Repository navigation
fix(devcontainer): replace flaky LLVM and kind features - #2826
Draft
Quang Nguyen (nddq) wants to merge 1 commit into
Draft
Quang Nguyen (nddq) wants to merge 1 commit into
Quang Nguyen (nddq) wants to merge 1 commit into
Conversation
Retina Code Coverage ReportTotal coverage no change |
The DevContainer build fails intermittently in two features: - The LLVM feature downloads llvm.sh from apt.llvm.org and adds that apt repository. Requests to apt.llvm.org from GitHub runners fail intermittently, and sometimes DNS returns only an IPv6 address that the build container cannot reach. The repository adds no packages. Its noble builds of LLVM 17 (1:17.0.6~++...) sort below Ubuntu's 1:17.0.6-9ubuntu1, so apt installs the Ubuntu packages. - The kind feature resolves "latest" through the GitHub API without a token. Shared runner IPs hit the rate limit (HTTP 403), and "latest" can resolve to an alpha tag that has no release (HTTP 404). Install clang-17 and llvm-17 from the Ubuntu archive in the apt-deps step in place of the LLVM feature. Add kind as a tool in go.mod, and install it with go install, which downloads through the Go module proxy. go.mod marks tool dependencies as indirect, and Dependabot skips indirect dependencies by default, so allow sigs.k8s.io/kind by name. The Go version check also passes when the versions differ. The Go feature installs 1.24.11, but go.mod requires 1.26.0. With GOTOOLCHAIN=auto, go version downloads and reports the go.mod version. Set the feature to 1.26.0, and run the check with GOTOOLCHAIN=local. Pin golangci-lint to the go.mod tool version, which the lint workflow builds, so that the editor lints like CI. Signed-off-by: Quang Nguyen <28567936+nddq@users.noreply.github.com>
Quang Nguyen (nddq)
force-pushed
the
nddq/devcontainer-ci-flakes
branch
from
October 6, 2026 15:00
5a185a8 to
d31b6f3
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The DevContainer workflow fails often because two features download from hosts that GitHub runners cannot reach reliably.
LLVM:
ghcr.io/devcontainers-community/features/llvmrunsllvm.shfromapt.llvm.organd adds that apt repository. The requests toapt.llvm.orgfail intermittently, and sometimes DNS returns only an IPv6 address that the build container cannot reach:The repository adds no packages. Its noble builds of LLVM 17 (
1:17.0.6~++…) sort below Ubuntu's1:17.0.6-9ubuntu1, so apt installs the Ubuntu packages anyway.kind:
ghcr.io/devcontainers-extra/features/kindresolveslatestthrough the GitHub API without a token. Shared runner IPs hit the rate limit, andlatestcan resolve to an alpha tag that has no release:The Go version check also passes when the versions differ. The Go feature installs
1.24.11, butgo.modrequiresgo 1.26.0. WithGOTOOLCHAIN=auto,go versiondownloads and reportsgo1.26.0.This PR:
apt-depsstep installsclang-17andllvm-17from the Ubuntu archive (the same packages as before) and creates theclangandllvm-stripsymlinks.sigs.k8s.io/kindv0.33.0joins thetoolblock ingo.mod, andgo-setuprunsgo install sigs.k8s.io/kind.go.modmarks tool dependencies// indirect, which Dependabot skips by default, sodependabot.yamlallowssigs.k8s.io/kindby name. Minor and patch updates arrive with thek8sgroup.1.26.0and runs the version check withGOTOOLCHAIN=local. Also pinsgolangciLintVersionto2.11.4, thego.modversion that the golangci-lint workflow builds, so that the editor lints like CI.Checklist
git commit -S -s ...). See this documentation on signing commits.Screenshots (if applicable) or Testing Completed
Built the dev container with
@devcontainers/cli0.89.0(the CLI version thatdevcontainers/ciuses) and ran the workflow'srunCmdin it. All steps pass, including the Go version check:go generaterebuilds all 7 eBPF objects, andgolangci-lint versionreports2.11.4. The module cache holds no downloaded Go toolchain. The DevContainer workflow runs on this PR because the PR changes.devcontainer/**andgo.mod.