Skip to content

CI: Docker image publish on main broken — invalid tag ":" (DOCKER_PUBLISH_CONDITION expands empty) #22425

Description

@yperbasis

The post-merge Docker publish workflow (CI-CD build and deploy docker images based on the last commit in the target branch) has been failing on every push to main since Jul 11.

This is a CI-config bug, not a code bug — all test/build merge-queue gates are green.

Symptom

The build step fails instantly with:

ERROR: failed to build: invalid tag ":": invalid reference format

The step env dump shows the cause:

DOCKER_PUBLISH_CONDITION: --tag :

i.e. it expands to --tag : with an empty repo and empty version, which buildx rejects.

Root cause

.github/workflows/ci-cd-main-branch-docker-images.yml:113:

env:
  BUILD_VERSION: "${{ ... }}"                 # line 111
  BUILD_VERSION_LATEST: "${{ ... }}"          # line 112
  DOCKER_PUBLISH_CONDITION: ${{ steps.def_docker_vars.outputs.keep_images > 0 && format(--tag {0}:{1} , env.DOCKER_URL, env.BUILD_VERSION) ||  }}  # line 113
  DOCKER_URL: ${{ env.DOCKERHUB_REPOSITORY }} # line 114

DOCKER_PUBLISH_CONDITION references env.DOCKER_URL and env.BUILD_VERSION, but both are siblings in the same step-level env: block. GitHub Actions evaluates every entry in an env: map against the environment as it existed before the block, so siblings cannot see each other — both resolve to empty and format(--tag {0}:{1} , , ) produces --tag :.

The --tag "$DOCKER_URL:$BUILD_VERSION_LATEST" (main-latest) tag on line 133 is fine — it is shell-expanded at runtime. Only the templated DOCKER_PUBLISH_CONDITION is broken.

Line 152 (BUILD_VERSION_CONDITION) has the identical sibling-reference mistake, but it only feeds an echo, so it is non-fatal.

Regression source

Commit 67a39dac82 — PR #22386 ("ci: fix zizmor template-injection in remaining QA/CD workflows"). It moved this expression out of the run: script (where the env context correctly includes step-level vars) into the env: block (where it does not).

Failing on every commit since:

2026-07-13 b887c6b95  failure
2026-07-13 b4ed135a4  failure
...
2026-07-12 4540ef19c  failure   <- first after the regression

Suggested fix

Do not reference sibling env vars — resolve from the source contexts directly (DOCKERHUB_REPOSITORY is job/workflow-level, not a sibling, so it is safe):

DOCKER_PUBLISH_CONDITION: ${{ steps.def_docker_vars.outputs.keep_images > 0 && format(--tag {0}:{1}-{2} , env.DOCKERHUB_REPOSITORY, steps.def_docker_vars.outputs.tag_name, steps.getCommitId.outputs.short_commit_id) ||  }}

Apply the same fix to BUILD_VERSION_CONDITION (line 152).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions