testcontainers / testcontainers/testcontainers-java

ImageFromDockerfile does not support authenticated pulls

Open
#1,799 6 comments 0 reactions 1 assignee View on GitHub

@rnorth is already working on this.

Since Dec 20, 2019.

resolution/acknowledged type/bug
Dominant language
Java
Stars
8.7k
Forks
1.9k
Avg merge
2d 17h
Merged PRs (30d)
9

Description

ImageFromDockerfile doesn't work if base layer(s) need to be pulled from an authenticated registry and if those images are not already pulled.

For example:

# Dockerfile
FROM my.authenticated.registry/somerepo/someimage

will result in a failure at image build time, even if the user has working credentials available on their machine (for example, a CLI docker pull or docker build works).

It looks like BuildImageCmd's withBuildAuthConfigs(AuthConfigurations); gives us an opportunity to improve this - however we'd have to perform a lookup for credentials for each image first.

I think it should be feasible to:

  • do a minimal parse of the Dockerfile to extract any FROM x [--as=y] declarations
  • run each image name found through RegistryAuthLocator and obtain an auth configuration for each registry
  • provide the auth configurations to BuildImageCmd

The main difficulty would be that we have a few different ways in which the Dockerfile flows through Testcontainers, so we'd need to make sure we capture Dockerfile content at the right time.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.