diff --git a/k8s/infra/forgejo-runner/templates/configmap.yaml b/k8s/infra/forgejo-runner/templates/configmap.yaml index 81e193d..c73d992 100644 --- a/k8s/infra/forgejo-runner/templates/configmap.yaml +++ b/k8s/infra/forgejo-runner/templates/configmap.yaml @@ -13,6 +13,18 @@ # runner serves bind-mount arbitrary paths off the runner pod's filesystem # into a job container, which is a real widening of the CI trust boundary, # not just a convenience. +# +# network: host is also only settable here, not per-workflow. A workflow's +# `container.options: --network host` is silently ignored -- confirmed live: +# every job's actual `docker create` call logged +# `network="FORGEJO-ACTIONS-TASK-N_..."`, an auto-generated per-job bridge, +# regardless of that options string. On that isolated bridge, DOCKER_HOST= +# tcp://localhost:2376 resolves to the job container itself (no daemon there), +# not to the dind sidecar, so any docker command that actually needs the +# daemon (build, push -- anything past docker login, which only talks to the +# registry over the network and never touches DOCKER_HOST) fails with "Cannot +# connect to the Docker daemon". host mode puts every job container in dind's +# own network namespace instead, where the daemon really is listening. apiVersion: v1 kind: ConfigMap metadata: @@ -23,3 +35,4 @@ data: container: valid_volumes: - /docker-certs/client + network: host