Skip to content

Check base images using mirror registry instead of public DockerHub - #2119

Merged
lbussell merged 4 commits into
dotnet:mainfrom
lbussell:fix-check-base-images
May 27, 2026
Merged

lbussell merged 4 commits into
dotnet:mainfrom
lbussell:fix-check-base-images

Conversation

@lbussell

@lbussell lbussell commented May 23, 2026 •

Copy link
Copy Markdown
Member

This PR responds to new network isolation requirements that broke the check base images pipeline. Outbound connections to DockerHub are blocked by 1ES Network Isolation policies ("CFSClean") in internal Azure Pipelines runs.

Previously the pipeline worked like this:

  1. Copy Base Images - imports new/updated external images to the internal mirror registry. Since this process runs in Azure, it isn't subject to the same Network Isolation policies as 1ES Pipelines.
  2. Get Stale Images - compares base image digests from two sources:
    • From dotnet/versions / image-info.json files.
    • From the upstream/DockerHub registry.
  3. Queue a build for all images that have mis-matched digests.

Obviously, comparing base image digests from DockerHub is a problem if the network blocks the connection.

This PR updates the getStaleImages command to use the mirrored images that we had already just copied anyways. For simplicity/consistency's sake, I also updated getStaleImages to use the exact same mirror/override arguments as copyBaseImages, that way we know we're referencing the images the exact same way.

lbussell and others added 4 commits May 26, 2026 10:20
The previous --base-override-regex/sub approach rewrote external FROM
tags to point at the staging mirror, but the rewritten repo prefix
also leaked into the digest comparison string. image-info.json stores
the digest against the canonical (public) repo, so every rewritten
image compared unequal and was reported stale on every run.

Switch getStaleImages to the same mechanism the build/matrix flow
already uses:
- Add --registry-override and --source-repo-prefix options (mirroring
  what ManifestOptions exposes and what copyBaseImages consumes).
- Construct ImageNameResolverForMatrix per subscription manifest.
  GetFromImagePullTag returns the staging mirror location for fetching
  the digest; GetFromImagePublicTag returns the canonical reference
  used to build the digest comparison string.

The pipeline yml now passes --registry-override / --source-repo-prefix
in place of the regex pair, matching how the copyBaseImages step in
the same job is invoked. --base-override-regex/sub remains supported
for genuine one-off overrides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Two different FROM spellings can normalize to the same pull tag
(e.g. 'almalinux:8' and 'library/almalinux:8' both pull from
'<staging>/mirror/library/almalinux:8') but produce different public
tags. The previous code cached the full '<repo>@<sha>' comparison
string by pull tag, which meant the second lookup could reuse the
first FROM's public repo prefix and falsely mark the image as stale.

Cache only the raw SHA so the comparison string is always built from
the current platform's own public tag.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lbussell

Copy link
Copy Markdown
Member Author

This PR contains ImageBuilder source code changes only. Pipeline changes are in #2123.

@lbussell
lbussell marked this pull request as ready for review May 26, 2026 17:24
@lbussell
lbussell requested a review from a team as a code owner May 26, 2026 17:24
@lbussell
lbussell requested a review from mthalman May 26, 2026 17:24
@mthalman

Copy link
Copy Markdown
Member

This process runs in Azure, and uses DockerHub credentials stored in Azure KeyVault, so it isn't subject to rate limiting or network isolation.

I don't understand why it's not subject to network isolation but other operations are.

@lbussell

Copy link
Copy Markdown
Member Author

I don't understand why it's not subject to network isolation but other operations are.

I updated the description to hopefully be a little more clear.

@lbussell
lbussell merged commit d141d20 into dotnet:main May 27, 2026
12 checks passed
@lbussell
lbussell deleted the fix-check-base-images branch May 27, 2026 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants