deploy/gitbay-runner.override.conf

96df83f2d3eb9f241bcaa53fcc243d090c53ab2b
gitbay/deploy/gitbay-runner.override.conf history · blame · raw

27 lines · 1104 bytes

 1# Drop-in for gitbay-runner.service, installed by `make deploy-runner` to
 2# /etc/systemd/system/gitbay-runner.service.d/override.conf.
 3#
 4# A build must never starve the host: the e2e suite alone starts sixty
 5# daemon instances, and with nothing holding it back a deploy's scp on
 6# the admin sshd stalled at 1%. Lower CPU and IO weight keep sshd,
 7# gitbayd and the backup timers responsive while a build runs.
 8#
 9# These weights are for the service, not per build, so `-jobs N` divides
10# them among N builds rather than taking N times as much. Raising -jobs
11# does not need them raised; it makes each build slower, not the host
12# busier.
13#
14# A build runs whatever the repository's ci.yml says, as the runner's
15# own user. Keep that user unprivileged: its key is added with
16# `keys add --scope runner`, which confines it to the runner protocol
17# and read-only git, and the sandboxing below keeps a step from
18# touching the system outside its workspace.
19[Service]
20Nice=10
21CPUWeight=30
22IOWeight=30
23NoNewPrivileges=yes
24ProtectSystem=full
25ProtectKernelTunables=yes
26ProtectControlGroups=yes
27RestrictSUIDSGID=yes