From 2591a07a4fe9c5bb89f23917ffb7ac03a8223d53 Mon Sep 17 00:00:00 2001 From: Gildas Garcia <1122076+djhi@users.noreply.github.com> Date: Tue, 23 Jun 2026 10:30:04 +0200 Subject: [PATCH] chore: Login to Docker Hub in e2e CI workflow to avoid rate limiting (#47091) ## Problem As the e2e workflow starts the Supabase CLI, it downloads all our images from the AWS ECR for every run. This makes many anonymous pulls that are rate limited. ## Solution Authenticate on AWS ECR ## Summary by CodeRabbit ## Chores * Updated the Studio E2E test workflow to include AWS ECR authentication. The workflow now uses tightened job permissions and conditionally authenticates with AWS and Docker registries to reliably pull required container images while improving security. --- .github/workflows/studio-e2e-test.yml | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/.github/workflows/studio-e2e-test.yml b/.github/workflows/studio-e2e-test.yml index 46e85ec2ae3..d25cb2e758c 100644 --- a/.github/workflows/studio-e2e-test.yml +++ b/.github/workflows/studio-e2e-test.yml @@ -23,7 +23,8 @@ jobs: tests_ran: ${{ steps.filter.outputs.studio == 'true' }} permissions: - contents: write + contents: read + id-token: write env: OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} @@ -83,6 +84,18 @@ jobs: if: steps.filter.outputs.studio == 'true' run: rm -rf supabase && pnpm exec supabase init && mkdir supabase/functions + # Authenticate with AWS ECR to avoid rate limiting + - name: configure aws credentials + if: steps.filter.outputs.studio == 'true' + uses: aws-actions/configure-aws-credentials@5fd3084fc36e372ff1fff382a39b10d03659f355 # v2.2.0 + with: + role-to-assume: ${{ secrets.PROD_AWS_ROLE }} + aws-region: us-east-1 + - uses: docker/login-action@465a07811f14bebb1938fbed4728c6a1ff8901fc # v2.2.0 + if: steps.filter.outputs.studio == 'true' + with: + registry: public.ecr.aws + - name: Pre-start diagnostics run: | docker ps -a