Files
setup-buildkit/action.yml
T
meda d606ea669d revert: restore loopback endpoint — executor really runs network=host
Job 9024 runner log proves the executor container is created with
network="host", where docker DNS names do not resolve, so
tcp://<name>:<port> cannot connect. Restore tcp://127.0.0.1:<port>
plus the loopback port publish. The failure #4 build-step timeout has
a different (still investigated) cause.
2026-09-01 13:49:27 +02:00

66 lines
2.8 KiB
YAML

name: 'Setup BuildKit (with labels)'
description: 'Idempotently start a labeled buildkitd container and point buildx at it via the remote driver. The default docker-container driver cannot set container labels, and the Docker API has no PATCH-labels for existing containers — so we manage the container ourselves and Watchtower/Dockhand see the labels.'
inputs:
container_name:
description: 'Name of the buildkitd container'
required: false
default: 'buildkitd'
image:
description: 'BuildKit image'
required: false
default: 'moby/buildkit:buildx-stable-1'
monitor_only:
description: 'Value for com.centurylinklabs.watchtower.monitor-only'
required: false
default: 'false'
dockhand_notify:
description: 'Value for dockhand.notify'
required: false
default: 'false'
cleanup:
description: 'Stop the buildkitd container after the job (idle cleanup; container restarts on demand on the next run)'
required: false
default: 'true'
network:
description: 'Docker network for the buildkitd container — MUST match the network the job containers run on, otherwise the name is unresolvable'
required: false
default: 'git_default'
port:
description: 'TCP port buildkitd listens on'
required: false
default: '8375'
runs:
using: 'composite'
steps:
- name: Start BuildKit container (with labels)
shell: bash
run: |
# Recreate if a stopped/old container exists (config drift, e.g. port
# mapping changes, would otherwise be skipped by the name guard).
# If it is already running with the right config, keep it (warm cache).
if [ "$(docker inspect -f '{{.State.Running}}' ${{ inputs.container_name }} 2>/dev/null)" != "true" ]; then
docker rm -f ${{ inputs.container_name }} >/dev/null 2>&1 || true
docker run -d --name ${{ inputs.container_name }} --privileged \
--network ${{ inputs.network }} \
-p 127.0.0.1:${{ inputs.port }}:${{ inputs.port }} \
--restart unless-stopped \
--label com.centurylinklabs.watchtower.monitor-only=${{ inputs.monitor_only }} \
--label dockhand.notify=${{ inputs.dockhand_notify }} \
${{ inputs.image }} --addr tcp://0.0.0.0:${{ inputs.port }}
fi
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
with:
driver: remote
# The act_runner executor runs with network=host (confirmed in runner
# logs), so it reaches buildkitd via the host-published loopback port.
# Docker DNS names are NOT resolvable from the host namespace.
endpoint: tcp://127.0.0.1:${{ inputs.port }}
- name: Stop BuildKit (idle cleanup)
if: ${{ inputs.cleanup == 'true' && always() }}
shell: bash
run: docker stop ${{ inputs.container_name }} || true