Conversation
Every backup since 2026-09-12 has failed, in this repository and in every
repository that calls this workflow. The `S3 Backup` step was
peter-evans/s3-backup, a Docker action whose Dockerfile starts
`FROM minio/mc:RELEASE.2022-05-04T06-07-55Z`. The self-hosted runner rebuilds
that image on every run, and Docker Hub now refuses the anonymous pull of that
2022 tag:
ERROR: failed to build: failed to solve:
minio/mc:RELEASE.2022-05-04T06-07-55Z: pull access denied, repository does
not exist or may require authorization: insufficient_scope
The build is step 3 of 8, so checkout, credentials and the backup itself all
report `skipped` and no object is written. Nothing in any of these repositories
changed on 2026-09-12 — the failure arrived without a commit, which is why it
went unnoticed for days.
Authenticating the pull would fix the symptom and leave the dependency. This
removes it: the AWS CLI is already on these runners and already reads the
credentials `Configure AWS credentials` exports two steps up, which is how
narrative-marketplace-backend's `aws s3 cp` steps work on the same runners.
`--delete` reproduces mc's `--remove`; the date-stamped prefix means each run
writes into an empty one regardless.
The trailing `aws s3 ls --summarize` prints an object count, so a reader can
tell from the run log alone that the backup wrote something. That is the check
`AUD-OPS-05` asks for and could not previously make without an AWS credential.
Fixes narrative-io/mintlify-docs#824
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
aws s3 sync instead of a Docker Hub pullaws s3 sync instead of a Docker Hub pull [sc-71258]
Root cause confirmed: the image was withdrawn, not gatedFiled as SC-71258, related to SC-71065 — which hit the sibling image Verified directly rather than inferred from the error string:
Both requests left the same IP. A rate limit is a 429 carrying quota headers — this never reaches a quota check, and alpine pulled fine alongside it with 98/100 remaining. This rules out one of the alternatives in the filed issue. Adding The failure is org-wide, not one repositoryEvery repository that calls this workflow. Run history across all 88 callers:
82 distinct repositories have failed at least once since 2026-09-12, and zero have succeeded. The org has taken no offsite copy for four consecutive mornings. Note that merging this alone fixes nothing: each caller pins this workflow by SHA, so the rollout is 88 SHA bumps. That is tracked in SC-71258 and is the bulk of the work. 🤖 Generated with Claude Code |
|
Closing in favour of a central backup: narrative-security's github-backup.yml (narrative-io/narrative-security#110) now backs up every repository as a git bundle, so the shared backup.yml is being removed rather than fixed. Thanks for tracking down the Docker Hub root cause. |
Ticket: SC-71258 · Audit issue: narrative-io/mintlify-docs#824 · Related: SC-71065
The failure
Every run of this workflow has failed since 2026-09-12 — here, and in every repository that calls it.
narrative-io/mintlify-docshas taken no offsite copy for four days:peter-evans/s3-backupis a Docker action whoseDockerfile:1isFROM minio/mc:RELEASE.2022-05-04T06-07-55Z. The self-hosted runner rebuilds that image on every run, and Docker Hub now refuses the anonymous pull of that 2022 tag:The image build is step 3 of 8, so
actions/checkout,Configure AWS credentialsandS3 Backupitself are allskippedand nothing is written:No commit landed in any of these repositories on 2026-09-12. The failure is external to the workflow, which is why it arrived silently.
The fix
Drop the action and use the AWS CLI directly.
Authenticating the pull (
docker/login-action) would fix today's symptom and keep the dependency; forking the action onto a currentminio/mctag defers it to the next tag Docker Hub stops serving anonymously. Neither is worth carrying for onesync.The CLI is already installed on these runners and already reads the credentials
Configure AWS credentialsexports two steps up —narrative-marketplace-backend'scontrol-plane-workflow-dsl-docs.ymldoes bareaws s3 cponruns-on: self-hostedbehind the sameconfigure-aws-credentials@e6de0542step, and its last five runs all succeeded. That also makes theACCESS_KEY_ID/SECRET_ACCESS_KEYenv plumbing (and its comment about which outputs the credentials action really exposes) unnecessary, so it goes too.Behaviour is unchanged:
--deleteis mc's--remove, and--overwritehas no counterpart becausesyncreplaces anything whose size or mtime differs and the target prefix is date-stamped, so each run writes into an empty prefix regardless.aws s3 sync .includes.git/, asmc mirrordid — which is whatpersist-credentials: falseon the checkout is guarding.The one addition is the trailing
aws s3 ls --recursive --summarize, which puts an object count in the log.AUD-OPS-05asks whether a scheduled backup "did the thing its name promises"; until now that could only be answered with an AWS credential, and the audit that filed this has none.Verification
actionlint(which shellchecks the newrun:block) — clean across all four workflowszizmor --persona=regular—No findings to report, no suppression addedgh workflow run backup-daily.yml -R narrative-io/common-githubexercises this repository's own caller; the run should concludesuccess, itsS3 Backupstep should not beskipped, and the object count should print.Fixes narrative-io/mintlify-docs#824
🤖 Generated with Claude Code