deploy/gitbay-runner-egress.service

v1.39.0
gitbay/deploy/gitbay-runner-egress.service history · blame · raw

37 lines · 1766 bytes

 1# Loads the CI runner's host egress rule (#260,
 2# deploy/gitbay-runner-egress.nft). gitbay-runner.service requires this
 3# unit, so the runner starts only with the rule in force; stopping this
 4# unit removes the table and stops the runner with it.
 5#
 6# Ordered after nftables.service and ufw.service: either may rewrite the
 7# ruleset at boot, and nftables.service's default config starts with
 8# flush ruleset. A missing unit in After= is ignored.
 9#
10# Reload re-reads the file and replaces the table in one transaction; it
11# does not restart the runner, which a restart of this unit would
12# (Requires= propagates restarts). `make deploy-runner` reloads.
13#
14# Stop uses destroy, which succeeds when the table is already gone (a
15# flush ruleset removes it); delete would fail and leave the unit failed.
16#
17# The builds table (gitbay-runner-builds.nft) is loaded by the runner's
18# own start, against its cgroups. Reload loads it again when the file is
19# installed and those cgroups exist, so after a restart of
20# nftables.service one reload puts both tables back; without the file
21# (taken out per the Admin page) the reload skips it and succeeds.
22[Unit]
23Description=Host egress rule for CI builds
24After=nftables.service ufw.service
25Before=gitbay-runner.service
26
27[Service]
28Type=oneshot
29RemainAfterExit=yes
30ExecStart=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft
31ExecReload=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft
32ExecReload=/bin/sh -c 'if [ -f /etc/gitbay-runner/builds.nft ] && [ -d /sys/fs/cgroup/system.slice/gitbay-runner.service/builds/untrusted ]; then exec /usr/sbin/nft -f /etc/gitbay-runner/builds.nft; fi'
33ExecStop=/usr/sbin/nft destroy table inet gitbay_runner
34ExecStop=/usr/sbin/nft destroy table inet gitbay_builds
35
36[Install]
37WantedBy=multi-user.target