deploy/Containerfile.ci
45 lines · 2163 bytes
1# The image gitbay's own CI jobs run in, once the runner isolates builds
2# (#144). Without it a job runs in the runner's default image, which has
3# no toolchain, and the suite's prerequisite check fails immediately.
4#
5# Build it on the runner host, where podman keeps it. The file is staged in
6# the runner user's home first: a login shell under su cannot read root's
7# stdin, and root's session does not share /tmp with it.
8#
9# scp -P 2222 deploy/Containerfile.ci root@gitbay.org:/var/lib/gitbay-runner/gitbay-ci.Containerfile
10# ssh -p 2222 root@gitbay.org 'chown ci-runner /var/lib/gitbay-runner/gitbay-ci.Containerfile \
11# && su - ci-runner -s /bin/sh -c "podman build -t localhost/gitbay-ci:2 -f gitbay-ci.Containerfile ." \
12# && rm /var/lib/gitbay-runner/gitbay-ci.Containerfile'
13#
14# Tagged, not :latest, so a change to this file is a deliberate bump in
15# .gitbay/ci.yml rather than a silent change under a running branch.
16FROM docker.io/library/golang:1.27-trixie
17
18# gitbay-runner-prune.service skips images carrying this label. A localhost/
19# image cannot be pulled back, so pruning it fails every job that names it.
20LABEL org.gitbay.keep=true
21
22# The suite drives real git, ssh, sshd and gpg rather than mocking them,
23# and asserts they are present before running. git-lfs has its own tests;
24# sshd must be the binary at /usr/sbin/sshd that the tests exec.
25# python3-venv: this is also the default image for every repository the
26# bay1 runner is attached to, and a lint job that makes a venv for ruff
27# fails without ensurepip (gitbay-ci:2). sqlite3: the same reason, for
28# a job that maintains an archive database.
29RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
30 git-lfs \
31 gnupg \
32 openssh-server \
33 openssh-client \
34 ca-certificates \
35 curl \
36 unzip \
37 python3 \
38 python3-venv \
39 sqlite3 \
40 && rm -rf /var/lib/apt/lists/*
41
42# A build runs as this image's root inside its own user namespace, mapped
43# to the runner's unprivileged user on the host. The workspace arrives
44# bind mounted at /workspace.
45WORKDIR /workspace