Skip to content

skip BuildKit image pre-pulls for explicit endpoints - #624

Merged
crazy-max merged 2 commits into
docker:masterfrom
crazy-max:skip-pull-with-endpoint
Sep 16, 2026
Merged

crazy-max merged 2 commits into
docker:masterfrom
crazy-max:skip-pull-with-endpoint

Conversation

@crazy-max

@crazy-max crazy-max commented Sep 16, 2026

Copy link
Copy Markdown
Member

fixes #623

Rregression introduced in v4.4.0 where the BuildKit image pre-pull targets the default Docker daemon even when an endpoint is specified. Skip pre-pulls for nodes with explicit endpoints and let Buildx pull on the target daemon during bootstrap. CI now covers named contexts and TCP endpoints with an unavailable default daemon.

I'm working on a follow-up to restore pre-pulls for explicit endpoints using the endpoint support proposed in docker/actions-toolkit#1326.

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max
crazy-max requested a review from a team September 16, 2026 07:42
@crazy-max
crazy-max marked this pull request as ready for review September 16, 2026 07:42

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@crazy-max
crazy-max merged commit f87e599 into docker:master Sep 16, 2026
53 checks passed
@crazy-max
crazy-max deleted the skip-pull-with-endpoint branch September 16, 2026 07:47
doonga pushed a commit to greyrock-labs/cert-manager-webhook-cloudns that referenced this pull request Sep 16, 2026
…dx-action (v4.4.0 ➔ v4.4.1) (#19)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | action | patch | `v4.4.0` → `v4.4.1` |

---

### Release Notes

<details>
<summary>docker/setup-buildx-action (https://github.com/docker/setup-buildx-action)</summary>

### [`v4.4.1`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1)

[Compare Source](docker/setup-buildx-action@v4.4.0...v4.4.1)

- Skip BuildKit image pre-pulls for explicit endpoints by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;624](docker/setup-buildx-action#624)

**Full Changelog**: <docker/setup-buildx-action@v4.4.0...v4.4.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC44NC4wIiwidXBkYXRlZEluVmVyIjoiNDQuODQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvZ2l0aHViLWFjdGlvbiIsInJlbm92YXRlL2dpdGh1Yi1yZWxlYXNlIiwidHlwZS9wYXRjaCJdfQ==-->

Reviewed-on: https://git.greyrock.io/todd/cert-manager-webhook-cloudns/pulls/19
marcocot pushed a commit to marcocot/vinted-search-mcp that referenced this pull request Sep 21, 2026
…ion to v4 (#9)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | action | major | `v3` → `v4` |

---

### Release Notes

<details>
<summary>docker/setup-buildx-action (https://github.com/docker/setup-buildx-action)</summary>

### [`v4.4.1`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1)

[Compare Source](docker/setup-buildx-action@v4.4.0...v4.4.1)

- Skip BuildKit image pre-pulls for explicit endpoints by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;624](docker/setup-buildx-action#624)

**Full Changelog**: <docker/setup-buildx-action@v4.4.0...v4.4.1>

### [`v4.4.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.0)

[Compare Source](docker/setup-buildx-action@v4.3.0...v4.4.0)

- Use official Buildx releases for cloud driver by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;606](docker/setup-buildx-action#606)
- Pull BuildKit image before builder creation by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;609](docker/setup-buildx-action#609)
- Use shared error helpers for Buildx and Docker commands by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;620](docker/setup-buildx-action#620)
- Bump [@&#8203;docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.95.0 to 0.100.0 in [#&#8203;610](docker/setup-buildx-action#610) [#&#8203;618](docker/setup-buildx-action#618) [#&#8203;619](docker/setup-buildx-action#619)
- Bump [@&#8203;humanfs/node](https://github.com/humanfs/node) from 0.16.7 to 0.16.8 in [#&#8203;614](docker/setup-buildx-action#614)
- Bump js-yaml from 5.3.0 to 5.4.2 in [#&#8203;608](docker/setup-buildx-action#608) [#&#8203;617](docker/setup-buildx-action#617)
- Bump postcss-selector-parser from 7.1.1 to 7.1.5 in [#&#8203;611](docker/setup-buildx-action#611)

