Conversation
Dockerfile git sources such as `ADD https://github.com/org/repo.git#ref` are fetched by buildkitd, which ignores any gitconfig and only authenticates with the GIT_AUTH_TOKEN[.<host>] session secret. linuxkit attached no secrets provider, so these fetches, and their submodules, were always anonymous. GitHub intermittently refuses anonymous fetches, failing package builds. Add a repeatable --secret flag using the buildx/buildctl syntax (id=X,env=VAR or id=X,src=PATH) and attach buildkit's secrets provider, like --ssh does for agent forwarding. This also makes secrets available to RUN --mount=type=secret. Unlike buildx, an env source that is unset or empty is an error: buildkit would otherwise send an empty git token and fail with an unrelated auth error. Signed-off-by: Paul Gaiduk <paulg@zededa.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
4 of 7 tasks
eriknordmark
reviewed
Oct 1, 2026
| if typ == "env" && env == "" { | ||
| env = src | ||
| } | ||
| if env == "" { |
Contributor
There was a problem hiding this comment.
A bare --secret id=GIT_AUTH_TOKEN (no env=/src=) skips this check, but buildkit's secretsprovider.NewStore falls back to os.LookupEnv(id) and uses the variable if it is set, even when empty. So on a fork PR where GIT_AUTH_TOKEN expands to "" this still sends an empty token. Could you also handle the case where env and src are both empty and the variable named by id is set but empty? (If it is unset, NewStore treats id as a file path and fails on the stat, which is fine.)
Contributor
|
@deitch could you take a look at this one? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
- What I did
Added a repeatable
--secretflag tolinuxkit pkg build(and sopkg push), using the buildx/buildctl syntax:id=X,env=VARorid=X,src=PATH.The motivation is Dockerfile git sources such as
ADD https://github.com/org/repo.git#ref. buildkitd fetches these itself, running git with a cleared environment andHOME=/dev/null, so the caller's gitconfig and credential helpers never apply. The only way to authenticate them is theGIT_AUTH_TOKEN[.<host>]session secret, and linuxkit attached no secrets provider, so these fetches and their recursive submodules were always anonymous. GitHub intermittently refuses anonymous fetches from busy CI IPs, which fails package builds withcould not read Username for 'https://github.com'. This hits packages with many submodules (edk2) especially hard. The flag also makes secrets available toRUN --mount=type=secret.- How I did it
Plumbed the flag through the build options the same way
--sshis plumbed:pkg_build.go→pkglib.WithSecrets→spec.ImageBuildOptions.Secrets.dockerimpl.gothen attaches buildkit's secrets provider, using the vendoredbuild.ParseSecretparser from buildctl.Unlike buildx, a secret sourced from an environment variable that is unset or empty is an error. Otherwise buildkit would send an empty git token and fail with an unrelated auth error. In GitHub Actions, secrets that are unavailable to a job, such as on fork PRs, expand to an empty string.
Secrets don't affect the package hash or tag.
- How to verify it
A package whose Dockerfile does
ADD https://github.com/<private-repo>.git#<ref>:linuxkit pkg build .fails withcould not read Username for 'https://github.com'GITHUB_TOKEN=... linuxkit pkg build --secret id=GIT_AUTH_TOKEN.github.com,env=GITHUB_TOKEN .succeedsRUN --mount=type=secret,id=probesees a second--secret id=probe,src=<file>env=source fails withenvironment variable X is unset or empty- Description for the changelog
linuxkit pkg buildaccepts--secretto expose buildkit secrets to builds, e.g. to authenticate Dockerfile git sources.🤖 Generated with Claude Code