From 7cab21067437e6c442010b8daafac159a7e9eb2d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Mon, 21 Sep 2026 13:04:56 -0300 Subject: [PATCH] ci: move the integration stack clear of the ports that host already uses 8000 was Portainer's Edge tunnel, not a stray process. The first attempt at a fix picked 18080/18081, which are the production dtf-cloud stack's own defaults in docker-compose.yml: it would have passed only while that stack was down and collided again the moment it came back. Use 28080/28081/28000/29000/29001, clear of Portainer (8000, 9443), both production stack definitions (18080/18081 and 8080/8081) and the usual MinIO ports. The occupants are listed in the workflow so the next person choosing a port can see what is taken. Ephemeral ports would remove the guesswork but do not work here: the published port is baked into PUBLIC_ORIGIN, ALLOWED_ORIGINS and the CSP when the containers start, so it has to be known before they run. Full suite verified on the new block, including the browser end-to-end. Co-Authored-By: Claude Opus 5 --- .gitea/workflows/deploy.yml | 20 +++++++++++++------- 1 file changed, 13 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 4e98690..c187491 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -32,13 +32,19 @@ jobs: timeout-minutes: 45 env: # The runner shares the host's Docker daemon, so every published port is - # taken on the machine itself and 8000/8080/9000 collide with whatever else - # runs there. Use a high block that nothing is likely to hold. - SITE_PORT: "18080" - KANBAN_PORT: "18081" - API_PORT: "18000" - STORAGE_PORT: "19000" - STORAGE_CONSOLE_PORT: "19001" + # taken on the machine itself. Known occupants of that host: + # 8000, 9443 Portainer (the Edge tunnel and its UI) + # 18080/18081 the production dtf-cloud stack (docker-compose.yml defaults) + # 8080/8081 deploy/stack.yaml defaults + # 9000/9001 MinIO defaults elsewhere + # This block avoids all of them. Ephemeral ports are not an option: the + # published port is baked into PUBLIC_ORIGIN, ALLOWED_ORIGINS and the CSP + # when the containers start, so it has to be known beforehand. + SITE_PORT: "28080" + KANBAN_PORT: "28081" + API_PORT: "28000" + STORAGE_PORT: "29000" + STORAGE_CONSOLE_PORT: "29001" COMPOSE: docker compose -f compose.local.yaml steps: - name: Checkout