Private base images

When declaring the image for your base, you can only use images that can be pulled from a public Docker registry. In some cases, you may instead want to use an image from a private Docker registry, or you may want to build an image from a Dockerfile and use the built image as your base. To facilitate this, use a base call which embeds an embedded run and targets a task that extracts the image you want to use:

base:
  call: ${{ run.dir }}/build-docker-image.yml
  target: image
  config: rwx/base 1.2.0

tasks: ...

See below for examples of build-docker-image.yml.

Pulling a private image

Inside the embedded run that you call, set up the authorization necessary and then run rwx-runner image export <TAG> --pull:

# build-docker-image.yml

base:
  image: ubuntu:24.04
  config: rwx/base 1.2.0

tasks:
  - key: aws-cli
    call: aws/install-cli 1.1.0

  - key: assume-role
    call: aws/assume-role 2.1.0
    with:
      region: us-east-2
      role-to-assume: arn:aws:iam::your-account-id:role/your-role

  - key: task-that-needs-role
    use: [aws-cli, assume-role]
    docker: true
    run: |
      aws ecr get-login-password --region us-east-2 | docker login --username AWS --password-stdin "${REGISTRY_HOST}"
      rwx-runner image export "${REGISTRY_HOST}/your-repository:your-tag" --pull
    env:
      AWS_OIDC_TOKEN_PATH: ${{ vaults.your-vault.oidc.aws.path }}
      REGISTRY_HOST: your-account-id.dkr.ecr.us-east-2.amazonaws.com

Building an image from a Dockerfile

Inside the embedded run that you call, build the image and then run rwx-runner image export <TAG>:

# build-docker-image.yml

base:
  image: ubuntu:24.04
  config: rwx/base 1.2.0

tasks:
  # Typically, you would clone your repository here and use a checked-in Dockerfile
  - key: dockerfile
    run: |
      cat << EOF > Dockerfile
      FROM ubuntu:26.04
      RUN touch example.txt
      EOF

  - key: image
    use: dockerfile
    docker: true
    run: |
      docker build . -t my-tag
      rwx-runner image export my-tag

You can also use incremental Docker builds within this embedded run to dramatically decrease the amount of time it takes to build your image.