5868607c27
The in-cluster service DNS (`gitea.git.svc.cluster.local`) is not resolvable from build containers running with `network: host`. The runner config has an `extra_hosts` mapping for this name, but `host` networking shares the host's network namespace and bypasses the container-level hosts file — which silently nullifies the mapping. Symptom: every Gitea Actions run on `dharma-el` (and any other neuron-technologies repo that has CI defined) failed at the first `actions/checkout` step with `Could not resolve host: gitea.git.svc.cluster.local`. CI had never actually validated for that org. Fix: register both the `will` and `neuron-technologies` runners with the public URL `https://git.neuralplatform.ai`. The runner polls Gitea over Cloudflare, and the build container's clone URL is derived from the runner's instance URL, so it inherits a name the build container can resolve. Also bumped `config-version` annotations on both runner deployments to force a rolling restart — the init container needs to re-register with the new URL. Trade-off: the runner now polls Gitea over Cloudflare instead of directly on the cluster network. Latency cost is small relative to build time, and the failure mode is gone.