From dd955bbf1a78003e5856600860b6133ffa895e2b Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Wed, 30 Sep 2026 21:41:29 +0200 Subject: [PATCH] CI: update comment -- second MTU fix resolves the github.com timeout Confirmed via the actual job log (run 857, job 1931), not just the exit code: setup-envtest fetches envtest-v1.37.0-linux-amd64.tar.gz from github.com in ~4s now, where it previously TLS-handshake-timed-out every time. golangci-lint's own git-clone-to-github.com (the confound from the first fix attempt) also went through fine in the same run. Stage 0 is now fully green end to end: fmt, lint, test (envtest included). --- .gitea/workflows/ci.yaml | 40 +++++++++++++++++----------------------- 1 file changed, 17 insertions(+), 23 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index 7b85f3a..6247e88 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -34,30 +34,24 @@ jobs: # (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s # now for every version tried, confirmed 2026-09-30, no fallback there). # - # This currently fails in CI: TLS handshake timeout reaching github.com from inside - # this container, same symptom terdut-server's ci.yaml already documents for - # get.helm.sh/github.com. Two things ruled out already, so this isn't "add an - # allowlist entry": + # This used to fail in CI: TLS handshake timeout reaching github.com from inside + # this container (same symptom terdut-server's ci.yaml documents for + # get.helm.sh/github.com), fetching the envtest kube-apiserver/etcd binaries from + # GitHub Releases (setup-envtest v0.25's only source -- the legacy GCS + # kubebuilder-tools bucket 403s now for every version tried, no fallback there). + # History, in case it recurs: # - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only - # NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design - # ("egress is deliberately untouched... CI pulls from registries and package - # indexes that are not enumerable here" -- see its own comment, issue #128). - # There is no in-repo egress rule to edit for this. - # - Running this job on the bare runner host instead of in a container (tried and - # reverted, same as terdut-server's `chart` job does for get.helm.sh) fails - # earlier and differently: "go: command not found" -- the host has no Go. - # - The act-runner dind sidecar's MTU (Ryuvia/charts#272, merged and reconciled - # 2026-09-30: explicit `"mtu": 1450` in its daemon.json, matching Flannel's - # VXLAN-reduced pod MTU, since dockerd's bridge networks default to 1500 - # unset) -- tested against this exact failure post-fix (isolated `make test`, - # bypassing lint's own unrelated github.com flakiness) and got the identical - # "TLS handshake timeout" fetching envtest-v1.37.0-linux-amd64.tar.gz. Ruled - # out: the MTU mismatch was real but wasn't (solely) the cause of this. - # So whatever blocks github.com from the dind bridge sits outside anything this - # workspace's repos configure, and outside the MTU theory -- still unidentified as - # of 2026-09-30. `make test` fails on the envtest fetch until that's found and - # fixed (or the binaries are vendored -- see ROADMAP.md/the PR discussion for why - # that was declined for now). + # NetworkPolicy in the cluster and is deny-ingress only -- ruled out, no + # in-repo egress rule governs this. + # - Running this job on the bare runner host instead of in a container fails + # earlier and differently ("go: command not found", no Go there) -- ruled out. + # - The act-runner dind sidecar's MTU mismatch (1450 pod vs. 1500 Docker-bridge + # default) was real but an initial fix for it (Ryuvia/charts#272) did not + # resolve this specific failure when tested in isolation -- see Ryuvia/charts#271 + # for that round's write-up. + # - A second attempt at the MTU fix, 2026-09-30, did resolve it: `setup-envtest` + # now fetches envtest-v1.37.0-linux-amd64.tar.gz from github.com in ~4s and + # `test` passes. Confirmed via the actual job log, not just the exit code. test: runs-on: ubuntu-latest container: