Skip to content

fix(image): resolve registry credentials from docker config for pulls - #108

Open
deveshctl wants to merge 1 commit into
mainfrom
fix/pull-registry-auth
Open

deveshctl wants to merge 1 commit into
mainfrom
fix/pull-registry-auth

Conversation

@deveshctl

Copy link
Copy Markdown
Owner

Summary

  • Private-registry pulls were always sent unauthenticated because pullOpts() left RegistryAuth empty. The Docker daemon does not fall back to its own credential store when the header is absent — it treats the call as anonymous, so pulls fail with 401 even when docker pull of the same reference succeeds.
  • resolveRegistryAuth (new image/dockerconfig.go) reads ~/.docker/config.json and follows the same lookup chain as the Docker CLI: per-registry credHelpers first, then the global credsStore, then inline auths tokens. Credential helpers are invoked via the docker-credential-<name> subprocess interface, covering osxkeychain, desktop, ecr-login, and any other compliant helper.
  • Encoding delegates to authconfig.Encode from github.com/moby/moby/api/pkg/authconfig — the canonical encoder the daemon's X-Registry-Auth decoder is the exact inverse of.

Test plan

  • Unit tests in image/dockerconfig_test.go cover: missing config file, inline auth round-trip, no matching entry, missing credsStore helper fallback to inline auths, per-registry credHelpers with missing helper
  • CI (go test ./...) passes on push
  • Verified against a local htpasswd-authenticated registry: layerx ci localhost:5001/private/testimage:latest now pulls and analyses successfully with stored credentials

Closes #105

…#105)

Private-registry pulls were always sent unauthenticated because pullOpts()
left RegistryAuth empty. The Docker daemon does not fall back to its own
credential store when the header is explicitly absent — it treats the call
as anonymous, so pulls fail with 401 even when docker pull succeeds.

resolveRegistryAuth (image/dockerconfig.go) now reads ~/.docker/config.json
and follows the same lookup chain as the Docker CLI: per-registry credHelpers
first, then the global credsStore, then inline auths. Credential helpers are
invoked via the docker-credential-<name> subprocess interface, which covers
osxkeychain, desktop, ecr-login, and any other compliant helper.

Encoding delegates to authconfig.Encode from github.com/moby/moby/api/pkg/authconfig
— the canonical encoder whose decoder the daemon uses for X-Registry-Auth.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remote pull ignores Docker credentials

1 participant