**Full Changelog**: <docker/setup-buildx-action@v4.3.0...v4.4.0>

### [`v4.3.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.3.0)

[Compare Source](docker/setup-buildx-action@v4.2.0...v4.3.0)

- Bump [@&#8203;docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.95.0 in [#&#8203;595](docker/setup-buildx-action#595)
- Bump brace-expansion from 1.1.13 to 1.1.18 in [#&#8203;600](docker/setup-buildx-action#600)
- Bump js-yaml from 5.2.0 to 5.3.0 in [#&#8203;585](docker/setup-buildx-action#585)
- Bump postcss from 8.5.10 to 8.5.25 in [#&#8203;598](docker/setup-buildx-action#598)
- Bump undici from 6.27.0 to 6.28.0 in [#&#8203;601](docker/setup-buildx-action#601)

**Full Changelog**: <docker/setup-buildx-action@v4.2.0...v4.3.0>

### [`v4.2.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.2.0)

[Compare Source](docker/setup-buildx-action@v4.1.0...v4.2.0)

- Preserve names in esbuild bundle by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;572](docker/setup-buildx-action#572)
- Bump [@&#8203;actions/core](https://github.com/actions/core) from 3.0.0 to 3.0.1 in [#&#8203;551](docker/setup-buildx-action#551)
- Bump [@&#8203;docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.90.0 to 0.92.0 in [#&#8203;557](docker/setup-buildx-action#557) [#&#8203;580](docker/setup-buildx-action#580)
- Bump [@&#8203;sigstore/core](https://github.com/sigstore/core) from 3.1.0 to 3.2.1 in [#&#8203;573](docker/setup-buildx-action#573)
- Bump [@&#8203;sigstore/verify](https://github.com/sigstore/verify) from 3.1.0 to 3.1.1 in [#&#8203;576](docker/setup-buildx-action#576)
- Bump js-yaml from 4.1.1 to 5.2.0 in [#&#8203;562](docker/setup-buildx-action#562)
- Bump sigstore from 4.1.0 to 4.1.1 in [#&#8203;577](docker/setup-buildx-action#577)
- Bump tmp from 0.2.5 to 0.2.7 in [#&#8203;556](docker/setup-buildx-action#556)
- Bump undici from 6.25.0 to 6.27.0 in [#&#8203;570](docker/setup-buildx-action#570)
- Bump vite from 7.3.2 to 7.3.6 in [#&#8203;569](docker/setup-buildx-action#569)

**Full Changelog**: <docker/setup-buildx-action@v4.1.0...v4.2.0>

### [`v4.1.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.1.0)

[Compare Source](docker/setup-buildx-action@v4.0.0...v4.1.0)

- Bump [@&#8203;docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.79.0 to 0.90.0 in [#&#8203;489](docker/setup-buildx-action#489)
- Bump brace-expansion from 1.1.12 to 5.0.6 in [#&#8203;547](docker/setup-buildx-action#547) [#&#8203;508](docker/setup-buildx-action#508)
- Bump fast-xml-builder from 1.0.0 to 1.2.0 in [#&#8203;540](docker/setup-buildx-action#540)
- Bump fast-xml-parser from 5.4.2 to 5.8.0 in [#&#8203;496](docker/setup-buildx-action#496)
- Bump flatted from 3.3.3 to 3.4.2 in [#&#8203;499](docker/setup-buildx-action#499)
- Bump glob from 10.3.12 to 13.0.6 in [#&#8203;495](docker/setup-buildx-action#495)
- Bump handlebars from 4.7.8 to 4.7.9 in [#&#8203;504](docker/setup-buildx-action#504)
- Bump lodash from 4.17.23 to 4.18.1 in [#&#8203;523](docker/setup-buildx-action#523)
- Bump picomatch from 4.0.3 to 4.0.4 in [#&#8203;503](docker/setup-buildx-action#503)
- Bump postcss from 8.5.6 to 8.5.10 in [#&#8203;537](docker/setup-buildx-action#537)
- Bump tar from 6.2.1 to 7.5.15 in [#&#8203;545](docker/setup-buildx-action#545)
- Bump undici from 6.23.0 to 6.25.0 in [#&#8203;492](docker/setup-buildx-action#492)
- Bump vite from 7.3.1 to 7.3.2 in [#&#8203;520](docker/setup-buildx-action#520)

**Full Changelog**: <docker/setup-buildx-action@v4.0.0...v4.1.0>

### [`v4.0.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.0.0)

[Compare Source](docker/setup-buildx-action@v3.12.0...v4.0.0)

- Node 24 as default runtime (requires [Actions Runner v2.327.1](https://github.com/actions/runner/releases/tag/v2.327.1) or later) by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;483](docker/setup-buildx-action#483)
- Remove deprecated inputs/outputs by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;464](docker/setup-buildx-action#464)
- Switch to ESM and update config/test wiring by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;481](docker/setup-buildx-action#481)
- Bump [@&#8203;actions/core](https://github.com/actions/core) from 1.11.1 to 3.0.0 in [#&#8203;475](docker/setup-buildx-action#475)
- Bump [@&#8203;docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.63.0 to 0.79.0 in [#&#8203;482](docker/setup-buildx-action#482) [#&#8203;485](docker/setup-buildx-action#485)
- Bump js-yaml from 4.1.0 to 4.1.1 in [#&#8203;452](docker/setup-buildx-action#452)
- Bump lodash from 4.17.21 to 4.17.23 in [#&#8203;472](docker/setup-buildx-action#472)
- Bump minimatch from 3.1.2 to 3.1.5 in [#&#8203;480](docker/setup-buildx-action#480)

**Full Changelog**: <docker/setup-buildx-action@v3.12.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Rome)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJjaG9yZSIsImRlcHMiLCJtYWpvciJdfQ==-->

Reviewed-on: https://git.homelab.devncode.it/marco/vinted-search-mcp/pulls/9
nickpell pushed a commit to cloudx-io/openauction that referenced this pull request Sep 21, 2026
#70)

## Summary

Routine refresh of the ratchet-managed Action pins under `.github/`.
Each pin moves to the newest release inside its existing `# ratchet:`
constraint; no constraint comment changes, so **no action moves to a new
major**. Four actions moved across five call sites in two workflow
files.

No major version was held back: after this update every pinned action is
simultaneously the newest release within its major and the newest
release overall, so there is no pending major upgrade to consider in a
follow-up.

## Refs that moved

| Action | Files | Constraint | Version (from → to) | SHA (from → to) |
| --- | --- | --- | --- | --- |
| `aws-actions/configure-aws-credentials` | `docker.yml`,
`eif-build.yml` | `@v6` | v6.2.4 → v6.3.0 | `cbe3b3927387` →
`e1253824e5c1` |
| `docker/build-push-action` | `docker.yml` | `@v7` | v7.3.0 → v7.4.0 |
`53b7df96c91f` → `c3c9e263c25d` |
| `docker/setup-buildx-action` | `docker.yml` | `@v4` | v4.3.0 → v4.4.1
| `37fe63102785` → `f87e5991a6d7` |
| `docker/setup-qemu-action` | `docker.yml` | `@v4` | v4.3.0 → v4.4.0 |
`1f40c72289ef` → `990126619549` |

The remaining seven pinned actions were already at the tip of their
constraint and are untouched.

