fix(macos): stop podman re-injecting the gateway name into containers
tracker-policy-pr / check-pr (pull_request) Successful in 13s
test / integration-docker (pull_request) Successful in 19s
lint / lint (push) Successful in 54s
test / unit (pull_request) Successful in 1m39s
test / integration-firecracker (pull_request) Successful in 3m29s
test / coverage (pull_request) Successful in 24s
test / publish-infra (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Successful in 13s
test / integration-docker (pull_request) Successful in 19s
lint / lint (push) Successful in 54s
test / unit (pull_request) Successful in 1m39s
test / integration-firecracker (pull_request) Successful in 3m29s
test / coverage (pull_request) Successful in 24s
test / publish-infra (pull_request) Has been skipped
The address-bearing proxy URLs from 892bfc16 were written correctly but
never took effect: podman copies the host's proxy environment into every
container by default, and that copy overrides containers.conf `env`,
restoring the `bot-bottle-gateway` name a nested container cannot
resolve. Verified on the macOS host — containers still reported
`wget: bad address 'bot-bottle-gateway:9099'` with the addresses in
place.
Setting http_proxy=false disables only podman's own passthrough; the
proxy vars still reach containers, by address, from the env list.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -136,6 +136,10 @@ path = Path(os.environ["CONTAINERS_CONF"])
|
|||||||
path.write_text("\n".join([
|
path.write_text("\n".join([
|
||||||
"[containers]",
|
"[containers]",
|
||||||
'cgroups="disabled"',
|
'cgroups="disabled"',
|
||||||
|
# podman copies the host's proxy vars into every container by default,
|
||||||
|
# and that copy *wins* over the env below — putting the unresolvable
|
||||||
|
# gateway name back. Turn it off so the address-bearing URLs stand.
|
||||||
|
"http_proxy=false",
|
||||||
'hosts_file="/etc/hosts"',
|
'hosts_file="/etc/hosts"',
|
||||||
f'volumes=["{ca}:{ca}:ro"]',
|
f'volumes=["{ca}:{ca}:ro"]',
|
||||||
"env=[",
|
"env=[",
|
||||||
|
|||||||
@@ -174,6 +174,13 @@ class TestInitScript(unittest.TestCase):
|
|||||||
self.assertIn('$2 == name { print $1; exit }', self.script)
|
self.assertIn('$2 == name { print $1; exit }', self.script)
|
||||||
self.assertIn('value.replace(name, ip)', self.script)
|
self.assertIn('value.replace(name, ip)', self.script)
|
||||||
|
|
||||||
|
def test_disables_podmans_own_proxy_passthrough(self) -> None:
|
||||||
|
"""podman copies the host's proxy vars into every container by
|
||||||
|
default, and that copy overrides the env we set — putting the
|
||||||
|
unresolvable gateway name back and leaving nested containers at
|
||||||
|
"bad address 'bot-bottle-gateway'"."""
|
||||||
|
self.assertIn('"http_proxy=false"', self.script)
|
||||||
|
|
||||||
def test_keeps_the_gateway_name_in_no_proxy(self) -> None:
|
def test_keeps_the_gateway_name_in_no_proxy(self) -> None:
|
||||||
"""NO_PROXY is matched against what a client asks for, and code inside
|
"""NO_PROXY is matched against what a client asks for, and code inside
|
||||||
a nested container still says bot-bottle-gateway."""
|
a nested container still says bot-bottle-gateway."""
|
||||||
|
|||||||
Reference in New Issue
Block a user