## Summary
Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths.
Closes#62
## What Changed
### E2E workflow reliability
- Fixed E2E workspace handoff to ensure expected repository contents are present during test execution.
- Added stricter preflight checks for required frontend files before running E2E.
- Reduced mount/path fragility while preserving runtime image pull and compose flow.
### Renovate workflow hardening
- Added internal-first endpoint reachability selection with fallback handling.
- Added token preflight checks for repository access.
- Added explicit host-rule auth handling for API/git paths.
- Added container-level connectivity preflight diagnostics.
- Added git URL override aligned with selected endpoint context.
- Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing.
## Why
CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures.
## Scope
- Workflow logic only (`cicd.yaml`, `renovate.yml`)
- No app feature or API behavior changes
## Validation
- Workflow YAML validation passed during updates.
- Changes were applied and verified iteratively from real failing run diagnostics.
Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #73