A Complete Documentation Of How I Fixed GitHub Actions Docker Push to ECR Failing for Netflix Clone Deployment
My project is a full Netflix clone: netflix_backend (Node.js API) and netflix_frontend (React). Code is on GitHub at netflix project folder. Goal is automatic deployment: every time I push to main branch, GitHub Actions should build Docker images and push to AWS ECR in us-east-1, then my EC2 server at sirvickcloud9.online pulls and runs them.
I set up .github/workflows/cicd.yaml with a job called build-and-push. Workflow looked fine in VS Code, but in GitHub Actions log, it failed at Step 4: Docker push.
The log showed: denied: Your authorization token has expired OR failed to push 4144...dkr.ecr.us-east-1.amazonaws.com/netflix_frontend:latest
I spent 4 hours debugging with fuel running.
My folder structure that caused problem:
netflix project/
.git (main repo)
netflix_backend/
.git (old nested - DELETE THIS)
Dockerfile
netflix_frontend/
Dockerfile
.github/
workflows/
cicd.yaml (CORRECT place - root)
Dockerfile
Two problems:
Nested .git: When I copied netflix_backend from another laptop, it came with its own .git. So inside my main repo, there was another repo. GitHub Actions checkout was confused. It would checkout root but the backend path still had its own git history. That's why in my screenshot you see me running rm -rf .git inside netflix_backend. I had to delete nested git.bash
cd netflix_backend
rm -rf .git
cd ..
Now only one .git at C:/netflix project root.
Wrong Dockerfile path and ECR tag:
My cicd.yaml was inside netflix_frontend/.github/workflows/ instead of root .github/workflows/. And my docker tag command was using netflix_frontend:latest to tag but pushing to netflix repo, not netflix_frontend repo. ECR is strict — tag name must match repo name exactly or it denies.The working cicd.yaml that finally pushed (Day 11 fix):
I moved file to root: netflix project/.github/workflows/cicd.yaml
name: Netflix CICD to ECR
on:
push:
branches: [ main ]
jobs:
build-and-push:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v2
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_KEY }}
aws-region: us-east-1
- name: Login to Amazon ECR
run: |
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin xxxx.dkr.ecr.us-east-1.amazonaws.com
- name: Build and Push Backend
run: |
docker build -t netflix_backend:latest ./netflix_backend
docker tag netflix_backend:latest xxxx.dkr.ecr.us-east-1.amazonaws.com/netflix_backend:latest
docker push xxxx.dkr.ecr.us-east-1.amazonaws.com/netflix_backend:latest
- name: Build and Push Frontend
run: |
docker build -t netflix_frontend:latest ./netflix_frontend
docker tag netflix_frontend:latest xxxx.dkr.ecr.us-east-1.amazonaws.com/netflix_frontend:latest
docker push xxxx.dkr.ecr.us-east-1.amazonaws.com/netflix_frontend:latest
After this fix, GitHub Actions turned green. Build took 3 mins 12 secs, both images pushed to ECR. My EC2 then pulls with docker pull and runs on port 3000 behind Nginx. If you are getting denied or authorization token expired when pushing to ECR from GitHub Actions, check these 3 things first before you recreate IAM user:
- Run rm -rf .git in any subfolder that was copied
- Make sure cicd.yaml is in root .github/workflows/, not inside frontend
- Your ECR repo must exist first in AWS console, and tag must match exactly: repo-name:latest
This is real error from my VS Code screenshot attached. No ChatGPT fix — I burned data and fuel for it in PH.
I will also let you know How I set up Nginx reverse proxy for this Docker deployment on Amazon Linux 2026 for sirvickcloud9.online.Live demo: sirvickcloud9.online | Full logs: sirvick-deployments.blogspot.com
Read also: How I Hosted My DevOps Portfolio Like a Real Cloud Engineer https://sirvick-deployments.blogspot.com/2026/10/day-10-from-32196145763000-to.html
Comments
Post a Comment