Describe the bug
The runner image has its own hook implementation, that is different to the runner-container-hooks docker implementation. This prevents using ACTIONS_RUNNER_NETWORK_DRIVER.
Adding the following would provide the docker-hooks directly in the default runner.
# https://github.com/actions/runner/blob/main/images/Dockerfile
RUN curl -f -L -o runner-container-hooks.zip https://github.com/actions/runner-container-hooks/releases/download/v0.8.1/actions-runner-hooks-docker-0.8.1.zip \
&& unzip ./runner-container-hooks.zip -d ./docker-hooks \
&& rm runner-container-hooks.zip
Is this an intentional decision to remove it? Are we meant to provide this ourselves? Because the default image does copy over the k8s and k8s-novolume versions of the container hooks
To Reproduce
- Create a runner with
ACTIONS_RUNNER_NETWORK_DRIVER=host
- Notice it does not create a network
Expected behavior
ACTIONS_RUNNER_NETWORK_DRIVER works for docker mode container hooks, see https://github.com/actions/runner-container-hooks/blob/d4c5425b2280223ac5b3a7afcce98d85107248fa/packages/docker/src/hooks/prepare-job.ts#L35
Runner Version and Platform
Version of your runner? 2.337.0
OS of the machine running the runner? Linux
What's not working?
It tries to use a network that is not host and this doesn't work with isolated unprivileged workloads
Job Log Output
/usr/bin/docker create --name 5e3aa931bc5c4a72992b1a6075550266_ubuntu2404_540059 --label 26b1d7 --workdir /__w/repo/repo --network github_network_48ed95a0dc6e4cadb9034d94b1bdf8bf -e "HOME=/github/home" -e GITHUB_ACTIONS=true -e CI=true -v "/var/run/docker.sock":"/var/run/docker.sock" -v "/home/runner/_work":"/__w" -v "/home/runner/externals":"/__e":ro -v "/home/runner/_work/_temp":"/__w/_temp" -v "/home/runner/_work/_actions":"/__w/_actions" -v "/opt/hostedtoolcache":"/__t" -v "/home/runner/_work/_temp/_github_home":"/github/home" -v "/home/runner/_work/_temp/_github_workflow":"/github/workflow" --entrypoint "tail" ubuntu:24.04 "-f" "/dev/null"
da3fa8cbfeb880c29a905656c025b00ce4a5ab2a9dfc8649765c7f43c2ff8302
/usr/bin/docker start da3fa8cbfeb880c29a905656c025b00ce4a5ab2a9dfc8649765c7f43c2ff8302
Error response from daemon: setting up Pasta: pasta failed with exit code 1:
Failed to open() /dev/net/tun: No such file or directory
Failed to set up tap device in namespace
failed to start containers: da3fa8cbfeb880c29a905656c025b00ce4a5ab2a9dfc8649765c7f43c2ff8302
Error: Docker start fail with exit code 1
Describe the bug
The runner image has its own hook implementation, that is different to the
runner-container-hooksdocker implementation. This prevents usingACTIONS_RUNNER_NETWORK_DRIVER.Adding the following would provide the docker-hooks directly in the default runner.
Is this an intentional decision to remove it? Are we meant to provide this ourselves? Because the default image does copy over the k8s and k8s-novolume versions of the container hooks
To Reproduce
ACTIONS_RUNNER_NETWORK_DRIVER=hostExpected behavior
ACTIONS_RUNNER_NETWORK_DRIVERworks for docker mode container hooks, see https://github.com/actions/runner-container-hooks/blob/d4c5425b2280223ac5b3a7afcce98d85107248fa/packages/docker/src/hooks/prepare-job.ts#L35Runner Version and Platform
Version of your runner? 2.337.0
OS of the machine running the runner? Linux
What's not working?
It tries to use a network that is not
hostand this doesn't work with isolated unprivileged workloadsJob Log Output