Confirmed the hard way (run 852, attempt 2): setup-envtest v0.25 fetches the envtest kube-apiserver/etcd tarball from github.com's release CDN, not the legacy GCS kubebuilder-tools bucket (that bucket 403s now for any object -- no fallback there for k8s 1.37 either). github.com is unreachable from this job's container the same way terdut-server's ci.yaml already documents for get.helm.sh -- TLS handshake timeout. Dropping `container:` on this job is the same fix terdut-server's `chart` job already uses for that exact class of problem (it reaches get.helm.sh only by running on the host). Unproven for a Go job specifically -- no workflow in this org has run Go outside a container before, so this also bets the runner host has Go installed. If it fails on a missing `go` instead of the envtest fetch, that bet was wrong and the real fix is allowlisting github.com's release CDN on the runner's NetworkPolicy instead (Ryuvia/charts or Ryuvia/k8s, outside this repo).
This commit is contained in:
+15
-13
@@ -30,21 +30,23 @@ jobs:
|
||||
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
|
||||
# and a green working copy mean the same thing by construction. `test` also drives
|
||||
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
||||
# chain), which needs storage.googleapis.com to fetch the envtest kube-apiserver/etcd
|
||||
# binaries -- unconfirmed whether that host is reachable from this runner's dind
|
||||
# bridge the way proxy.golang.org and git.ryuvia.com are (terdut-server's ci.yaml
|
||||
# flags get.helm.sh and github.com as *not* reachable from here); if this job goes
|
||||
# red on the fetch specifically rather than on a real test failure, move it out of
|
||||
# `container:` the way the chart job in terdut-server's ci.yaml runs on the host
|
||||
# instead, for the same "can't reach a fetch target from the dind bridge" reason.
|
||||
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
|
||||
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket
|
||||
# 403s now, confirmed 2026-09-30, no fallback there for k8s 1.37).
|
||||
#
|
||||
# Confirmed the hard way: running this in `container: golang:1.26.6-bookworm` hits
|
||||
# exactly the restriction terdut-server's ci.yaml already documents for
|
||||
# get.helm.sh/github.com -- TLS handshake timeout reaching github.com from the dind
|
||||
# bridge. No `container:` here, unlike every other Go job in this org's repos, on
|
||||
# the same theory as terdut-server's `chart` job (which reaches get.helm.sh only by
|
||||
# running on the host, not in a container) -- this is that same fix applied to a Go
|
||||
# job for the first time, so it additionally assumes the runner host has Go
|
||||
# available directly, which no prior workflow here has needed. If this goes red on
|
||||
# "go: command not found" rather than the envtest fetch, that assumption was wrong
|
||||
# and this needs the other fix instead (allowlist github.com's release CDN on the
|
||||
# runner's NetworkPolicy, in Ryuvia/charts or Ryuvia/k8s).
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
- gobin-cache:/go/bin
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
|
||||
Reference in New Issue
Block a user