Conversation
I believe recent build failures (openwrt#211) are caused by GitHub redacting the Docker Hub and Quay.io usernames inside Docker tag names passed to buildx. This changes the Docker Hub and Quay.io usernames to be stored as configuration variables[1], which are not redacted by GitHub, rather than as secrets. [1]: https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-variables#defining-configuration-variables-for-multiple-workflows Signed-off-by: Jeffery To <jeffery.to@gmail.com>
|
I should note that I'm only guessing this will fix #211 as I don't have a practical way to debug the issue or test this fix. I think it is a good idea in general to store the usernames as variables instead of as secrets. |
|
I just spent a while poking around and I'm still pretty hazy on what might be failing, but it seems to me that the Then after that, it's only in the Or, if |
|
My guess is either the tags passed to buildx have literal asterisks ( I think buildx is processing tags in random order and exiting with an error for the first invalid tag it finds, but this is also just a guess. |
Yeah, that does seem very strange, doesn't it? From what I've read, github's redaction algo is pretty stupid and brute force, so you'd expect all of them to get swapped. At this point, I'm betting on your idea about invisible delimiters. @BKPepe Could you copy the |
|
Oh, @jefferyto is back! I did not notice that. Sorry guys, I did not look at it so far. :(( Hopefully in a few days, I will have some free time to look at it. |
|
@BKPepe On Docker Hub and Quay, the organization name is "openwrt" but is the user name the same or different? If it is different then perhaps the issue is the workflow is trying to tag images for the user ( |
|
If the username is different then that explains why "openwrt" is not redacted in the logs. Thinking more about this, I think it makes more sense for the usernames to be secret, since workflow logs are basically public. (So ignore this PR.) If my second guess is correct then the fix would be to add secrets for the organization name. |
Oho, that makes a lot more more sense. |
|
I created this PR: #213 |
I believe recent build failures (#211) are caused by GitHub redacting the Docker Hub and Quay.io usernames inside Docker tag names passed to buildx.
This changes the Docker Hub and Quay.io usernames to be stored as configuration variables, which are not redacted by GitHub, rather than as secrets.