Skip to content

Commit ea8b5ea

Browse files
andinuxclaude
andcommitted
ci: pull the Supabase base image from Docker Hub
The supabase docker jobs failed twice on "toomanyrequests: Data limit exceeded" while resolving FROM public.ecr.aws/supabase/postgres. Anonymous ECR Public pulls are charged to a quota keyed on the source IP, which on GitHub-hosted runners is a NAT pool shared with every other Actions user. Supabase publishes the same image to Docker Hub. Both tags resolve to the same manifest index digest -- 17.6.1.170 to sha256:6087b151...6728f and 15.14.1.170 to sha256:bc165447...70b02 -- with linux/amd64 and linux/arm64 on each, so the published images are unchanged. The docker-publish job already logs in to Docker Hub before it builds, so these pulls are now authenticated and counted against our own account. make postgres-supabase-build is unaffected: its sed already rewrites both spellings of the FROM line to the running Supabase CLI image tag, which keeps its public.ecr.aws name so the CLI still picks up the rebuilt image. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 1403d3f commit ea8b5ea

2 files changed

Lines changed: 9 additions & 3 deletions

File tree

‎docker/postgresql/Dockerfile.supabase‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,8 +46,10 @@ RUN mkdir -p /tmp/cloudsync-artifacts/lib /tmp/cloudsync-artifacts/extension &&
4646
cp /tmp/cloudsync/src/postgresql/migrations/cloudsync--*--*.sql /tmp/cloudsync-artifacts/extension/; \
4747
fi
4848

49-
# Runtime image based on Supabase Postgres
50-
FROM public.ecr.aws/supabase/postgres:${SUPABASE_POSTGRES_TAG}
49+
# Runtime image based on Supabase Postgres. Docker Hub and public.ecr.aws carry
50+
# the same image; see Dockerfile.supabase.release for why this one is used.
51+
# make postgres-supabase-build rewrites this line to the running CLI image tag.
52+
FROM supabase/postgres:${SUPABASE_POSTGRES_TAG}
5153

5254
# Extension version (derived from src/cloudsync.h by the Makefile and passed in
5355
# as a build arg); used only for the image label.

‎docker/postgresql/Dockerfile.supabase.release‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,11 @@
1919
#
2020

2121
ARG SUPABASE_POSTGRES_TAG=17.6.1.170
22-
FROM public.ecr.aws/supabase/postgres:${SUPABASE_POSTGRES_TAG}
22+
# Supabase publishes the same image to Docker Hub and to public.ecr.aws; both
23+
# tags resolve to identical manifest digests. Docker Hub is used here because CI
24+
# already authenticates to it, while anonymous ECR Public pulls are charged to a
25+
# data quota shared by every GitHub Actions runner.
26+
FROM supabase/postgres:${SUPABASE_POSTGRES_TAG}
2327

2428
ARG CLOUDSYNC_VERSION
2529
ARG TARGETARCH

0 commit comments

Comments
 (0)