fix(ci): build with the host network until the runner resolves DNS #23
No reviewers
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
vicoli-oss/docker-forgejo-mcp!23
Loading…
Reference in a new issue
No description provided.
Delete branch "piscis/forgejo-image-ci"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Refs #22. Follow-up to #20 (#6):
cihas been red on main since #20 merged, because the build'sRUNsteps can't resolve DNS on the runner.Summary
Why the builds fail: the dind daemon has only its default bridge. Containers on that bridge, including BuildKit
RUNsteps, fall back to8.8.8.8/8.8.4.4, and DNS to those times out from the runner. With--network host,RUNsteps use the dind container's own resolver (127.0.0.11), which works. The real fix is on the runner; #22 has the details from a probe run (18).A local
make builddoesn't change:BUILD_NETWORKis empty unless set.How it was verified
f6e2437apk add git→DNS: transient errornslookuptimes out;--network hostandbuildx build --network hostresolveapk addandgit cloneran,PASS: 156 tools listedon amd64 and arm644bb73ae, PR run plus two dispatches concurrently.git/configuntil the post-job step removed it. Nowactions/checkoutlogs "Removing auth" right after the fetch, before any build step.docker loginand no--push, and the build only uses--load.GET /api/v1/packages/vicoli-oss?type=containerstill returns[]./code-reviewagainstb8d583d(all of #20 plus this PR):tonistiigi/binfmtby digest, since it runs--privilegedon the shared daemon for every PR; and the Makefile comment now says why CI setsBUILD_NETWORK.Merge Danger
Door: two-way
Revert the commit, or once #22 is fixed drop
BUILD_NETWORK=hostfromci.yml.Blast Radius: CI
Only the
ciworkflow's build step changes.RUNsteps share the dind container's network namespace, so they can reach anything listening there, including the daemon's own port. The job already has full daemon access, so for this repo's own PRs that adds little, but the workaround shouldn't become permanent (#22).