According to the documentation of this Atlassian organization owned pipe atlassian/aws-ecr-push-image, nothing suggests that the "latest" tag must exist when not attempting to push it, but in practice it seems mandatory.
The following script step:
- export IMAGE_NAME=my/image
- docker build -t $IMAGE_NAME:example .
- export TAGS=example
- pipe: atlassian/aws-ecr-push-image:1.6.2
variables:
AWS_OIDC_ROLE_ARN: "<ARN>"
IMAGE_NAME: "$IMAGE_NAME"
TAGS: example
fails with this error:
INFO: Authenticating with a OpenID Connect (OIDC) Web Identity Provider
INFO: Executing the aws-ecr-push-image pipe...
INFO: Successfully logged in to https://***.dkr.ecr.us-east-1.amazonaws.com
✖ Image not found: 404 Client Error for http://host.docker.internal:2375/v1.41/images/my/image/json: Not Found ("no such image: my-image: No such image: my/image:latest")
^ it does not seem sensible that the pipe is looking for the "latest" tag at all when we clearly set it to push tag "example" only.
If we also tag the image with "latest" before calling the pipe, the push completes successfully:
- export IMAGE_NAME=my/image
# need to also tag as "latest":
- docker build -t $IMAGE_NAME:latest -t $IMAGE_NAME:example .
- export TAGS=example
- pipe: atlassian/aws-ecr-push-image:1.6.2
variables:
AWS_OIDC_ROLE_ARN: "<ARN>"
IMAGE_NAME: "$IMAGE_NAME"
TAGS: example
We think this is a bug: if the "latest" tag is not specified in "variables.TAGS", it should not be mandatory for the tag to be set in local docker registry.
Please forward this feedback to the Atlassian developer(s) of this pipe.