deploy/runner-podman-setup.sh
64 lines · 2282 bytes · executable
1#!/bin/sh
2# Prepare a runner host for container-isolated builds (#144).
3#
4# Run this on the runner host as root BEFORE deploying a gitbay-runner
5# that requires isolation. The runner refuses to start without a working
6# podman rather than falling back to running builds unsandboxed, so the
7# order matters: prepare the host, then `make deploy-runner`.
8#
9# ssh -p 2222 root@bay1 'sh -s' < deploy/runner-podman-setup.sh
10#
11# Idempotent: safe to re-run.
12set -eu
13
14RUNNER_USER="${RUNNER_USER:-ci-runner}"
15
16# The runner's home is wherever the account was created with; podman's
17# store lives under it and the systemd drop-in names the same path.
18
19if ! id "$RUNNER_USER" >/dev/null 2>&1; then
20 echo "no such user: $RUNNER_USER" >&2
21 exit 1
22fi
23
24echo "==> installing podman"
25if ! command -v podman >/dev/null 2>&1; then
26 apt-get update
27 DEBIAN_FRONTEND=noninteractive apt-get install -y podman uidmap
28fi
29podman --version
30
31# Rootless podman maps container uids into a range delegated to the user.
32# Without these the runner's `podman run` fails with a mapping error.
33echo "==> subuid/subgid for $RUNNER_USER"
34for f in /etc/subuid /etc/subgid; do
35 if ! grep -q "^$RUNNER_USER:" "$f" 2>/dev/null; then
36 echo "$RUNNER_USER:200000:65536" >>"$f"
37 echo " added to $f"
38 else
39 echo " already in $f"
40 fi
41done
42
43# User namespaces are what rootless podman is built on. Debian 13 enables
44# them by default; check rather than assume, because a build silently
45# running as the host user is exactly what this is meant to prevent.
46echo "==> kernel support"
47max_ns=$(cat /proc/sys/user/max_user_namespaces 2>/dev/null || echo 0)
48if [ "$max_ns" -lt 1 ]; then
49 echo "user namespaces are disabled (user.max_user_namespaces=$max_ns);" >&2
50 echo "rootless podman cannot work until they are enabled" >&2
51 exit 1
52fi
53echo " max_user_namespaces=$max_ns"
54
55# Lingering keeps the user's systemd session — and so podman's storage
56# and any running container — alive when nobody is logged in.
57echo "==> lingering for $RUNNER_USER"
58loginctl enable-linger "$RUNNER_USER"
59
60echo "==> verifying rootless podman as $RUNNER_USER"
61su - "$RUNNER_USER" -s /bin/sh -c 'podman info --format "{{.Host.Security.Rootless}}"'
62
63echo
64echo "host is ready; now: make deploy-runner"