# Snyk container test times out pulling a large ML image

## TL;DR

Pre-pull the image with `docker pull` before running `snyk container test`, so the scan reads the image from the local Docker daemon instead of pulling it through snyk's own shorter timeout. Snyk's internal pull has no layer resume and a hard timeout, so a 6GB ML image fails identically on every retry. Pulling once with the Docker daemon, which resumes interrupted layers, turns three doomed retries into one working scan.

## The failure

```text
snyk container test: image pull timed out before the scan could start
(repeated 3x with identical failures, 6GB ML image, no scan results produced)
```

## Steps

1. Pre-pull the image with the Docker daemon: run `docker pull [REGISTRY]/[IMAGE]:[TAG]`. Expected: every layer reports download complete and the pull finishes, even if it takes a while.

2. Run the scan against the local image: run `snyk container test [REGISTRY]/[IMAGE]:[TAG]` using the exact same reference string. Expected: snyk resolves the image from the local daemon and the test completes without attempting a new pull.

3. If the pull itself stalls, check daemon disk space and network, then retry the pull rather than the scan. Expected: the second pull finishes quickly because completed layers are cached and only missing layers download.

4. For recurring CI runs, cache the pulled image in the runner or split the scan so the ML layers are scanned once. Expected: the scan step drops under 10 minutes on warm cache.

## Use this when

- `snyk container test` dies during the pull phase on images over roughly 2GB
- the agent retried the same failing scan multiple times with identical timeouts
- CI runners with slow or flaky network hit registry timeouts on large layers
- ML images with CUDA or model-weight layers that make pulls take 15+ minutes

## Not for this skill when

- the pull succeeds but the scan itself errors (that is a different problem)
- the registry rejects the pull with "unauthorized" (fix credentials, not timeouts)
- you cannot pull the image locally at all (no local daemon access)
- the timeout happens on tiny images (look at DNS or proxy issues instead)

## Variant phrasings

- snyk container scan times out downloading a large image
- snyk test on a big docker image keeps failing during pull
- snyk container test exceeded its timeout pulling an ML image

## Why it happens

Snyk container test pulls the image with its own internal timeout budget and no layer resume. A 6GB ML image (CUDA layers, model weights, framework deps) exceeds that budget on a normal network, and retrying the scan restarts the exact same doomed pull from zero. Docker's own pull resumes interrupted layers and reports progress, so pre-pulling decouples the slow part from the scan's timeout. The scan then becomes a pure local analysis step.

## Edge cases

- Pre-pulling a mutable tag can scan different content than CI built. Pin a digest for repeat runs when the exact bytes matter.
- Snyk may still attempt a pull if the local image reference does not match exactly. Use identical reference strings for pull and test.
- On runners without a Docker daemon (remote builders), push the image to a registry the runner can reach quickly instead of pre-pulling.
- Corporate proxies can slow layer downloads enough that even `docker pull` times out. Set the daemon's proxy config and retry before blaming snyk.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_292m1ZuWgCj2IS0HQzZ-pQ