## Upstream changelog

### aws-actions/configure-aws-credentials v6.2.4 → v6.3.0

A single feature, [add translate-env-variables option
(#1961)](aws-actions/configure-aws-credentials#1961).
The action has always translated a fixed list of `AWS_*`/role-related
environment variables into their equivalent action inputs; v6.3.0 puts
that translation behind a new optional `translate-env-variables` input
that **defaults to `true`**, so the default path is byte-for-byte the
previous behavior. The release also adds an info log line when a
translation actually occurs, and trims an example from the
`sts-endpoint` input description.

This is the only `action.yml` change in the whole set — the new optional
input plus that description edit.

### docker/setup-buildx-action v4.3.0 → v4.4.1

Two releases.
[v4.4.0](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.0)
adds [Pull BuildKit image before builder creation
(#609)](docker/setup-buildx-action#609),
switches the cloud driver to official Buildx releases
([#606](docker/setup-buildx-action#606)), routes
command failures through shared error helpers
([#620](docker/setup-buildx-action#620)), and
bumps `@docker/actions-toolkit` 0.95.0 → 0.100.0.
[v4.4.1](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1)
then adds [Skip BuildKit image pre-pulls for explicit endpoints
(#624)](docker/setup-buildx-action#624),
refining the pre-pull introduced one release earlier. Landing directly
on v4.4.1 means this repo never runs the unrefined v4.4.0 form of that
behavior.

### docker/build-push-action v7.3.0 → v7.4.0


[v7.4.0](https://github.com/docker/build-push-action/releases/tag/v7.4.0)
contains [Prevent workflow command injection in metadata logs
(#1617)](docker/build-push-action#1617), the
shared error helper change
([#1620](docker/build-push-action#1620)), and
`@docker/actions-toolkit` 0.92.0 → 0.100.0 plus routine dependency
bumps.

### docker/setup-qemu-action v4.3.0 → v4.4.0


[v4.4.0](https://github.com/docker/setup-qemu-action/releases/tag/v4.4.0)
is the shared error helper change
([#345](docker/setup-qemu-action#345)) plus
`@docker/actions-toolkit` 0.96.0 → 0.100.0 and routine dependency bumps.
The only source change is the error handling described below.

## Risk assessment

None of the four releases is labelled breaking, and `action.yml` is
byte-identical across all three Docker action bumps, so no input,
output, or runtime contract changed for them. Three behavior changes do
reach this repository and are worth reading closely.

**BuildKit image pre-pull is reachable and changes the Docker Build
workflow's step sequence.** The build job calls
`docker/setup-buildx-action` with only `platforms`, so it uses the
default `docker-container` driver with no `endpoint`, `append`, or
`driver-opts`, and the builder never pre-exists on a fresh runner. Every
guard on the new pre-pull path is therefore satisfied, and the action
now runs an explicit `docker pull moby/buildkit:buildx-stable-1` in a
new "Pulling BuildKit image(s)" group before creating the builder. That
is the same image from the same registry that `buildx create`/bootstrap
pulled implicitly before; what changes is that it happens earlier and
goes through the toolkit's five-attempt retry helper rather than a
single unretried implicit pull. The practical effect is better
resilience to transient registry failures and an extra log group. The
v4.4.1 follow-up skips the pre-pull when an explicit endpoint is
configured, which is inert here because no endpoint is set.

**Command failure detection is now stricter in all three Docker
actions.** The shared error helper work changed the failure condition
from `res.stderr.length > 0 && res.exitCode != 0` to simply
`res.exitCode != 0`, with messages routed through `getErrorMessage`,
which strips terminal control characters and returns the last non-empty
stderr line behind a step-specific prefix. This is reachable at every
Docker action call site in this repo. Previously a docker or buildx
command that exited non-zero while writing nothing to stderr was
silently treated as success; it now raises an error. This is a
correctness improvement, and the only way it turns a previously green
build red is if a command was genuinely failing and being swallowed.

