CI: revert to container-based test job; correct the NetworkPolicy claim
CI / test (push) Failing after 2m42s
CI / test (push) Failing after 2m42s
Host-mode (previous commit) fails earlier and differently: "go: command not found" -- the runner host has no Go, so that path is dead. Checked Ryuvia/charts' act-runner/templates/networkpolicy.yaml directly rather than assuming: it's the only NetworkPolicy in the cluster, and it is explicitly deny-ingress only -- its own comment states egress is deliberately untouched, "CI pulls from registries and package indexes that are not enumerable here" (issue #128). So my earlier claim that this needs "allowlisting github.com on the runner's NetworkPolicy" was wrong: there is no in-repo egress rule governing this at all. Whatever blocks github.com from the dind bridge is outside anything Ryuvia/charts or Ryuvia/k8s expresses in a Kubernetes object -- back to container-based (matching every other Go job in this org) as the known-good shape, with `make test` left red on the envtest fetch until that's actually found.
This commit is contained in:
+25
-13
@@ -31,22 +31,34 @@ jobs:
|
||||
# and a green working copy mean the same thing by construction. `test` also drives
|
||||
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
||||
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
|
||||
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket
|
||||
# 403s now, confirmed 2026-09-30, no fallback there for k8s 1.37).
|
||||
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s
|
||||
# now for every version tried, confirmed 2026-09-30, no fallback there).
|
||||
#
|
||||
# Confirmed the hard way: running this in `container: golang:1.26.6-bookworm` hits
|
||||
# exactly the restriction terdut-server's ci.yaml already documents for
|
||||
# get.helm.sh/github.com -- TLS handshake timeout reaching github.com from the dind
|
||||
# bridge. No `container:` here, unlike every other Go job in this org's repos, on
|
||||
# the same theory as terdut-server's `chart` job (which reaches get.helm.sh only by
|
||||
# running on the host, not in a container) -- this is that same fix applied to a Go
|
||||
# job for the first time, so it additionally assumes the runner host has Go
|
||||
# available directly, which no prior workflow here has needed. If this goes red on
|
||||
# "go: command not found" rather than the envtest fetch, that assumption was wrong
|
||||
# and this needs the other fix instead (allowlist github.com's release CDN on the
|
||||
# runner's NetworkPolicy, in Ryuvia/charts or Ryuvia/k8s).
|
||||
# This currently fails in CI: TLS handshake timeout reaching github.com from inside
|
||||
# this container, same symptom terdut-server's ci.yaml already documents for
|
||||
# get.helm.sh/github.com. Two things ruled out already, so this isn't "add an
|
||||
# allowlist entry":
|
||||
# - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only
|
||||
# NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design
|
||||
# ("egress is deliberately untouched... CI pulls from registries and package
|
||||
# indexes that are not enumerable here" -- see its own comment, issue #128).
|
||||
# There is no in-repo egress rule to edit for this.
|
||||
# - Running this job on the bare runner host instead of in a container (tried and
|
||||
# reverted, same as terdut-server's `chart` job does for get.helm.sh) fails
|
||||
# earlier and differently: "go: command not found" -- the host has no Go.
|
||||
# So whatever blocks github.com from the dind bridge sits outside anything this
|
||||
# workspace's repos configure -- a firewall/DNS layer neither Ryuvia/charts nor
|
||||
# Ryuvia/k8s expresses in Kubernetes objects. `make test` fails on the envtest fetch
|
||||
# until that's found and fixed (or the binaries are vendored -- see ROADMAP.md/the
|
||||
# PR discussion for why that was declined for now).
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
- gobin-cache:/go/bin
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
|
||||
Reference in New Issue
Block a user