Configure BuildKit to allow plain HTTP to the local registry
Build and push server image / build-and-push (push) Failing after 10s

Docker defaults to HTTPS for any non-docker.io registry, and
10.0.0.246:3000 (a bare LAN IP:port) isn't serving valid HTTPS -- the
push kept going out over HTTPS and failing. Adds a buildkitd config
telling BuildKit specifically to use HTTP for that host.

This only fixes the actual build+push step (BuildKit). The "Log in"
step runs a plain `docker login` through the classic Docker CLI/daemon
instead, which doesn't read this config -- that one still needs
10.0.0.246:3000 added to "insecure-registries" in the actual Docker
daemon's /etc/docker/daemon.json on whatever host runs the Gitea
Actions runner, followed by a daemon restart. That's runner-host
infrastructure outside this repo.
This commit is contained in:
2026-07-23 17:12:33 -04:00
parent 8ae09f238b
commit 1f62653118
+16
View File
@@ -16,6 +16,22 @@ jobs:
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: docker/setup-buildx-action@v3
with:
# 10.0.0.246:3000 is plain HTTP (a bare LAN IP:port, no TLS cert
# would validate for it), but BuildKit defaults to HTTPS for any
# registry that isn't docker.io. This tells BuildKit specifically
# to skip that for this one host. NOTE: this only covers the
# actual build+push (BuildKit). The "Log in" step below runs a
# plain `docker login`, which goes through the classic Docker
# CLI/daemon instead of BuildKit and does NOT read this config --
# that one only works once the Docker daemon backing this runner
# has 10.0.0.246:3000 listed under "insecure-registries" in its
# own /etc/docker/daemon.json (then `systemctl restart docker`).
# That's runner-host infrastructure this repo can't configure.
config-inline: |
[registry."10.0.0.246:3000"]
http = true
insecure = true
- name: Log in to local Gitea Container Registry - name: Log in to local Gitea Container Registry
uses: docker/login-action@v3 uses: docker/login-action@v3