The Forgejo runner infra now gives job containers a privileged
container pre-wired to its own dind sidecar via DOCKER_HOST, so
defining our own docker:dind service would start a conflicting
second daemon. Keep the node image + docker CLI install (still
needed) and drop the services/env block.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
JS actions (checkout, login-action, etc.) need Node.js, so the docker
CLI-only alpine image couldn't run them. Switch to node:20-bookworm and
install the docker CLI/buildx plugin as a step instead.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The runner's default job image has no docker binary. Run the job in
docker:27-cli with a docker:27-dind sidecar service instead of relying
on the runner exposing a host docker socket.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>