Repository navigation
nix: flake update command exceeds GitHub API rate limit during lock maintenance #21567
Replies: 2 comments 16 replies
|
we already do it on containerbase tests 🙃 |
16 replies
|
I'm hitting this as well using the Renovate GH on GitHub. Here's the error I'm getting: dotboris/alt#319 (comment) Full error{
"err": {
"cmd": "/bin/sh -c docker run --rm --name=renovate_a_sidecar --label=renovate_a_child -v \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\":\"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" -v \"/tmp/worker/01bb5f/8a3b67/cache\":\"/tmp/worker/01bb5f/8a3b67/cache\" -e BUILDPACK_CACHE_DIR -e CONTAINERBASE_CACHE_DIR -w \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" ghcr.io/containerbase/sidecar bash -l -c \"install-tool nix 2.16.1 && nix --extra-experimental-features nix-command --extra-experimental-features flakes --extra-access-tokens github.com=**redacted** flake update\"",
"stderr": "warning: '/nix/var/nix' does not exist, so Nix will use '/home/ubuntu/.local/share/nix/root' as a chroot store\n\r\u001b[K\r\u001b[Kerror:\n … while updating the lock file of flake 'git+file:///tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt?ref=refs/heads/main&rev=63cf88294fab30d41550010601025fdbdd209954'\n\n … while updating the flake input 'flake-utils'\n\n … while fetching the input 'github:numtide/flake-utils'\n\n error: unable to download 'https://api.github.com/repos/numtide/flake-utils/commits/HEAD': HTTP error 401\n\n response body:\n\n {\n \"message\": \"Bad credentials\",\n \"documentation_url\": \"https://docs.github.com/rest\"\n }\n",
"stdout": "[23:58:51.110] INFO (9): Installing tool nix v2.16.1...\n[23:58:51.113] INFO (9): Preparing legacy tool nix ...\ninstalling v2 tool nix v2.16\nlinking tool nix v2.16\nnix (Nix) 2.16.2\nInstalled v2 //usr/local/containerbase/tools/v2/nix.sh in 2 seconds\n[23:58:53.642] INFO (9): Installed tool nix in 2532ms.\n",
"options": {
"cwd": "/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt",
"encoding": "utf-8",
"env": {
"HOME": "/home/ubuntu",
"PATH": "/home/ubuntu/.cargo/bin:/home/ubuntu/.local/bin:/go/bin:/home/ubuntu/bin:/home/ubuntu/.npm-global/bin:/home/ubuntu/.cargo/bin:/home/ubuntu/.local/bin:/go/bin:/home/ubuntu/bin:/home/ubuntu/.npm-global/bin:/home/ubuntu/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
"LC_ALL": "C.UTF-8",
"LANG": "C.UTF-8",
"BUILDPACK_CACHE_DIR": "/tmp/worker/01bb5f/8a3b67/cache/containerbase",
"CONTAINERBASE_CACHE_DIR": "/tmp/worker/01bb5f/8a3b67/cache/containerbase"
},
"maxBuffer": 10485760,
"timeout": 900000
},
"exitCode": 1,
"name": "ExecError",
"message": "Command failed: docker run --rm --name=renovate_a_sidecar --label=renovate_a_child -v \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\":\"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" -v \"/tmp/worker/01bb5f/8a3b67/cache\":\"/tmp/worker/01bb5f/8a3b67/cache\" -e BUILDPACK_CACHE_DIR -e CONTAINERBASE_CACHE_DIR -w \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" ghcr.io/containerbase/sidecar bash -l -c \"install-tool nix 2.16.1 && nix --extra-experimental-features nix-command --extra-experimental-features flakes --extra-access-tokens github.com=**redacted** flake update\"\nwarning: '/nix/var/nix' does not exist, so Nix will use '/home/ubuntu/.local/share/nix/root' as a chroot store\n\r\u001b[K\r\u001b[Kerror:\n … while updating the lock file of flake 'git+file:///tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt?ref=refs/heads/main&rev=63cf88294fab30d41550010601025fdbdd209954'\n\n … while updating the flake input 'flake-utils'\n\n … while fetching the input 'github:numtide/flake-utils'\n\n error: unable to download 'https://api.github.com/repos/numtide/flake-utils/commits/HEAD': HTTP error 401\n\n response body:\n\n {\n \"message\": \"Bad credentials\",\n \"documentation_url\": \"https://docs.github.com/rest\"\n }\n",
"stack": "ExecError: Command failed: docker run --rm --name=renovate_a_sidecar --label=renovate_a_child -v \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\":\"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" -v \"/tmp/worker/01bb5f/8a3b67/cache\":\"/tmp/worker/01bb5f/8a3b67/cache\" -e BUILDPACK_CACHE_DIR -e CONTAINERBASE_CACHE_DIR -w \"/tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt\" ghcr.io/containerbase/sidecar bash -l -c \"install-tool nix 2.16.1 && nix --extra-experimental-features nix-command --extra-experimental-features flakes --extra-access-tokens github.com=**redacted** flake update\"\nwarning: '/nix/var/nix' does not exist, so Nix will use '/home/ubuntu/.local/share/nix/root' as a chroot store\n\r\u001b[K\r\u001b[Kerror:\n … while updating the lock file of flake 'git+file:///tmp/worker/01bb5f/8a3b67/repos/github/dotboris/alt?ref=refs/heads/main&rev=63cf88294fab30d41550010601025fdbdd209954'\n\n … while updating the flake input 'flake-utils'\n\n … while fetching the input 'github:numtide/flake-utils'\n\n error: unable to download 'https://api.github.com/repos/numtide/flake-utils/commits/HEAD': HTTP error 401\n\n response body:\n\n {\n \"message\": \"Bad credentials\",\n \"documentation_url\": \"https://docs.github.com/rest\"\n }\n\n at ChildProcess.<anonymous> (/opt/containerbase/tools/renovate/35.144.2/node_modules/renovate/lib/util/exec/common.ts:99:11)\n at ChildProcess.emit (node:events:525:35)\n at ChildProcess.emit (node:domain:489:12)\n at Process.ChildProcess._handle.onexit (node:internal/child_process:291:12)"
}
} |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Type of discussion.
I just want to chat
Tell us more.
The nix flake update command can fail during lock file maintenance due to the GitHub API rate limit:
The Nix configuration file has an option to map hosts to their auth token called access-token:
https://nixos.org/manual/nix/stable/command-ref/conf-file.html#conf-access-tokens
I suppose Renovate should pass down its GitHub token (and any other host tokens it has?) to Nix. The places where Nix reads its config are listed at the top of the above linked documentation page.
The current code:
renovate/lib/modules/manager/nix/artifacts.ts
Lines 25 to 29 in 60ac8c7
Here is a live example: parca-dev/parca-agent#1570
cc @JamieMagee
All reactions