You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ci: Docker Hub anonymous pull rate limit fails integration and e2e jobs on hosted runners #805
CI's integration, e2e and coverage jobs pull their test containers (Redis, NATS, ClickHouse and others) from Docker Hub anonymously, from GitHub-hosted ubuntu-latest runners. Docker Hub rate-limits anonymous pulls per source IP, and hosted runners share IPs, so a job can fail before any test runs because a container can't be created. Those failures look like test failures and turn main red for reasons unrelated to the change.
PR ci(e2e): cache the oldest-Node download of the SDK dist smoke #803 (a CI-cache change touching no Go code), the same evening: Integration tests (app), Integration tests (backends), E2E tests and Coverage failed. In integration (backends), 18 tests failed, starting with internal/cache (TestRedis_Conformance and its siblings), each with:
create container: Error response from daemon: toomanyrequests: You have reached your unauthenticated pull rate limit. https://www.docker.com/increase-rate-limit
The three main runs before c01b912 passed, so this is intermittent, depending on which runner IP a job lands on and how many pulls that IP has already made.
Where the images come from
Testcontainers pulls images by Docker Hub name, for example redis:8.10.2-alpine in the cache tests and clickhouse/clickhouse-server:<version> in the orchestrator, with no registry prefix and no docker login step in the workflows. Each job that starts containers pulls on its own, so one workflow run makes several anonymous pulls per image.
Re-run result (measured): re-running only the failed jobs, on fresh runners, passed both for main at c01b912 (run 37989407513, attempt 2) and for #803 (run 37990130879, attempt 2). Same code, so the failures were the pull limit, not the change.
Problem
CI's integration, e2e and coverage jobs pull their test containers (Redis, NATS, ClickHouse and others) from Docker Hub anonymously, from GitHub-hosted
ubuntu-latestrunners. Docker Hub rate-limits anonymous pulls per source IP, and hosted runners share IPs, so a job can fail before any test runs because a container can't be created. Those failures look like test failures and turnmainred for reasons unrelated to the change.Evidence (measured, 2026-10-09)
mainat c01b912 (ci: add make ci-remote and make the repo's hooks fail closed #798's merge): CI failed in Integration tests (app) and Coverage. The integration (app) job log containstoomanyrequests6 times.PR ci(e2e): cache the oldest-Node download of the SDK dist smoke #803 (a CI-cache change touching no Go code), the same evening: Integration tests (app), Integration tests (backends), E2E tests and Coverage failed. In integration (backends), 18 tests failed, starting with
internal/cache(TestRedis_Conformanceand its siblings), each with:The three
mainruns before c01b912 passed, so this is intermittent, depending on which runner IP a job lands on and how many pulls that IP has already made.Where the images come from
Testcontainers pulls images by Docker Hub name, for example
redis:8.10.2-alpinein the cache tests andclickhouse/clickhouse-server:<version>in the orchestrator, with no registry prefix and nodocker loginstep in the workflows. Each job that starts containers pulls on its own, so one workflow run makes several anonymous pulls per image.Part of #740.