From ae55bd7bdee22c94fbf1ab6fd4d5a9dab8d6da05 Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 16 Sep 2026 10:33:07 +0200 Subject: [PATCH] Builds that need the registry run on the host network An image build with an npm credential, and a package publish, join the host network so 127.0.0.1 reaches the registry where the binding names it. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- internal/builder/builder.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/internal/builder/builder.go b/internal/builder/builder.go index a7cddcc..32895a1 100644 --- a/internal/builder/builder.go +++ b/internal/builder/builder.go @@ -333,6 +333,9 @@ func one(ctx context.Context, run Runner, publish Publisher, // it at that step and it is in no image layer. A Dockerfile that does not ask for it is // unaffected; the secret is simply not read (novox/hq ADR 0076). invocation = append(invocation, "--secret", "id=npmrc,src="+npmrc) + // Host network for the build, so a RUN reaching the package registry finds it where the + // binding says it is — the machine's own loopback, where the registry answers. + invocation = append(invocation, "--network", "host") } invocation = append(invocation, ".") say("image", "docker build -f %s", a.From) @@ -616,6 +619,8 @@ func publishPackage(ctx context.Context, run Runner, module, dir string, a catal const within = "/app/module" invocation := []string{ "run", "--rm", + // Host network, so the publish reaches the registry at the address the binding names. + "--network", "host", "--volume", dir + ":" + within, // Read-only, so a build cannot alter the credential, and at /root where npm reads it. "--volume", npmrc + ":/root/.npmrc:ro",