ci: drop the BUILD_NETWORK=host workaround, the runner resolves DNS again #24

Merged
piscis merged 1 commit from piscis/forgejo-image-ci into main 2026-09-30 15:11:59 +00:00
Owner

Closes #22. Reverts the workaround from #23: the runner's firewall was blocking outbound DNS (UDP port 53), and that's fixed now.

Summary

 # Makefile
-BUILD_NETWORK ?=
 build:
-  docker buildx build --platform "$$p" $(if $(BUILD_NETWORK),--network "$(BUILD_NETWORK)") \
+  docker buildx build --platform "$$p" \

 # .forgejo/workflows/ci.yml
-  - run: make build IMAGE="$IMAGE" BUILD_NETWORK=host
+  - run: make build IMAGE="$IMAGE"

The Makefile is back to what #20 merged. #23's other two changes stay: persist-credentials: false and the digest-pinned tonistiigi/binfmt.

How it was verified

Case Run Result
Before the firewall fix, default network 14–17 red: apk add git → DNS: transient error
After: this PR's head 44f8614, the PR run plus two concurrent dispatches 25, 26, 27 all green. The build's RUN steps didn't use --network host, so their cache didn't apply: apk add ran for amd64 and arm64 (26 packages per run), no DNS: errors, PASS: 156 tools listed on both architectures

Merge Danger

Door: two-way

If the firewall blocks port 53 again, CI goes red at apk add. Reverting this PR brings the workaround back.

Blast Radius: CI

Only ci's build step changes. Build steps no longer share the dind container's network namespace, which removes the extra path to the daemon that #23 opened.

Closes #22. Reverts the workaround from #23: the runner's firewall was blocking outbound DNS (UDP port 53), and that's fixed now. ## Summary ```diff # Makefile -BUILD_NETWORK ?= build: - docker buildx build --platform "$$p" $(if $(BUILD_NETWORK),--network "$(BUILD_NETWORK)") \ + docker buildx build --platform "$$p" \ # .forgejo/workflows/ci.yml - - run: make build IMAGE="$IMAGE" BUILD_NETWORK=host + - run: make build IMAGE="$IMAGE" ``` The Makefile is back to what #20 merged. #23's other two changes stay: `persist-credentials: false` and the digest-pinned `tonistiigi/binfmt`. ## How it was verified | Case | Run | Result | |---|---|---| | Before the firewall fix, default network | [14](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/14)–[17](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/17) | **red**: `apk add git` → `DNS: transient error` | | After: this PR's head `44f8614`, the PR run plus two concurrent dispatches | [25](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/25), [26](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/26), [27](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/27) | all green. The build's `RUN` steps didn't use `--network host`, so their cache didn't apply: `apk add` ran for amd64 and arm64 (26 packages per run), no `DNS:` errors, `PASS: 156 tools listed` on both architectures | ## Merge Danger **Door:** two-way If the firewall blocks port 53 again, CI goes red at `apk add`. Reverting this PR brings the workaround back. **Blast Radius:** CI Only `ci`'s build step changes. Build steps no longer share the dind container's network namespace, which removes the extra path to the daemon that #23 opened.
Revert BUILD_NETWORK=host in ci: the runner resolves DNS again (#22)
All checks were successful
ci / build (pull_request) Successful in 15s
44f8614e7a
The runner's firewall blocked outbound UDP on port 53, so containers on
the dind daemon's bridge couldn't reach their fallback resolvers. With
that fixed, builds use the daemon's default network again, and the
Makefile no longer needs BUILD_NETWORK.
piscis merged commit d37146b40d into main 2026-09-30 15:11:59 +00:00
piscis deleted branch piscis/forgejo-image-ci 2026-09-30 15:11:59 +00:00
Sign in to join this conversation.
No description provided.