Skip to content

fix(ecr): push sandbox-runner image to synapseai-codeapi-sandbox-runner - #1

Merged
amos-maganyane merged 1 commit into
mainfrom
fix/ecr-sandbox-runner-repo-name
Sep 23, 2026
Merged

amos-maganyane merged 1 commit into
mainfrom
fix/ecr-sandbox-runner-repo-name

Conversation

@amos-maganyane

Copy link
Copy Markdown

Problem

synapseai-codeapi-sandbox-runner-deploy never started on the DEV deployment because its image does not exist in ECR. The image builds fine — only the push failed, every run:

#58 [sandbox-runner 1/3] COPY --from=sandbox-build / /sandbox-rootfs/   DONE 5.7s
#61 exporting manifest sha256:863756fd... done
ERROR: failed to push 323463077991.dkr.ecr.af-south-1.amazonaws.com/synapseai-codeapi-sandbox:ff5c770:
  unknown: The repository with name 'synapseai-codeapi-sandbox' does not exist in the registry with id '323463077991'

Evidence (GitHub Actions):

run commit result
35335263009 ff5c770 sandbox failure, package-init failure; other 5 green
35223475558 6b0af13 sandbox failure; other 5 green
35212138323 b29ec82 sandbox failure; other 5 green

The Enviro ECR placeholder for this image is synapseai-codeapi-sandbox-runner, but this matrix row pushed to synapseai-codeapi-sandbox, which does not exist in account 323463077991. synapseai-codeapi-package-init failed the same way and its repo now exists.

Change

Align the push target with the repo that exists: synapseai-codeapi-sandbox-runner.

The consumer is updated in lockstep — hydra/synapseai specs/dev/code-intepreter.yaml pulls the same name.

Not in this PR

  • Repo must exist before the build runs. docker push cannot create an ECR repo; synapseai-codeapi-sandbox-runner must be created in 323463077991 (and in the destination registry 245094849113 for the sync job).
  • The deploy tag moves. Because this file changes, the next build's SHA is a new commit, so CODEAPI_IMAGE_TAG in hydra/synapseai must be set to that new short SHA (it currently pins 6b0af13, which predates both the no-KVM sandbox-runner target and the package-init row).
  • Manifest signing keys. ENC[{CODEAPI_MANIFEST_PUBLIC_KEY_ENC}] / ENC[{CODEAPI_MANIFEST_PRIVATE_KEY_ENC}] in code-intepreter.yaml are never substituted by CI, so with CODEAPI_HARDENED_SANDBOX_MODE=true and SANDBOX_REQUIRE_EGRESS_MANIFEST=true, sandbox execution fails signature verification even once the image exists.
  • ReadWriteOnce packages PVC. The package-init Job and the runner Deployment both mount synapseai-codeapi-sandbox-packages (ReadWriteOnce); whichever pod attaches first blocks the other.

Why not reuse an existing image

There is no substitute. The synapseai-codeapi-worker image was temporarily used for both services and reverted in fd68789 ("correct images are needed") — neither service can run the worker image.

Note on the image target

--target sandbox-runner (directory root) is correct for Momentum: nodes are m5 (Xen) with no /dev/kvm, so the baked/KVM target is unusable and packages come from the PVC via the package-init Job.

…runner repo

The Enviro ECR placeholder for the NsJail sandbox-runner is named
synapseai-codeapi-sandbox-runner, but this matrix row pushed to
synapseai-codeapi-sandbox, which does not exist in account 323463077991.
The image builds fine; only the push failed:

  ERROR: failed to push .../synapseai-codeapi-sandbox:ff5c770:
    The repository with name 'synapseai-codeapi-sandbox' does not exist
    in the registry with id '323463077991'

Align the push target with the repo that exists. The deploy spec
(hydra/synapseai specs/dev/code-intepreter.yaml) is updated to pull the
same name.
@amos-maganyane
amos-maganyane merged commit 89775f8 into main Sep 23, 2026
10 checks passed
@amos-maganyane
amos-maganyane deleted the fix/ecr-sandbox-runner-repo-name branch September 23, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant