing the Docker Hub registry image with a GHCR image to avoid Docker Hub rate limits.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets Passed The pull request changes only the container image reference in osac-aap/tests/integration/setup_test_env.sh, from registry:2 to ghcr.io/distribution/distribution:3. The changed value contains no…
No-Weak-Crypto Passed The pull request changes only the container image reference to ghcr.io/distribution/distribution:3. The added line contains no MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB, custom crypto, or secret-comp…
No-Injection-Vectors Passed The pull request changes only a static container image reference in osac-aap/tests/integration/setup_test_env.sh: registry:2 becomes ghcr.io/distribution/distribution:3. The change adds no SQL, …
Container-Privileges Passed The pull request changes only the registry image in a shell-based container launch. The diff adds no --privileged, host PID/network/IPC settings, SYS_ADMIN capability, allowPrivilegeEscalation, …
No-Sensitive-Data-In-Logs Passed PASS. The pull request changes only the container image argument from registry:2 to ghcr.io/distribution/distribution:3 in the integration setup script. It adds no logging, credentials, tokens, pa…
Ai-Attribution Passed AI use is explicitly identified in the PR description and commit message. The commit includes an Assisted-by: Claude Code (claude.ai) trailer and does not include a Co-Authored-By trailer.


✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Create a new PR



Comment @coderabbitai help to get the list of available commands.

@ygalblum
ygalblum requested a review from eliorerz October 9, 2026 22:00
The CI integration test uses a local OCI registry container. Pulling
the `registry:2` image from Docker Hub is subject to unauthenticated
pull rate limits, which cause intermittent CI failures. Switch to the
equivalent CNCF Distribution image hosted on GitHub Container Registry
(`ghcr.io/distribution/distribution:2`), which has no such limits.

Assisted-by: Claude Code (claude.ai)
Signed-off-by: Chai Bot <chai-bot@redhat.com>
@redhat-chai-bot
redhat-chai-bot force-pushed the fix/docker-hub-ratelimit branch from 928f32d to ba3d117 Compare October 9, 2026 22:02
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🧭 Jobs Selection (informational only)

E2E Suites

Suite Decision Source Reason
VMAAS sanity deterministic-default-sanity No changed files matched a path rule for this suite, and no exclusive-skip allow-list covers it
CAAS sanity deterministic-default-sanity No changed files matched a path rule for this suite, and no exclusive-skip allow-list covers it
BMAAS sanity deterministic-default-sanity No changed files matched a path rule for this suite, and no exclusive-skip allow-list covers it

No AI validation needed -- nothing in this PR was recognized as relevant to any E2E suite.
Estimated cost: $0.0000 (0 input + 0 output tokens, gemini-3.1-pro-preview)

Unit Tests

Job Decision Reason
fulfillment-service run This workflow has no per-component scoping -- runs for any non-doc change
osac-metering run This workflow has no per-component scoping -- runs for any non-doc change
osac-metering/adapters run This workflow has no per-component scoping -- runs for any non-doc change
osac-metering/schema run This workflow has no per-component scoping -- runs for any non-doc change

Integration Tests

Job Decision Reason
fulfillment-service run This workflow has no per-component scoping -- runs for any non-doc change
osac-operator run This workflow has no per-component scoping -- runs for any non-doc change
bare-metal-fulfillment-operator run This workflow has no per-component scoping -- runs for any non-doc change
osac-aap run This workflow has no per-component scoping -- runs for any non-doc change
osac-installer run This workflow has no per-component scoping -- runs for any non-doc change

Helm Lint

Job Decision Reason
osac-operator skip No changed files matched this job's path filter
bare-metal-fulfillment-operator skip No changed files matched this job's path filter
fulfillment-service skip No changed files matched this job's path filter
osac-aap skip No changed files matched this job's path filter
osac-csi-driver skip No changed files matched this job's path filter
osac-metering skip No changed files matched this job's path filter
osac-installer skip No dependent component chart changed

Checks & Builds

Job Decision Reason
Check generated code (proto) skip No changed files matched this job's path filter
fulfillment-service checks skip No changed files matched this job's path filter
Build container image (osac-operator) skip No changed files matched this job's path filter
Build container image (bare-metal-fulfillment-operator) skip No changed files matched this job's path filter
ansible-lint (osac-aap) run Matches this job's path filter
Darwin keychain tests skip No changed files matched this job's path filter

Every table above is informational only -- nothing here gates whether a job actually runs. The E2E Suites table can use AI judgment for ambiguous files; every other table is deterministic-only (no AI).

@openshift-ci

openshift-ci Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eliorerz, redhat-chai-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

E2E on lgtm

All merge-required e2e gates already success on HEAD — skipping replay.

Accepted: e2e-vmaas-gate, e2e-bmaas-gate, e2e-caas-gate on ba3d117.

@osac-ci-bot
osac-ci-bot enabled auto-merge October 9, 2026 22:08
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

E2E on CodeRabbit approval

All merge-required e2e gates already success on HEAD — skipping replay.

Accepted: e2e-vmaas-gate, e2e-bmaas-gate, e2e-caas-gate on ba3d117.

@osac-ci-bot
osac-ci-bot added this pull request to the merge queue Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants