tailscale / tailscale/github-action

Docker Build Action can't push to Tailscale-based registry

Open
#108 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
938
Forks
137
PR merge metrics
No merged PRs in 30d

Description

I strung together a github actions job with the steps:

  1. tailscale/github-action
  2. docker/setup-qemu-action
  3. sigstore/cosign-install
  4. docker/setup-buildx-action
  5. actions/checkout
  6. docker/metadata-action
  7. docker/build-push-action

(2-7 are pretty much default multi-platform image build pipeline github gives you.)

On my tailnet, I'm running the registry:2 container.

The problem is that when build-push-action goes to push, it can't connect:

ERROR: failed to solve: failed to push registry.redacted.ts.net/repo:tag: failed to do request: Head "https://registry.redacted.ts.net/v2/repo/blobs/sha256:9b215f6cf4b06c007e35fcc4c41c620c3728d5135472a1dd6390bb0d1dccbcd5": dial tcp: lookup registry.redacted.ts.net on 168.63.129.16:53: no such host

Adding some debug steps, I've determined:

  • tailscale status runs and shows a bunch of machines
  • curl -iL http://registry.redacted.ts.net/v2/_catalog shows a blob of JSON from the registry
  • docker pull can pull from that registry

I'm not sure if I need to set buildx to use host networking (similar to https://github.com/tailscale/github-action/issues/101#issuecomment-1889694427) or if I should set up proxy settings, or if Docker in GitHub Actions is just Weird™️.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the workflow using tailscale/github-action, docker/setup-buildx-action, and docker/build-push-action against the Tailscale-hosted registry. Start by comparing connectivity from tailscale status, curl, docker pull, and the buildx push step. Done means identifying the required buildx networking or proxy configuration and documenting or implementing a working workflow.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions
Domain
devops, infrastructure, networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.