0004: Test harness runs without in-cluster registry access¶
Date: 2026-10-07 · Status: accepted
Context¶
make test-all must run unattended in the Claude Code cloud workspace and in GitHub Actions. In the workspace:
Docker Hub rate-limits anonymous pulls, outbound TLS is re-terminated by a proxy that containers inside k3d do not
trust, MinIO no longer publishes container images, the host uses cgroup v1 on a recent kernel, and the sandbox
forbids lowering oom_score_adj.
Decision¶
- Nothing is pulled from inside the cluster. The harness pulls (Docker daemon mirror
mirror.gcr.ioin the workspace) and imports every image withdocker save --platform linux/amd64 | ctr import; k3s system images come from the k3s airgap tarball (GitHub release, cached in~/.cache/keeper-harness). - MinIO is built from source (
images/minio/Dockerfile, pinned module version) and cached askeeper-test/minio:dev. - k3s v1.31 with a static containerd config template (
hack/k3s-containerd.toml.tmpl) that setsrestrict_oom_score_adj = true(as rootless containerd does) and kubelet eviction thresholds of 1% (the workspace reports a large disk that looks almost full). - Image builds accept an optional BuildKit secret
ca(a CA bundle) sogo mod downloadworks behind the proxy; CI does not pass it.
Consequences¶
The harness works the same in CI and in the workspace. Upgrading k3s means regenerating the containerd template from a running node of the new version.