Observed (2026-09-27)
- Repo variable
CI_REGISTRY_MIRROR = 172.16.0.1:5555 (set 2026-09-01), consumed by containers.yml's "Compose the buildkit registry config" step on homeserver-routed runs.
- On the homeserver there is no
ci-registry-mirror.service, no /etc/apiary-registry-mirror.env, and no registry:3 container. Nothing listens on 172.16.0.1:5555.
- Port 5555 on the homeserver is bound only on the WireGuard address, by the multipot honeypot container (
hp-multipot), not by a registry.
containers.yml runs still go green, so buildkit presumably falls back from the unreachable mirror to docker.io — i.e. the #2819 pull-through cache is not in effect and every run pulls from Hub directly (only the authenticated login from #2819 is protecting against toomanyrequests). Each base resolve likely also pays a connect-refused round-trip first.
Options
- Run
scripts/github-ci-runner/install-registry-mirror.sh on each CI executor host, or
- unset
CI_REGISTRY_MIRROR so the config honestly says "no mirror".
Not fixed here; found while adding the precision CI host (see linked issue).
Observed (2026-09-27)
CI_REGISTRY_MIRROR=172.16.0.1:5555(set 2026-09-01), consumed bycontainers.yml's "Compose the buildkit registry config" step on homeserver-routed runs.ci-registry-mirror.service, no/etc/apiary-registry-mirror.env, and noregistry:3container. Nothing listens on172.16.0.1:5555.hp-multipot), not by a registry.containers.ymlruns still go green, so buildkit presumably falls back from the unreachable mirror to docker.io — i.e. the #2819 pull-through cache is not in effect and every run pulls from Hub directly (only the authenticated login from #2819 is protecting againsttoomanyrequests). Each base resolve likely also pays a connect-refused round-trip first.Options
scripts/github-ci-runner/install-registry-mirror.shon each CI executor host, orCI_REGISTRY_MIRRORso the config honestly says "no mirror".Not fixed here; found while adding the
precisionCI host (see linked issue).