diff --git a/internal/builder/builder.go b/internal/builder/builder.go index a7cddcc..32895a1 100644 --- a/internal/builder/builder.go +++ b/internal/builder/builder.go @@ -333,6 +333,9 @@ func one(ctx context.Context, run Runner, publish Publisher, // it at that step and it is in no image layer. A Dockerfile that does not ask for it is // unaffected; the secret is simply not read (novox/hq ADR 0076). invocation = append(invocation, "--secret", "id=npmrc,src="+npmrc) + // Host network for the build, so a RUN reaching the package registry finds it where the + // binding says it is — the machine's own loopback, where the registry answers. + invocation = append(invocation, "--network", "host") } invocation = append(invocation, ".") say("image", "docker build -f %s", a.From) @@ -616,6 +619,8 @@ func publishPackage(ctx context.Context, run Runner, module, dir string, a catal const within = "/app/module" invocation := []string{ "run", "--rm", + // Host network, so the publish reaches the registry at the address the binding names. + "--network", "host", "--volume", dir + ":" + within, // Read-only, so a build cannot alter the credential, and at /root where npm reads it. "--volume", npmrc + ":/root/.npmrc:ro",