Skip to content

test: unflake customers docker and outbound IP checks - #672

Merged
adamdecaf merged 2 commits into
masterfrom
fix/ci-test-failures
Sep 2, 2026
Merged

adamdecaf merged 2 commits into
masterfrom
fix/ci-test-failures

Conversation

@adamdecaf

Copy link
Copy Markdown
Member

Summary

  • Customers integration tests were hitting http://localhost/ping (port 80) because moov/watchman:static now listens on :8084 and no longer EXPOSEs 8080, so GetPort("8080/tcp") was empty. Point the tests at 8084, use a Docker network instead of legacy links, and dial 127.0.0.1.
  • TestRejectOutboundIPRange failed when Cloudflare returned a different A record than addrs[0] (e.g. 104.20.35.194). Match any resolved address against the allow list, and whitelist every IPv4//24 in the test.

Fixes the Ubuntu Go Build job: https://github.com/moov-io/paygate/actions/runs/33641980132/job/100287068229

Test plan

  • go test ./pkg/upload/ ./pkg/customers/ -count=1
  • CI Go Build on ubuntu-latest

Watchman:static listens on :8084 and no longer EXPOSEs 8080, so
GetPort("8080/tcp") was empty and the tests dialed port 80. Check
every resolved address against the FTP/SFTP allow list so Cloudflare
round-robin on moov.io cannot fail TestRejectOutboundIPRange.
ubuntu-18.04 is no longer hosted, so the job queued forever. Use
ubuntu-latest and the preinstalled Docker Compose v2 plugin.
@adamdecaf
adamdecaf merged commit 462253f into master Sep 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant