Run CI on the self-hosted GitLab #2

Merged
jcoffey-dev merged 3 commits from ci/gitlab-pipeline into main 2026-09-21 03:04:16 +00:00
Showing only changes of commit 2441e47390 - Show all commits
+10 -9
View File
@@ -32,14 +32,6 @@ node:
image: node:26-bookworm-slim@sha256:582460f614631b59b824ac6020533b9bf339c7fdf3a6d7db31abb6b4065f0212 # 26-bookworm-slim image: node:26-bookworm-slim@sha256:582460f614631b59b824ac6020533b9bf339c7fdf3a6d7db31abb6b4065f0212 # 26-bookworm-slim
variables: variables:
NPM_CONFIG_CACHE: "$CI_PROJECT_DIR/.npm" NPM_CONFIG_CACHE: "$CI_PROJECT_DIR/.npm"
# imageproxy.test.ts binds its "reached by name" server to ::1 and then
# asks for localhost, on the assumption that localhost resolves to IPv6
# first. That holds on a workstation and on GitHub's ubuntu-latest; inside
# this container /etc/hosts answers 127.0.0.1 first, the request lands on
# the pinned server instead and the control case fails. Node 17 onwards
# returns getaddrinfo order verbatim, so ask for the order the test
# expects rather than rewriting the test around the runner.
NODE_OPTIONS: "--dns-result-order=ipv6first"
cache: cache:
key: key:
files: [package-lock.json] files: [package-lock.json]
@@ -52,7 +44,16 @@ node:
# config.test.ts chmods a directory to 0555 and expects the write to be # config.test.ts chmods a directory to 0555 and expects the write to be
# refused. Root ignores the permission bits, so as root that assertion can # refused. Root ignores the permission bits, so as root that assertion can
# never hold. The tests run as the image's unprivileged `node` user for # never hold. The tests run as the image's unprivileged `node` user for
# that reason; -p keeps the environment, including NODE_OPTIONS above. # that reason; -p keeps the environment.
#
# imageproxy.test.ts needs IPv6 as well, which is not set here but on the
# runner: jobs run on the `ci-net` docker network, created with --ipv6.
# Without a non-loopback IPv6 address on the container, getaddrinfo's
# AI_ADDRCONFIG drops ::1 from the results entirely, localhost resolves to
# IPv4 only, and the test's control case connects to a port nothing is
# listening on. That is a runner property, so it cannot be fixed from this
# file -- if these tests ever fail again with ECONNREFUSED on 127.0.0.1,
# check that the runner still puts jobs on an IPv6-enabled network.
- chown -R node:node "$CI_PROJECT_DIR" - chown -R node:node "$CI_PROJECT_DIR"
script: script:
- su node -p -c "npm ci --ignore-scripts" - su node -p -c "npm ci --ignore-scripts"