diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index 197f890..ee83182 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -31,22 +31,34 @@ jobs: # and a green working copy mean the same thing by construction. `test` also drives # controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test` # chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases - # (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket - # 403s now, confirmed 2026-09-30, no fallback there for k8s 1.37). + # (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s + # now for every version tried, confirmed 2026-09-30, no fallback there). # - # Confirmed the hard way: running this in `container: golang:1.26.6-bookworm` hits - # exactly the restriction terdut-server's ci.yaml already documents for - # get.helm.sh/github.com -- TLS handshake timeout reaching github.com from the dind - # bridge. No `container:` here, unlike every other Go job in this org's repos, on - # the same theory as terdut-server's `chart` job (which reaches get.helm.sh only by - # running on the host, not in a container) -- this is that same fix applied to a Go - # job for the first time, so it additionally assumes the runner host has Go - # available directly, which no prior workflow here has needed. If this goes red on - # "go: command not found" rather than the envtest fetch, that assumption was wrong - # and this needs the other fix instead (allowlist github.com's release CDN on the - # runner's NetworkPolicy, in Ryuvia/charts or Ryuvia/k8s). + # This currently fails in CI: TLS handshake timeout reaching github.com from inside + # this container, same symptom terdut-server's ci.yaml already documents for + # get.helm.sh/github.com. Two things ruled out already, so this isn't "add an + # allowlist entry": + # - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only + # NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design + # ("egress is deliberately untouched... CI pulls from registries and package + # indexes that are not enumerable here" -- see its own comment, issue #128). + # There is no in-repo egress rule to edit for this. + # - Running this job on the bare runner host instead of in a container (tried and + # reverted, same as terdut-server's `chart` job does for get.helm.sh) fails + # earlier and differently: "go: command not found" -- the host has no Go. + # So whatever blocks github.com from the dind bridge sits outside anything this + # workspace's repos configure -- a firewall/DNS layer neither Ryuvia/charts nor + # Ryuvia/k8s expresses in Kubernetes objects. `make test` fails on the envtest fetch + # until that's found and fixed (or the binaries are vendored -- see ROADMAP.md/the + # PR discussion for why that was declined for now). test: runs-on: ubuntu-latest + container: + image: golang:1.26.6-bookworm + volumes: + - go-mod-cache:/go/pkg/mod + - go-build-cache:/root/.cache/go-build + - gobin-cache:/go/bin steps: - name: Checkout