diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index d79361a..197f890 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -30,21 +30,23 @@ jobs: # `make fmt lint test` is exactly what a developer runs locally, so a green job here # and a green working copy mean the same thing by construction. `test` also drives # controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test` - # chain), which needs storage.googleapis.com to fetch the envtest kube-apiserver/etcd - # binaries -- unconfirmed whether that host is reachable from this runner's dind - # bridge the way proxy.golang.org and git.ryuvia.com are (terdut-server's ci.yaml - # flags get.helm.sh and github.com as *not* reachable from here); if this job goes - # red on the fetch specifically rather than on a real test failure, move it out of - # `container:` the way the chart job in terdut-server's ci.yaml runs on the host - # instead, for the same "can't reach a fetch target from the dind bridge" reason. + # chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases + # (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket + # 403s now, confirmed 2026-09-30, no fallback there for k8s 1.37). + # + # Confirmed the hard way: running this in `container: golang:1.26.6-bookworm` hits + # exactly the restriction terdut-server's ci.yaml already documents for + # get.helm.sh/github.com -- TLS handshake timeout reaching github.com from the dind + # bridge. No `container:` here, unlike every other Go job in this org's repos, on + # the same theory as terdut-server's `chart` job (which reaches get.helm.sh only by + # running on the host, not in a container) -- this is that same fix applied to a Go + # job for the first time, so it additionally assumes the runner host has Go + # available directly, which no prior workflow here has needed. If this goes red on + # "go: command not found" rather than the envtest fetch, that assumption was wrong + # and this needs the other fix instead (allowlist github.com's release CDN on the + # runner's NetworkPolicy, in Ryuvia/charts or Ryuvia/k8s). test: runs-on: ubuntu-latest - container: - image: golang:1.26.6-bookworm - volumes: - - go-mod-cache:/go/pkg/mod - - go-build-cache:/root/.cache/go-build - - gobin-cache:/go/bin steps: - name: Checkout