Add ECR authentication support to image-builder #18506
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR adds ECR auth support to image builder. For an ECR registry to become accessible, it needs to be listed explicitly in the build request, e.g. using
defaultBaseImageRegistryWhitelist
.Building images with private ECR images does not work yet, only pulling them directly.
Summary generated by Copilot
🤖 Generated by Copilot at 50edde1
This pull request adds support for additional authentication for Amazon ECR repositories in the image-builder-mk3 and image-builder-api components. This feature allows users to access private ECR repositories using IAM roles for service accounts. It also updates the configuration and installation packages to enable this feature. It modifies the
auth
,orchestrator
, andresolve
packages in theimage-builder-mk3
component, and theconfig
package in theimage-builder-api
component. It also changes the filescomponents/image-builder-mk3/go.mod
,components/image-builder-api/go/config/config.go
,install/installer/pkg/components/image-builder-mk3/configmap.go
, andinstall/installer/pkg/config/v1/config.go
.How to test
This change is deployed to dev-internal.
There's a test image at
422899872803.dkr.ecr.eu-central-1.amazonaws.com/private-repo-demo:latest
.Documentation
Preview status
gitpod:summary
Build Options
Build
Run the build with werft instead of GHA
Run Leeway with
--dont-test
Publish
Installer
Add desired feature flags to the end of the line above, space separated
Preview Environment / Integration Tests
If enabled this will build
install/preview
If enabled this will create the environment on GCE infra
Valid options are
all
,workspace
,webapp
,ide
,jetbrains
,vscode
,ssh
. If enabled,with-preview
andwith-large-vm
will be enabled./hold