Repository navigation
Fix docker credentials in the skipper container and expose the push destination - #197
Merged
Merged
Conversation
khizunov
force-pushed
the
anton/fix-docker-config-mount
branch
3 times, most recently
from
September 14, 2026 12:49
10152ef to
9d2d3b9
Compare
khizunov
force-pushed
the
anton/fix-docker-config-mount
branch
4 times, most recently
from
September 14, 2026 13:05
11c92e2 to
211bfb8
Compare
khizunov
force-pushed
the
anton/fix-docker-config-mount
branch
from
September 14, 2026 13:37
211bfb8 to
398d5b2
Compare
khizunov
force-pushed
the
anton/fix-docker-config-mount
branch
from
September 14, 2026 13:44
398d5b2 to
b0a7f93
Compare
ofir-amir
approved these changes
Sep 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
Closes #195
Closes #196
Docker credentials (#195)
Mount the credentials from the right place.
handle_volumes_bind_mountbuilt the mount source from$HOMErather than$HOME/.docker, so on Linux the whole home directory was bind-mounted read-write at/opt/.docker(and/opt/.docker/config.jsonstill did not exist), while on macOS the source$HOME/config.jsondid not exist and the mount was skipped altogether. The source is now the effective host docker config directory -DOCKER_CONFIGwhen set,~/.dockerotherwise - so a custom config location reaches the container too.Also mount the credentials at their host path. The container keeps the host's
HOME, so a nested skipper,helmororaslooks for$HOME/.docker/config.jsonrather than atDOCKER_CONFIG. The same credentials are mounted there read-only — writes belong in theDOCKER_CONFIGcopy.Honor
DOCKER_CONFIGwhen reading the registry login.set_remote_registry_login_inforead~/.docker/config.jsonunconditionally. It now does the same lookup docker itself does (DOCKER_CONFIG, falling back to~/.docker), so a skipper running inside a skipper container finds the login info forpush,images -randrmi -r.Point every runtime at the writable copy.
DOCKER_CONFIG={DOCKER_CONFIG}was injected only for the docker runtime, so under podman a docker-format credential writer (docker login,oras login) resolved to$HOME/.docker/config.json- now a read-only mount. The injection is no longer inside the runtime branch;DOCKER_CONTEXTandSKIPPER_DOCKER_GIDstay docker-only.Point helm at the mounted credentials. helm reads the docker config format but locates it through
HELM_REGISTRY_CONFIG, notDOCKER_CONFIG._run_nestednow setsHELM_REGISTRY_CONFIG=/opt/.docker/config.jsonunless the caller defined it (is_environment_variable_definedcompares the name before=, so an unrelatedMY_HELM_REGISTRY_CONFIGno longer suppresses it), sohelm pushto an OCI registry works off the samedocker loginas everything else.Registry and namespace variables (#196)
skipper run/make/shellnow exportSKIPPER_REGISTRY(from--registryorregistry) andSKIPPER_NAMESPACE(frompush.namespace), each only when configured. They are prepended to the environment list, so an explicitenv/-eentry of the same name still wins. Documented in the README.Testing
ruff check --preview skipper testspasses.pytest tests— 124 passed, 1 failed:test_run_simple_command_nested_with_multiple_env_filesfails identically onupstreambefore this branch (macOS-only: default netbridgevshost, and/private/etc/dockersymlink resolution), so it is pre-existing and unrelated.New coverage:
HELM_REGISTRY_CONFIGdefault and user override, exact-name environment matching, the docker config lookup honoringDOCKER_CONFIG, both credential mounts following it, a YAML-nullpush:section, and the injected push-destination variables. The runner tests spell out both credential mounts explicitly instead of reusing the production expression, so a change to the mounted path shows up as a failure.Generated description
Below is a concise technical summary of the changes proposed in this PR:
graph LR cli_("cli"):::modified set_remote_registry_login_info_("set_remote_registry_login_info"):::modified get_docker_config_path_("get_docker_config_path"):::added get_docker_config_dir_("get_docker_config_dir"):::added run_nested_("_run_nested"):::modified is_environment_variable_defined_("is_environment_variable_defined"):::modified handle_volumes_bind_mount_("handle_volumes_bind_mount"):::modified HELM_("HELM"):::added cli_ -- "CLI now stores namespace before loading registry authentication." --> set_remote_registry_login_info_ set_remote_registry_login_info_ -- "Registry authentication now respects DOCKER_CONFIG or default Docker directory." --> get_docker_config_path_ get_docker_config_path_ -- "Constructs config.json from configurable Docker directory." --> get_docker_config_dir_ run_nested_ -- "Environment checks now recognize variables defined in env files." --> is_environment_variable_defined_ run_nested_ -- "Nested containers receive configurable Docker directory and credentials." --> get_docker_config_dir_ handle_volumes_bind_mount_ -- "Mounts credentials from DOCKER_CONFIG, with home-directory fallback." --> get_docker_config_dir_ run_nested_ -- "Helm receives Docker registry credentials via HELM_REGISTRY_CONFIG." --> HELM_ classDef added stroke:#15AA7A classDef removed stroke:#CD5270 classDef modified stroke:#EDAC4C linkStyle default stroke:#CBD5E1,font-size:13pxFix nested container Docker credential discovery and mounting by updating
runner,utils, and Helm environment handling to honorDOCKER_CONFIGwhile preserving writable and read-only credential paths. Export configured push destinations throughcliforrun,make, andshell, and document the new variables.SKIPPER_REGISTRYandSKIPPER_NAMESPACEvalues to containerizedrun,make, andshellflows while allowing explicit environment entries to take precedence, and document the behavior.Modified files (3)
Latest Contributors(2)
DOCKER_CONFIG, mounting credentials from the effective host directory at writable and host-home paths, and applying precise environment overrides across Docker and Podman runtimes.Modified files (5)
Latest Contributors(2)
Customize your next review