Skip to content

0004: Test harness runs without in-cluster registry access

Date: 2026-10-07 · Status: accepted

Context

make test-all must run unattended in the Claude Code cloud workspace and in GitHub Actions. In the workspace: Docker Hub rate-limits anonymous pulls, outbound TLS is re-terminated by a proxy that containers inside k3d do not trust, MinIO no longer publishes container images, the host uses cgroup v1 on a recent kernel, and the sandbox forbids lowering oom_score_adj.

Decision

  • Nothing is pulled from inside the cluster. The harness pulls (Docker daemon mirror mirror.gcr.io in the workspace) and imports every image with docker save --platform linux/amd64 | ctr import; k3s system images come from the k3s airgap tarball (GitHub release, cached in ~/.cache/keeper-harness).
  • MinIO is built from source (images/minio/Dockerfile, pinned module version) and cached as keeper-test/minio:dev.
  • k3s v1.31 with a static containerd config template (hack/k3s-containerd.toml.tmpl) that sets restrict_oom_score_adj = true (as rootless containerd does) and kubelet eviction thresholds of 1% (the workspace reports a large disk that looks almost full).
  • Image builds accept an optional BuildKit secret ca (a CA bundle) so go mod download works behind the proxy; CI does not pass it.

Consequences

The harness works the same in CI and in the workspace. Upgrading k3s means regenerating the containerd template from a running node of the new version.