deploy: join gitea netns instead of bridge (machine kernel lacks ip_tables for rootless netavark); pin image digests; push-to-create repo

This commit is contained in:
2026-07-28 14:07:44 +02:00
parent ed7a9c01e7
commit 80d886c0cb
6 changed files with 28 additions and 34 deletions
+10 -8
View File
@@ -12,10 +12,12 @@ GITEA_URL="${GITEA_URL:-http://localhost:3000}" # published by ctao-demo-gitea
REPO="${REPO:-ctao/portal}" # owner/repo in Gitea
BRANCH="${BRANCH:-main}"
BUILD_IMAGE="${BUILD_IMAGE:-localhost/ctao-portal-build:1}"
BUILD_NET="${BUILD_NET:-ctao-demo}" # bridge from ctao-demo.network
# Clone URL as seen from INSIDE the build network (container-name DNS);
# the poll below uses $GITEA_URL because it runs on the host.
REPO_INTERNAL="${REPO_INTERNAL:-http://ctao-demo-gitea:3000/$REPO.git}"
# The build joins the Gitea container's network namespace: localhost inside
# the build = Gitea's loopback (port 3000), host loopback stays unreachable.
# (A netavark bridge would be equivalent, but rootless bridges need the
# ip_tables kernel module, absent on the machine — pasta needs nothing.)
BUILD_NETNS="${BUILD_NETNS:-container:ctao-demo-gitea}"
REPO_INTERNAL="${REPO_INTERNAL:-http://localhost:3000/$REPO.git}"
KEEP="${KEEP:-3}" # released builds to retain
mkdir -p "$BASE/repo" "$BASE/releases" "$BASE/state"
@@ -35,11 +37,11 @@ t0=$(date +%s)
# --- 2. Build in the ephemeral container (git + pinned node live there).
# SECURITY: the container runs npm lifecycle scripts from the repo, so it is
# confined to the ctao-demo bridge — it reaches Gitea by container name and
# the internet (for `npm ci` when the lockfile changed), but NOT the host's
# loopback services (code-server, Strapi). Never use --network=host here.
# confined to Gitea's netns — it reaches Gitea on localhost:3000 and the
# internet (for `npm ci` when the lockfile changed), but NOT the host's
# loopback services (code-server). Never use --network=host here.
# node_modules and .deps-hash are untracked, so they survive checkouts.
podman run --rm --network="$BUILD_NET" --memory=1g \
podman run --rm --network="$BUILD_NETNS" --memory=1g \
-e ASTRO_TELEMETRY_DISABLED=1 \
-e SHA="$sha" -e REPO_URL="$REPO_INTERNAL" -e BRANCH="$BRANCH" \
-v "$BASE/repo:/work/repo:z" \