Root cause: docker-compose.yml used ${DATABASE_URL:-…}, so the Act runner’s host/prodDATABASE_URL was interpolated into the web service. Containerized deploy tests then ran against shared Postgres instead of the bundled compose db.
Stop reading host DATABASE_URL in compose (use COMPOSE_DATABASE_URL override only).
Deploy docker step: unset DB secrets, dedicated compose project name, up --wait db, force test DATABASE_URL to postgres://scha:scha@db:5432/scha, down -v on exit (ephemeral DB).
Clear DATABASE_URL/DB_HOST in unittests.yml / ci.yml so host sqlite-fallback tests cannot hit prod either.
Test plan
Merge to master and watch Unit Tests + Deploy docker job.
Confirm docker step connects only to compose db (no traffic/errors against 10.0.0.230).
Local: docker compose up --build still works with bundled Postgres.
## Summary
- Root cause: `docker-compose.yml` used `${DATABASE_URL:-…}`, so the Act runner’s host/`prod` `DATABASE_URL` was interpolated into the web service. Containerized deploy tests then ran against shared Postgres instead of the bundled compose `db`.
- Stop reading host `DATABASE_URL` in compose (use `COMPOSE_DATABASE_URL` override only).
- Deploy docker step: unset DB secrets, dedicated compose project name, `up --wait db`, force test `DATABASE_URL` to `postgres://scha:scha@db:5432/scha`, `down -v` on exit (ephemeral DB).
- Clear `DATABASE_URL`/`DB_HOST` in `unittests.yml` / `ci.yml` so host sqlite-fallback tests cannot hit prod either.
## Test plan
- [ ] Merge to `master` and watch Unit Tests + Deploy docker job.
- [ ] Confirm docker step connects only to compose `db` (no traffic/errors against `10.0.0.230`).
- [ ] Confirm `docker compose -p scha-ci-<sha> …` volumes cleaned after job (`down -v`).
- [ ] Local: `docker compose up --build` still works with bundled Postgres.
Compose was interpolating ${DATABASE_URL} from the Act runner, so containerized tests could hit shared Postgres. Use COMPOSE_DATABASE_URL, an ephemeral compose project with down -v, and clear DB env in unit-test workflows.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
docker-compose.ymlused${DATABASE_URL:-…}, so the Act runner’s host/prodDATABASE_URLwas interpolated into the web service. Containerized deploy tests then ran against shared Postgres instead of the bundled composedb.DATABASE_URLin compose (useCOMPOSE_DATABASE_URLoverride only).up --wait db, force testDATABASE_URLtopostgres://scha:scha@db:5432/scha,down -von exit (ephemeral DB).DATABASE_URL/DB_HOSTinunittests.yml/ci.ymlso host sqlite-fallback tests cannot hit prod either.Test plan
masterand watch Unit Tests + Deploy docker job.db(no traffic/errors against10.0.0.230).docker compose -p scha-ci-<sha> …volumes cleaned after job (down -v).docker compose up --buildstill works with bundled Postgres.Compose was interpolating ${DATABASE_URL} from the Act runner, so containerized tests could hit shared Postgres. Use COMPOSE_DATABASE_URL, an ephemeral compose project with down -v, and clear DB env in unit-test workflows.