nixos/git: Fix Actions runner cache timeout

Job containers using actions/cache hung and timed out reaching the
runner's built-in artifact cache server. With cache.host unset,
act_runner announced the box's autodetected outbound address, which
containers on podman0 can't route back to; even to the right address
the host input chain (policy drop) dropped the connection, as only the
forward chain was opened for the podman subnet.

Pin cache.host to the podman bridge gateway and cache.port to a fixed
value, and open that one port on podman0 in the input chain. Declare
the podman subnet once in the box file and derive the gateway, the
default_subnet and both firewall rules from it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-08-03 22:56:30 +01:00
parent b8f31e23f8
commit 5e3b196ee0
2 changed files with 25 additions and 2 deletions
+4 -2
View File
@@ -38,6 +38,8 @@ in
let
inherit (lib) mkMerge;
inherit (lib.my) networkdAssignment;
podmanSubnet = "10.88.0.0/16";
in
{
imports = [
@@ -158,7 +160,7 @@ in
oci-containers = {
backend = "podman";
};
containers.containersConf.settings.network.default_subnet = "10.88.0.0/16";
containers.containersConf.settings.network.default_subnet = podmanSubnet;
};
systemd.network = {
@@ -195,7 +197,7 @@ in
extraRules = ''
table inet filter {
chain forward {
ip saddr 10.88.0.0/16 accept
ip saddr ${podmanSubnet} accept
}
}
'';