Skip to content
Latchkey LogoLatchkey home
Latchkey Learn

Docker in CI: Registry, Build & Runtime

Docker failures that happen in CI: pulls, pushes, auth, BuildKit, runtime and platform mismatches, diagnosed with the exact fix for each one.

Registry and pulls

Auth, manifests, mirrors.

"denied: requested access"Fix denied requested access to the resource is denied on a CI push: one 403 for four situations, and only "imagetools create" failingWhen docker buildx imagetools create failed in CI, read the stage: source resolution, the copy between containerd image store offDocker containerd image store not enabled is why buildx refuses a multi-platform load, and attestations cause "insecure-registries" not setDocker insecure-registries not configured is usually an entry that misses, because the daemon matches the "invalid reference format"Fix Docker invalid reference format in GitHub Actions: the grammar a reference must match, and three ways a "manifest unknown"Fix docker manifest unknown in GitHub Actions: the repository exists and the reference does not, for one of "net/http: request canceled"Docker net/http request canceled on a pull or push is a Go client timeout, and the exact wording says the "pull access denied"Fix Docker pull access denied repository does not exist in GitHub Actions: tell a missing name from a private "manifest invalid"Fix docker push manifest invalid in CI: the registry names the media type it refused in a detail field that "repository does not exist" (ECR)Fix Docker push to ECR repository does not exist in GitHub Actions: create the repo first, or add the "unexpected status ... 401/403"A docker unexpected status code from registry is not one error: the 5xx wording, the 403 wording and the "x509: certificate signed by unknown authority"Fix Docker x509 certificate signed by unknown authority in GitHub Actions: give the daemon the CA that signed BuildKit and a plain registryAn insecure registry HTTP response to HTTPS client failure inside a build is BuildKit in a container builder,

Runtime

Exec, cgroups, platform, sockets.

"cannot enter cgroupv2"Fix Docker cannot enter cgroupv2 and the cgroup mount errors in GitHub Actions: delegate the controllers a "container name is already in use"Docker Conflict. The container name is already in use in CI means a container from an earlier step or job "device or resource busy"Fix docker device or resource busy in GitHub Actions: a mount or an open file is holding the path, and the "error during connect: docker_engine"Fix Docker error during connect docker_engine on a Windows runner in GitHub Actions: start the engine, fix "exec user process caused"Docker exec user process caused: no such file or directory in CI is a missing interpreter or loader, not a "failed to create shim task"Fix Docker failed to create shim task executable file not found in GitHub Actions: the image cannot run the "failed to create shim task"Docker failed to create shim task runtime error in CI is a chain of wrappers, not a cause. "failed to set up container networking"Fix docker failed to set up container networking in GitHub Actions: the clause after the colon names the real "does not match the specified platform"Docker image does not match the specified platform in CI means a cached single-arch image cannot serve the "read-only file system"Docker mkdir /var/lib/docker: read-only file system in CI means the daemon data root is not writable. "OCI runtime error" on /procDocker OCI runtime error container_linux mkdir /proc in CI is usually a rootfs mount refusal, not a mkdir. "OCI runtime exec failed"Fix Docker OCI runtime exec failed in GitHub Actions: the binary your docker exec named is not in the image, "permission denied ... docker.sock"Docker permission denied docker.sock in CI means the job user cannot open the daemon socket. "exec ... permission denied"Exec user process caused: permission denied in Docker CI is a missing executable bit on the entrypoint, not a "unable to configure the Docker daemon"Unable to configure the Docker daemon with file daemon.json stops dockerd before it starts.

Build and BuildKit

Dockerfile, cache, buildx.

"Attestation is not supported"Attestation is not supported for the docker driver is one of four separate refusals. "failed to receive status"Buildx failed with: failed to receive status is written by the GitHub Action, not by buildx, and the action "lstat ...: permission denied"Docker build lstat permission denied is three programs in one line, and the words lstat and permission denied "too many open files"Docker build too many open files is your program reporting EMFILE, not Docker. "buildx bake" failedA docker buildx bake failed message comes from one of four layers. "build must be a string"Docker Compose build must be a string is misleading: a mapping is equally valid. "declared as external"Fix docker compose network declared as external in GitHub Actions: Compose never creates one, so create it in "the attribute version is obsolete"Fix docker compose the attribute version is obsolete in GitHub Actions: Compose only warns and exits 0, so "COPY --from" unknown stageA docker COPY --from stage not found is not an error at all: BuildKit treats the unknown name as an image and "COPY failed: file not found"Fix docker copy failed: file not found in build context in GitHub Actions: the context, .dockerignore, and "dockerfile parse error"A docker dockerfile parse error names a line because one half of the frontend rejected it. "failed to calculate checksum"Docker failed to calculate checksum of ref is the real wording. "failed to fetch oauth token"Fix docker failed to fetch oauth token in GitHub Actions: the word in front of token says whether a "rpc error: code = Canceled"Docker failed to solve: rpc error: code = Canceled is four programs in one line, and none is reporting a "invalid file request"Docker invalid file request is the context transfer protocol losing track of a file, not a path permission or "invalid mount config"Docker invalid mount config comes from the daemon validating a container mount. "target stage could not be found"Docker target stage could not be found ignores case in the lookup but not in the hint, so a near miss gets a "--mount requires BuildKit"Fix the --mount option requires buildkit in GitHub Actions: the legacy builder refuses cache and secret
Explore other topics