**Build metadata logging is hardened.** `docker/build-push-action` now
prints the build metadata JSON via the toolkit's `printUntrusted`, which
brackets the output with `::stop-commands::<random token>` so the
Actions runner cannot interpret workflow-command syntax embedded in that
JSON. This reaches the Docker Build workflow, which prints that group on
every build. It is defense in depth with no behavior change for
well-formed metadata.

**The AWS credentials bump is inert here.** Neither call site sets the
new `translate-env-variables` input, and its `true` default reproduces
the prior unconditional translation exactly. The only variable from the
translated list that this repo sets is `AWS_REGION`, at workflow level
in the Build EIF workflow, and both credential steps already pass
`aws-region` explicitly — so the corresponding input is already
populated and the new guard skips the assignment, resolving to the same
value as before. Both call sites also pass only `role-to-assume` and
`aws-region` in jobs granting `id-token: write`, so nothing else in the
release surface applies.

**Nothing newer has shipped**, and the upstream issue trackers show no
open reports against any of these four releases.

## CI coverage caveat

All five moved call sites live in `docker.yml` and `eif-build.yml`,
which trigger on `workflow_run` and `workflow_dispatch` rather than
`pull_request`. PR CI therefore confirms the workflow files are
well-formed and correctly pinned, but does not execute any of the four
updated actions. The behavior changes above are first exercised after
merge, which is what the post-merge section covers.

## Pre-merge checklist

- [ ] `mise run //:ratchet:update` produced exactly the ref changes in
this diff and nothing else. — Verification: The historical update
invocation was not rerun; changed pins match their claimed release tags
and CI proves pin idempotence.
- [x] `mise run //:ratchet:lint` passes — every external ref is still
pinned to a full SHA (19 of 19 `uses:` call sites). — Verification:
Confirmed in the successful [Ratchet Lint
job](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741),
including pinning and the clean-diff check.
- [x] `mise run //:ratchet:pin` is idempotent and produces no further
diff. — Verification: Confirmed in the successful [Ratchet Lint
job](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741),
including pinning and the clean-diff check.
- [x] PR CI is green, including `Ratchet Lint`. — Verification: All 3
reported checks are successful or intentionally skipped at
`6605eb41bf09`; [Ratchet
Lint](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741)
passed.
- [x] Diff touches only pinned SHA values; no constraint comments,
workflow logic, or unrelated files changed. — Verification: Verified
every added/deleted line after replacing SHA and digest values with a
common placeholder.

## Post-merge verification

- [ ] Workflows on `main` resolve to the new pins. — Verification:
Pending merge and deployment; this result has not been observed.
- [ ] The next Docker Build run succeeds, and the new "Pulling BuildKit
image(s)" group pulls `moby/buildkit:buildx-stable-1` before the builder
is created. — Verification: Pending merge and deployment; this result
has not been observed.
- [ ] The Docker Build image build, push, and multi-architecture
emulation behave as before, with SBOM and provenance still attached. —
Verification: Pending merge and deployment; this result has not been
observed.
- [ ] The next Build EIF run authenticates successfully with the updated
credentials action. — Verification: Pending merge and deployment; this
result has not been observed.

## Weekly verification, 2026-09-21

- [x] Current HEAD CI verified. All 3 reported checks are successful or
intentionally skipped at `6605eb41bf09`; [Ratchet
Lint](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741)
passed.
- [x] Copilot reviewed this HEAD. No unresolved review threads.
- [x] Upstream release commits verified through the GitHub API:
`aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd`
= `v6.3.0`.
- [x] Docker action release commits verified:
`docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1` =
`v4.4.0`;
`docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069` =
`v4.4.1`;
`docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc` =
`v7.4.0`.
- [x] Diff normalization verified: changes are only action SHAs and, for
SSP, the documented image digests; no workflow logic or ratchet
constraint changes.

<div><a
href="https://cursor.com/agents/bc-48004c83-b1d4-4fa3-b4a3-c77a3f9bf753?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/65e8572f-8209-11f1-a7d1-d6b4613131ce"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Endpoint is being disregarded

2 participants