From 24cb52d9927e86021da1adef26006574816600e2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Mon, 21 Sep 2026 13:00:17 -0300 Subject: [PATCH] fix: stop the CI stack colliding with ports already used on the runner The integration job failed with "Bind for 0.0.0.0:8000 failed: port is already allocated". The runner shares the host's Docker daemon, so every published port is claimed on the machine itself, where other services already listen. Port 8000 was the first collision; 8080, 8081, 9000 and 9001 were equally exposed. MinIO's ports were hardcoded, and S3_PUBLIC_ENDPOINT was pinned to localhost:9000 independently, so moving storage would have broken the presigned URLs the browser fetches. Both now derive from STORAGE_PORT and move together. CI runs on 18080/18081/18000/19000/19001. Local defaults are unchanged. Verified by running the whole stack and the full suite on exactly those ports, including the browser end-to-end, which downloads through a presigned URL and so proves the storage endpoint followed the port. Co-Authored-By: Claude Opus 5 --- .gitea/workflows/deploy.yml | 11 ++++++++--- compose.local.yaml | 14 ++++++++++---- 2 files changed, 18 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 182328d..4e98690 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -31,9 +31,14 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 45 env: - SITE_PORT: "8080" - KANBAN_PORT: "8081" - API_PORT: "8000" + # The runner shares the host's Docker daemon, so every published port is + # taken on the machine itself and 8000/8080/9000 collide with whatever else + # runs there. Use a high block that nothing is likely to hold. + SITE_PORT: "18080" + KANBAN_PORT: "18081" + API_PORT: "18000" + STORAGE_PORT: "19000" + STORAGE_CONSOLE_PORT: "19001" COMPOSE: docker compose -f compose.local.yaml steps: - name: Checkout diff --git a/compose.local.yaml b/compose.local.yaml index 04719b1..5debf51 100644 --- a/compose.local.yaml +++ b/compose.local.yaml @@ -14,7 +14,7 @@ x-app: &app APP_ENV: local DATABASE_URL: postgresql://${APP_DB_USER:-dtf_app}:${APP_DB_PASSWORD:-local-app-database-only}@db:5432/${POSTGRES_DB:-dtf_local} S3_ENDPOINT: http://storage:9000 - S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}} S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork} AWS_ACCESS_KEY_ID: ${S3_APP_USER:-dtf_app} AWS_SECRET_ACCESS_KEY: ${S3_APP_PASSWORD:-local-app-storage-only} @@ -74,7 +74,9 @@ services: environment: MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local} MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-local-storage-only} - ports: ["127.0.0.1:9000:9000", "127.0.0.1:9001:9001"] + ports: + - "127.0.0.1:${STORAGE_PORT:-9000}:9000" + - "127.0.0.1:${STORAGE_CONSOLE_PORT:-9001}:9001" volumes: [storage-data:/data] networks: [local, edge] healthcheck: @@ -165,9 +167,13 @@ services: context: . dockerfile: local/Dockerfile.web environment: - S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}} ports: + # Published ports are host-wide even bound to loopback, so on a shared + # machine any of them can collide with something unrelated. CI overrides + # every one; see .gitea/workflows/deploy.yml. - "127.0.0.1:${SITE_PORT:-8080}:80" + # Convenience only: the API through its own gateway. No test uses it. - "127.0.0.1:${API_PORT:-8000}:81" networks: [local, edge] depends_on: @@ -184,7 +190,7 @@ services: dockerfile: local/Dockerfile.web environment: WEB_INDEX: kanban.html - S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:${STORAGE_PORT:-9000}} ports: ["127.0.0.1:${KANBAN_PORT:-8081}:80"] networks: [local, edge] depends_on: