Skip to content

fix(ci): add packages:write permission to engine docker release workflows - #697

Merged
slin1237 merged 1 commit into
mainfrom
slin/fix-engine-docker-permissions
Mar 10, 2026
Merged

slin1237 merged 1 commit into
mainfrom
slin/fix-engine-docker-permissions

Conversation

@slin1237

@slin1237 slin1237 commented Mar 10, 2026 •

Copy link
Copy Markdown
Member

Summary

Fixes GHCR push failure in engine docker release workflows (sglang, vllm, trtllm).

What changed

  • Added permissions: contents: read, packages: write to release-sglang-docker.yml, release-vllm-docker.yml, release-trtllm-docker.yml

Why

The workflows failed with error from registry: installation not allowed to Write organization package because the GITHUB_TOKEN only had Packages: read. The nightly-docker.yml workflow already has this permission set correctly — this brings the engine release workflows in line.

Test plan

  • Verified nightly-docker.yml uses the same permissions pattern
  • Re-run engine docker builds after merge to confirm push succeeds

Summary by CodeRabbit

  • Chores
    • Enhanced Docker image release automation with explicit permissions configuration. Updated workflows now specify minimal required access levels for repository contents and package registry operations across all release pipelines, establishing clear security boundaries for the automated container image release infrastructure.

…lows

The engine docker workflows (sglang, vllm, trtllm) failed to push
images to GHCR with "installation not allowed to Write organization
package" because the GITHUB_TOKEN only had Packages: read.

Add permissions block with contents: read and packages: write to
all three workflows, matching the nightly-docker.yml pattern.

Signed-off-by: Simo Lin <linsimo.mark@gmail.com>
@github-actions github-actions Bot added the ci CI/CD configuration changes label Mar 10, 2026
@slin1237
slin1237 merged commit a68278a into main Mar 10, 2026
10 of 12 checks passed
@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: e1409422-b019-40ae-98cd-acf741955d66

📥 Commits

Reviewing files that changed from the base of the PR and between 4b03d32 and e21e802.

📒 Files selected for processing (3)
  • .github/workflows/release-sglang-docker.yml
  • .github/workflows/release-trtllm-docker.yml
  • .github/workflows/release-vllm-docker.yml

📝 Walkthrough

Walkthrough

Adds a top-level permissions block to three Docker release GitHub Actions workflows, explicitly granting read access to repository contents and write access to container packages. This enables the workflows to authenticate with the container registry for pushing Docker images.

Changes

Cohort / File(s) Summary
Docker Release Workflow Permissions
.github/workflows/release-sglang-docker.yml, .github/workflows/release-trtllm-docker.yml, .github/workflows/release-vllm-docker.yml
Added identical top-level permissions block granting contents: read and packages: write to enable container registry authentication across all three Docker release workflows.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

Suggested labels

ci, docker

Suggested reviewers

  • CatherineSue
  • key4ng
  • XinyueZhang369

Poem

🐰 Hop, hop, hooray! ✨
Three workflows aligned in harmony,
Permissions granted with clarity,
Docker images now run so free,
Registry doors unlocked to be! 🐇

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch slin/fix-engine-docker-permissions

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@slin1237
slin1237 deleted the slin/fix-engine-docker-permissions branch March 10, 2026 15:50
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant