Skip to content

pass: docker login does not work after rotating gpg key #299

Description

@nicks

Repro steps:

  • Store a login cred:
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin 123456789.dkr.ecr.us-east-1.amazonaws.com
  • Rotate your gpg key
  • Re-store the login cred with the same command as step 1

Expected result:
The creds are stored successfully

Actual result:
The old credentials can't be decrypted, so the credential helper fails with gpg: decryption failed: No secret key

Activity

  1. nicks commented on Oct 16, 2023

    @nicks
    ContributorAuthor

    Note that there are other issues with this error message - e.g., #118

    but it wasn't clear to me if they're the same issue

  2. nicks commented on Oct 16, 2023

    @nicks
    ContributorAuthor

    i actually think this is kind of an interop issue between docker-credential-helpers and DD, where DD is assuming that if the credential has a decryption error, it means the credential store is corrupted somehow, and so prevents the Store()

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions