fix(deploy): unblock every rebuild on BuildKit's host-network refusal
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-unit (push) Failing after 2m4s
CI / tests-integration (push) Successful in 2m6s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Skipped

Docker 29.1.3 ships BuildKit v0.26, which refuses to grant a build host
networking unless each caller passes --allow=network.host. All three rebuild
paths asked for it, and `docker compose build` has no flag to grant it, so a
rebuild failed immediately with "additional privileges requested". The live
container was never replaced, which is exactly the reported symptom: the site
kept serving the previous release after a rebuild.

Nothing in the build actually needs host networking. It uses the network only
for apk, pnpm and next/font/google — all outbound internet, which the default
bridge provides. Verified by building both the full runner image and the
migrations stage with --no-cache after dropping the flag.

Runtime `network_mode: host` stays: blue/green needs per-release host ports
(3002/3003) and nginx reaches each slot over 127.0.0.1.

The second gap is how a rebuild could still ship the wrong code. ci-deploy.sh
stamped every image with HEAD's revision label, and verify-deployed-release.mjs
only re-checks that same label, so a dirty working tree produced an image that
claimed to be release $sha while containing uncommitted code. docker-update.sh
already refused this; ci-deploy.sh now does too, before any build work.
This commit is contained in:
openhands committed 2026-10-10 13:07:13 +02:00
1 parent 48291ab641
commit fdb7af7ef5
6 files changed
+29 -6

No files matched your search

+1 -1
View File
@@ -94,7 +94,7 @@ describe("isolated branch preflight", () => {
expect(
result.calls.split("\n").filter((line) => line.startsWith("docker ")),
).toEqual([
expect.stringContaining("docker build --network=host"),
expect.stringContaining("docker build --progress=plain"),
`docker image rm ${image}`,
]);
expect(result.calls).not.toMatch(
+1 -1
View File
@@ -11,7 +11,7 @@ pnpm() {
docker() {
echo "docker $*" >> "$TEST_DIR/calls"
case "$1 $2" in
'build --network=host') [ "$SCENARIO" != build-failure ] ;;
'build --progress=plain') [ "$SCENARIO" != build-failure ] ;;
'image rm') [ "$SCENARIO" != cleanup-failure ] ;;
*) return 92 ;;
esac