{"record":{"id":"af51e3f42b6400a9","repo":"apache/kafka","slug":"docker-image-push-failed","errorCode":null,"errorMessage":"Docker image push failed","messagePattern":"Docker image push failed","errorType":"exception","errorClass":"SystemError","httpStatus":null,"severity":"error","filePath":"docker/docker_release.py","lineNumber":49,"sourceCode":"        docker_release <image> --kafka-url <kafka_url> --image-type <type>\n\n        This command will build the multiarch image of type <type> (jvm by default),\n        named <image> using <kafka_url> to download kafka and push it to the docker image name <image> provided.\n        Make sure image is in the format of <registry>/<namespace>/<image_name>:<image_tag>.\n\"\"\"\n\nfrom datetime import date\nimport argparse\n\nfrom common import execute, build_docker_image_runner\n\ndef build_push(image, kafka_url, image_type):\n    try:\n        create_builder()\n        build_docker_image_runner(f\"docker buildx build -f $DOCKER_FILE --build-arg kafka_url={kafka_url} --build-arg build_date={date.today()} --push \\\n              --platform linux/amd64,linux/arm64 --tag {image} $DOCKER_DIR\", image_type)\n    except:\n        raise SystemError(\"Docker image push failed\")\n    finally:\n        remove_builder()\n\ndef create_builder():\n    execute([\"docker\", \"buildx\", \"create\", \"--name\", \"kafka-builder\", \"--use\"])\n\ndef remove_builder():\n    execute([\"docker\", \"buildx\", \"rm\", \"kafka-builder\"])\n\nif __name__ == \"__main__\":\n    print(\"\\\n          This script will build and push docker images of apache kafka.\\n \\\n          Please ensure that image has been sanity tested before pushing the image. \\n \\\n          Please ensure you are logged in the docker registry that you are trying to push to.\")\n    parser = argparse.ArgumentParser()\n    parser.add_argument(\"image\", help=\"Dockerhub image that you want to push to (in the format <registry>/<namespace>/<image_name>:<image_tag>)\")\n    parser.add_argument(\"--image-type\", \"-type\", choices=[\"jvm\", \"native\"], default=\"jvm\", dest=\"image_type\", help=\"Image type you want to build\")\n    parser.add_argument(\"--kafka-url\", \"-u\", dest=\"kafka_url\", help=\"Kafka url to be used to download kafka binary tarball in the docker image\")","sourceCodeStart":31,"sourceCodeEnd":67,"githubUrl":"https://github.com/apache/kafka/blob/996fb4585aa1bcc8980b0e1b8d6b168b986cd979/docker/docker_release.py#L31-L67","documentation":"docker/docker_release.py:build_push wraps the multi-arch buildx push (`--platform linux/amd64,linux/arm64 --tag ... --push`) in a bare except and re-raises SystemError('Docker image push failed'). remove_builder() runs in `finally`. Like error 115 the underlying cause is discarded by the bare except.","triggerScenarios":"The `docker buildx build ... --push` step fails - most commonly due to registry authentication, permissions on the target tag, network issues during layer push, or a build failure (which also surfaces here because build and push are one command).","commonSituations":"Not logged in to Docker Hub (`docker login`); pushing to a tag/namespace you lack push rights for; build failure on one of the two platforms; expired registry token.","solutions":["`docker login` with an account that has push rights to the target namespace, then re-run.","Verify the --tag target namespace/repo is correct and that the account is authorized.","Re-run the buildx command without --push first to confirm the build itself succeeds on both linux/amd64 and linux/arm64.","Check registry quota/rate limits; retry after a backoff if it is a transient push error."],"exampleFix":"# before\n$ python3 docker/docker_release.py\n... -> SystemError: Docker image push failed  (cause hidden)\n\n# debug\n$ docker login\n$ docker buildx build -f <DF> --build-arg kafka_url=<url> --build-arg build_date=$(date +%F) \\\n      --platform linux/amd64,linux/arm64 --tag <image> <DIR>\n# build-only run surfaces real stderr without attempting the push","handlingStrategy":"try-catch","validationCode":"import subprocess\nlogged_in = subprocess.run([\"docker\",\"logout\"], capture_output=True).returncode == 0\n# better: check `docker system info` for registry auth before pushing\nif subprocess.run([\"docker\",\"login\",\"--help\"], capture_output=True).returncode != 0:\n    raise SystemExit(\"docker login required before push\")","typeGuard":"null","tryCatchPattern":"try:\n    build_push(image, kafka_url, image_type)\nexcept SystemError:\n    print(\"push failed; run `docker login` and re-try\", file=sys.stderr)\n    raise","preventionTips":["`docker login` to the target registry before running the script.","Run the buildx build without --push first to isolate build vs push failures.","Confirm the target tag/namespace has push rights for the logged-in account."],"tags":["docker","buildx","registry","release-tools","python","tooling"],"backgroundTag":null,"analyzedSha":"996fb4585aa1bcc8980b0e1b8d6b168b986cd979","analyzedAt":"2026-08-11T22:03:28.655Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}