fix(macos): substitute the gateway address before the service starts

Third attempt at the same symptom, and the first at the right layer.
podman's Docker-compatible API injects proxy settings from the *daemon*
environment after containers.conf is applied, so neither the env list
(892bfc16) nor http_proxy=false (21c144ae) could override it — the same
compat-path blind spot already seen with hosts_file. Nested containers
kept reporting `wget: bad address 'bot-bottle-gateway:9099'` through
both.

Substituting the resolved address into the service's own environment,
before `podman system service` starts, is the one place it sticks.
NO_PROXY keeps the name, which is matched against what a client asks
for.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-21 20:50:12 -04:00
parent 7a9628fc03
commit 854a8956ad
2 changed files with 27 additions and 0 deletions
@@ -174,6 +174,18 @@ class TestInitScript(unittest.TestCase):
self.assertIn('$2 == name { print $1; exit }', self.script)
self.assertIn('value.replace(name, ip)', self.script)
def test_substitutes_the_address_into_the_service_environment(self) -> None:
"""The compat API injects proxy settings from the daemon environment
after containers.conf is applied, so neither the env list nor
http_proxy=false can override it — the same blind spot it has for
hosts_file. Substituting before the service starts is the only place
the address sticks."""
launch = self.script[self.script.index("podman system service"):]
self.assertNotIn("$GATEWAY_NAME", launch) # substitution precedes it
setup = self.script[:self.script.index("podman system service")]
self.assertIn("for var in HTTP_PROXY HTTPS_PROXY http_proxy https_proxy",
setup)
def test_disables_podmans_own_proxy_passthrough(self) -> None:
"""podman copies the host's proxy vars into every container by
default, and that copy overrides the env we set — putting the