fix(macos): substitute the gateway address before the service starts

Third attempt at the same symptom, and the first at the right layer.
podman's Docker-compatible API injects proxy settings from the *daemon*
environment after containers.conf is applied, so neither the env list
(892bfc16) nor http_proxy=false (21c144ae) could override it — the same
compat-path blind spot already seen with hosts_file. Nested containers
kept reporting `wget: bad address 'bot-bottle-gateway:9099'` through
both.

Substituting the resolved address into the service's own environment,
before `podman system service` starts, is the one place it sticks.
NO_PROXY keeps the name, which is matched against what a client asks
for.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-21 20:50:12 -04:00
parent 7a9628fc03
commit 854a8956ad
2 changed files with 27 additions and 0 deletions
@@ -178,6 +178,21 @@ if docker info >/dev/null 2>&1; then
exit 0
fi
# The service's own environment is the last word on what a nested container
# gets. podman's Docker-compatible API injects proxy settings from the daemon
# environment *after* containers.conf is applied, so neither the `env` list
# below nor `http_proxy=false` can override it — the same blind spot the
# compat path has for `hosts_file`. Substituting here, before the service
# starts, is therefore the only place the address actually sticks.
#
# Assigned via command substitution, never echoed: these carry the bottle's
# identity token.
for var in HTTP_PROXY HTTPS_PROXY http_proxy https_proxy; do
eval "value=\${$var:-}"
[ -n "$value" ] || continue
eval "export $var=\"\${value%%$GATEWAY_NAME*}$gateway_ip\${value#*$GATEWAY_NAME}\""
done
log=/tmp/bot-bottle-nested-containers.log
nohup podman system service --time=0 \
"unix://$XDG_RUNTIME_DIR/podman.sock" \