CI: update comment -- second MTU fix resolves the github.com timeout
CI / test (push) Successful in 1m17s

Confirmed via the actual job log (run 857, job 1931), not just the exit
code: setup-envtest fetches envtest-v1.37.0-linux-amd64.tar.gz from
github.com in ~4s now, where it previously TLS-handshake-timed-out every
time. golangci-lint's own git-clone-to-github.com (the confound from the
first fix attempt) also went through fine in the same run.

Stage 0 is now fully green end to end: fmt, lint, test (envtest included).
This commit is contained in:
Niklas Ye
2026-09-30 21:41:29 +02:00
parent 0e89816ad4
commit dd955bbf1a
+17 -23
View File
@@ -34,30 +34,24 @@ jobs:
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s
# now for every version tried, confirmed 2026-09-30, no fallback there).
#
# This currently fails in CI: TLS handshake timeout reaching github.com from inside
# this container, same symptom terdut-server's ci.yaml already documents for
# get.helm.sh/github.com. Two things ruled out already, so this isn't "add an
# allowlist entry":
# This used to fail in CI: TLS handshake timeout reaching github.com from inside
# this container (same symptom terdut-server's ci.yaml documents for
# get.helm.sh/github.com), fetching the envtest kube-apiserver/etcd binaries from
# GitHub Releases (setup-envtest v0.25's only source -- the legacy GCS
# kubebuilder-tools bucket 403s now for every version tried, no fallback there).
# History, in case it recurs:
# - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only
# NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design
# ("egress is deliberately untouched... CI pulls from registries and package
# indexes that are not enumerable here" -- see its own comment, issue #128).
# There is no in-repo egress rule to edit for this.
# - Running this job on the bare runner host instead of in a container (tried and
# reverted, same as terdut-server's `chart` job does for get.helm.sh) fails
# earlier and differently: "go: command not found" -- the host has no Go.
# - The act-runner dind sidecar's MTU (Ryuvia/charts#272, merged and reconciled
# 2026-09-30: explicit `"mtu": 1450` in its daemon.json, matching Flannel's
# VXLAN-reduced pod MTU, since dockerd's bridge networks default to 1500
# unset) -- tested against this exact failure post-fix (isolated `make test`,
# bypassing lint's own unrelated github.com flakiness) and got the identical
# "TLS handshake timeout" fetching envtest-v1.37.0-linux-amd64.tar.gz. Ruled
# out: the MTU mismatch was real but wasn't (solely) the cause of this.
# So whatever blocks github.com from the dind bridge sits outside anything this
# workspace's repos configure, and outside the MTU theory -- still unidentified as
# of 2026-09-30. `make test` fails on the envtest fetch until that's found and
# fixed (or the binaries are vendored -- see ROADMAP.md/the PR discussion for why
# that was declined for now).
# NetworkPolicy in the cluster and is deny-ingress only -- ruled out, no
# in-repo egress rule governs this.
# - Running this job on the bare runner host instead of in a container fails
# earlier and differently ("go: command not found", no Go there) -- ruled out.
# - The act-runner dind sidecar's MTU mismatch (1450 pod vs. 1500 Docker-bridge
# default) was real but an initial fix for it (Ryuvia/charts#272) did not
# resolve this specific failure when tested in isolation -- see Ryuvia/charts#271
# for that round's write-up.
# - A second attempt at the MTU fix, 2026-09-30, did resolve it: `setup-envtest`
# now fetches envtest-v1.37.0-linux-amd64.tar.gz from github.com in ~4s and
# `test` passes. Confirmed via the actual job log, not just the exit code.
test:
runs-on: ubuntu-latest
container: