deploy/gitbay-runner.override.conf
22 lines · 877 bytes
1# Drop-in for gitbay-runner.service, installed by `make deploy-runner` to
2# /etc/systemd/system/gitbay-runner.service.d/override.conf.
3#
4# A build must never starve the host: the e2e suite alone starts sixty
5# daemon instances, and with nothing holding it back a deploy's scp on
6# the admin sshd stalled at 1%. Lower CPU and IO weight keep sshd,
7# gitbayd and the backup timers responsive while a build runs.
8#
9# A build runs whatever the repository's ci.yml says, as the runner's
10# own user. Keep that user unprivileged: its key is added with
11# `keys add --scope runner`, which confines it to the runner protocol
12# and read-only git, and the sandboxing below keeps a step from
13# touching the system outside its workspace.
14[Service]
15Nice=10
16CPUWeight=30
17IOWeight=30
18NoNewPrivileges=yes
19ProtectSystem=full
20ProtectKernelTunables=yes
21ProtectControlGroups=yes
22RestrictSUIDSGID=yes