Repository navigation
Conversation
There was a problem hiding this comment.
Pull request overview
Adds configurable, tag-prefix-based ECR lifecycle rules so branch images can expire much sooner than long-lived tags, reducing storage and scan noise while keeping a longer catch-all retention.
Changes:
- Introduces
tag-ttlconfiguration to set per-tag-prefix TTLs for ECR lifecycle policies. - Adds a default TTL of 1 day for
branch--prefixed tags. - Updates documentation to describe new retention behavior and configuration.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
| plugin.yml | Adds tag-ttl configuration schema entry. |
| hooks/lib/ecr-registry-provider.bash | Builds multi-rule ECR lifecycle policy using tag-prefix TTL mappings + catch-all max age. |
| README.md | Documents default branch retention and new tag-ttl configuration. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated 5 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 6 out of 6 changed files in this pull request and generated 3 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| @@ -0,0 +1,58 @@ | |||
| validate_tag_ttl_env_vars() { | |||
| local base_var='BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_' | |||
| declare -A prefix_indices ttl_indices | |||
There was a problem hiding this comment.
This validator uses declare -A associative arrays, which requires Bash 4+. Since the hooks run under #!/usr/bin/env bash (and macOS agents commonly provide Bash 3.2), this will hard-fail with a syntax error on those environments. Consider rewriting this without associative arrays (e.g., collect indices in regular arrays / strings and check membership), or explicitly documenting/enforcing a Bash 4+ requirement for the plugin.
| log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1 | ||
| fi | ||
| done | ||
|
|
||
| for idx in "${!prefix_indices[@]}"; do | ||
| if [[ -z "${ttl_indices[$idx]:-}" ]]; then | ||
| log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1 |
There was a problem hiding this comment.
Same issue here: the message mentions TAG_TTL_${idx}_PREFIX / TAG_TTL_${idx}_TTL, but those env vars don’t exist. Please update the error to reference BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and ..._${idx}_TTL (or the corresponding tag-ttl[${idx}] config keys) so users can fix the right setting.
| log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1 | |
| fi | |
| done | |
| for idx in "${!prefix_indices[@]}"; do | |
| if [[ -z "${ttl_indices[$idx]:-}" ]]; then | |
| log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1 | |
| log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_TTL must be configured (or the corresponding tag-ttl[${idx}].prefix and tag-ttl[${idx}].ttl config keys)" 1 | |
| fi | |
| done | |
| for idx in "${!prefix_indices[@]}"; do | |
| if [[ -z "${ttl_indices[$idx]:-}" ]]; then | |
| log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_TTL must be configured (or the corresponding tag-ttl[${idx}].prefix and tag-ttl[${idx}].ttl config keys)" 1 |
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Support branch-specific image retention policies in ECR
With container scanning enabled, temporary branch images can accumulate in repositories and create noise/cost + keep vulerabilities "stuck" in teams dashboards for up to 30 days (current default), even if fixed.
Ideally, users would need to have a way to aggressively clean up branch images while maintaining longer retention for primary/master images to enable fast deployments.
This PR adds support for configurable, tag-based lifecycle policies in ECR. Allows users to specify a TTL specifically for images tagged with desired patterns, while keeping other images under the original
max-age-daysdefault policy.Changes
branch-tags (gantry standard) to1 daypattern + ttlconfiguration option to override 30 days default for custom patterns. Can specify up to 8 rules (because we have limit of 10 total and 2 defaults already)Expected benefits: