deploy/gitbay-runner.override.conf
44 lines · 2094 bytes
1# Drop-in for gitbay-runner.service, installed by `make deploy-runner` to
2# /etc/systemd/system/gitbay-runner.service.d/override.conf.
3#
4# A build must never starve the host: the e2e suite alone starts sixty
5# daemon instances, and with nothing holding it back a deploy's scp on
6# the admin sshd stalled at 1%. Lower CPU and IO weight keep sshd,
7# gitbayd and the backup timers responsive while a build runs.
8#
9# These weights are for the service, not per build, so `-jobs N` divides
10# them among N builds rather than taking N times as much. Raising -jobs
11# does not need them raised; it makes each build slower, not the host
12# busier.
13#
14# A build runs whatever the repository's ci.yml says, as the runner's
15# own user. Keep that user unprivileged: its key is added with
16# `keys add --scope runner`, which confines it to the runner protocol
17# and read-only git, and the sandboxing below keeps a step from
18# touching the system outside its workspace.
19#
20# Delegate=yes
21# The service unit's ExecStart carries -isolation; podman is the default,
22# and a runner that cannot find one refuses to start rather than running
23# repository code on the host. Prepare the host first
24# (deploy/runner-podman-setup.sh). and the storage path below are what rootless podman needs
25# (#144): it manages its own cgroups for a container, and its image and
26# container store lives under the runner's home, which ProtectSystem
27# would otherwise make read-only. Prepare the host with
28# deploy/runner-podman-setup.sh before deploying a runner that isolates.
29[Service]
30Nice=10
31CPUWeight=30
32IOWeight=30
33NoNewPrivileges=yes
34ProtectSystem=full
35ProtectKernelTunables=yes
36ProtectControlGroups=yes
37RestrictSUIDSGID=yes
38Delegate=yes
39# The runner's home is /var/lib/gitbay-runner (see the Admin page), and
40# the leading - makes a missing path ignored rather than fatal: this
41# drop-in installs on hosts that have not been prepared for podman yet,
42# and a unit that refuses to start would stop every build on the
43# instance.
44ReadWritePaths=-/var/lib/gitbay-runner/.local/share/containers -/var/lib/gitbay-runner/.config/containers