Prune stale ephemeral Docker Hub tags weekly - #349
Merged
Merged
Conversation
CI pushes a unique image tag per run — `test-<sha>` on every push to main, `test-<model_slug>-<run_id>` per PR smoke test — and a `dev-<branch>` tag per branch. Nothing ever deletes them, so the repository has accumulated 211 tags, 112 of them ephemeral leftovers. Add scripts/prune_docker_tags.py plus a weekly workflow that removes `test-*` / `dev-*` tags not updated in the last 14 days. Releases (`v1.2.3` / `1.2.3`) and `latest` match no configured prefix, so they are protected by construction; an empty prefix is rejected outright since it would match every tag. Deletes go through the Docker Hub API (there is no native retention policy), using the existing DOCKERHUB_USERNAME / DOCKERHUB_TOKEN secrets. The workflow also supports manual runs with a `dry_run` input to preview the deletion list.
colin99d
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CI pushes a unique image tag per run and nothing ever deletes them:
test-<sha>on every push to main,test-<model_slug>-<run_id>per PR smoke test, anddev-<branch>per branch. The repo currently holds 211 tags, 112 of them ephemeral leftovers (verified live via dry run).scripts/prune_docker_tags.py— deletestest-*/dev-*tags not updated in the last--min-age-days(default 14) via the Docker Hub API (there is no native tag-retention policy). Releases (v1.2.3/1.2.3) andlatestmatch no configured prefix, so they are protected by construction.--dry-runneeds no credentials..github/workflows/prune-docker-tags.yml— weekly schedule (Mondays 04:17 UTC) plusworkflow_dispatchwithmin_age_daysanddry_runinputs. Reuses the existingDOCKERHUB_USERNAME/DOCKERHUB_TOKENsecrets.tests/test_prune_docker_tags.py— unit tests plus an end-to-end run against a local stub Docker Hub server that records real HTTP traffic.docs/conventions.mdand.github/CONTRIBUTING.md.Safety
--prefixpreviously madename.startswith("")true for every tag, releases included — now rejected before any network call.Test plan
python -m pytest tests→ 114 passed (on this branch'sorigin/mainbase).runpod/worker-v1-vllm→ 211 tags, 112 candidates, releases preserved.dry_run: trueto confirm the CI path and secret scope before the first real deletion.Note: the delete path is exercised against a stub server, not the real API (no credentials in the dev environment), and the schedule only arms once this lands on the default branch.
DOCKERHUB_TOKENmust carry delete scope on the repository.