deploy/Containerfile.ci

e91fdfe0cc2f9bfdcf99bf1a316d219bed8e2ebf
gitbay/deploy/Containerfile.ci history · blame · raw

37 lines · 1598 bytes

 1# The image gitbay's own CI jobs run in, once the runner isolates builds
 2# (#144). Without it a job runs in the runner's default image, which has
 3# no toolchain, and the suite's prerequisite check fails immediately.
 4#
 5# Build it on the runner host, where podman keeps it:
 6#
 7#   ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \
 8#     "podman build -t localhost/gitbay-ci:2 -f - ." ' < deploy/Containerfile.ci
 9#
10# Tagged, not :latest, so a change to this file is a deliberate bump in
11# .gitbay/ci.yml rather than a silent change under a running branch.
12FROM docker.io/library/golang:1.27-trixie
13
14# The suite drives real git, ssh, sshd and gpg rather than mocking them,
15# and asserts they are present before running. git-lfs has its own tests;
16# sshd must be the binary at /usr/sbin/sshd that the tests exec.
17# python3-venv: this is also the default image for every repository the
18# bay1 runner is attached to, and a lint job that makes a venv for ruff
19# fails without ensurepip (gitbay-ci:2). sqlite3: the same reason, for
20# a job that maintains an archive database.
21RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
22        git-lfs \
23        gnupg \
24        openssh-server \
25        openssh-client \
26        ca-certificates \
27        curl \
28        unzip \
29        python3 \
30        python3-venv \
31        sqlite3 \
32    && rm -rf /var/lib/apt/lists/*
33
34# A build runs as this image's root inside its own user namespace, mapped
35# to the runner's unprivileged user on the host. The workspace arrives
36# bind mounted at /workspace.
37WORKDIR /workspace