Commit 29051440c6
29051440c691412a0cc6dfaf57b1f10f3ad6ef83
parent: e3632a5503
Verified · cmc ci/build: success ci/test: failure
cmc <hello@cleberg.net> · 2026-09-06 22:27 UTC
ci, deploy, wiki: an image gitbay's own jobs can build in
Every job now names localhost/gitbay-ci:1, built from a Containerfile
carrying the toolchain the suite asserts: go, git, git-lfs, gpg, sshd.
Without it an isolated runner would run these jobs in a bare default
image and every build would fail on the prerequisite check.
Ref #144
Layout: unified · split
.gitbay/ci.yml
+4
| @@ -2,6 +2,7 @@ jobs: |
| 2 | 2 | # Fast feedback: this finishes in seconds, so it is not held behind the |
| 3 | 3 | # suite. |
| 4 | 4 | build: |
| 5 | image: localhost/gitbay-ci:1 |
| 5 | 6 | steps: |
| 6 | 7 | - go build ./... |
| 7 | 8 | - go vet ./... |
| @@ -12,6 +13,7 @@ jobs: |
| 12 | 13 | # The 20m is under the runner's own 30m limit, so go times out first and |
| 13 | 14 | # says which test hung instead of the runner killing it blind. |
| 14 | 15 | test: |
| 16 | image: localhost/gitbay-ci:1 |
| 15 | 17 | steps: |
| 16 | 18 | - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; } |
| 17 | 19 | - go test ./... -count=1 -timeout 20m |
| @@ -31,6 +33,7 @@ jobs: |
| 31 | 33 | # `build trigger krz/gitbay vuln` runs it on demand before a release |
| 32 | 34 | # (#177). |
| 33 | 35 | vuln: |
| 36 | image: localhost/gitbay-ci:1 |
| 34 | 37 | schedule: "0 3 * * *" |
| 35 | 38 | steps: |
| 36 | 39 | - go run golang.org/x/vuln/cmd/govulncheck@latest ./... |
| @@ -53,6 +56,7 @@ jobs: |
| 53 | 56 | # linux-x64 bundle carries its own JRE, which is why the host needs no |
| 54 | 57 | # Java. |
| 55 | 58 | sonar: |
| 59 | image: localhost/gitbay-ci:1 |
| 56 | 60 | schedule: "30 3 * * *" |
| 57 | 61 | steps: |
| 58 | 62 | - | |
.gitbay/wiki/Admin.org
+16
| @@ -416,6 +416,22 @@ where every repository is trusted. There is no automatic fallback: a |
| 416 | 416 | runner started with =-isolation podman= that cannot find a working |
| 417 | 417 | podman exits rather than running a build unsandboxed. |
| 418 | 418 | |
| 419 | gitbay's own jobs name =localhost/gitbay-ci:1=, built from |
| 420 | =deploy/Containerfile.ci= on the runner host. A job's image must carry |
| 421 | what its steps need: the suite drives real git, git-lfs, gpg and sshd and |
| 422 | asserts they exist before running, so the stock runner default would fail |
| 423 | it immediately. Build or rebuild it with: |
| 424 | |
| 425 | #+begin_src sh |
| 426 | ssh -p 2222 root@<host> 'cat > /tmp/Containerfile.ci' < deploy/Containerfile.ci |
| 427 | ssh -p 2222 root@<host> 'su - ci-runner -s /bin/sh -c \ |
| 428 | "podman build -t localhost/gitbay-ci:1 -f /tmp/Containerfile.ci /tmp"' |
| 429 | #+end_src |
| 430 | |
| 431 | The tag is deliberate rather than =:latest=: changing the file means |
| 432 | bumping the tag in =.gitbay/ci.yml=, so a running branch's image does not |
| 433 | change under it. |
| 434 | |
| 419 | 435 | =-image= sets the default image for jobs that name none |
| 420 | 436 | (=docker.io/library/debian:stable-slim= if unset); a job overrides it |
| 421 | 437 | with =image:= in =.gitbay/ci.yml=, validated as a reference so a config |
deploy/Containerfile.ci
added
+30
| @@ -0,0 +1,30 @@ |
| 1 | # The image gitbay's own CI jobs run in, once the runner isolates builds |
| 2 | # (#144). Without it a job runs in the runner's default image, which has |
| 3 | # no toolchain, and the suite's prerequisite check fails immediately. |
| 4 | # |
| 5 | # Build it on the runner host, where podman keeps it: |
| 6 | # |
| 7 | # ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \ |
| 8 | # "podman build -t localhost/gitbay-ci:1 -f - ." ' < deploy/Containerfile.ci |
| 9 | # |
| 10 | # Tagged, not :latest, so a change to this file is a deliberate bump in |
| 11 | # .gitbay/ci.yml rather than a silent change under a running branch. |
| 12 | FROM docker.io/library/golang:1.27-trixie |
| 13 | |
| 14 | # The suite drives real git, ssh, sshd and gpg rather than mocking them, |
| 15 | # and asserts they are present before running. git-lfs has its own tests; |
| 16 | # sshd must be the binary at /usr/sbin/sshd that the tests exec. |
| 17 | RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ |
| 18 | git-lfs \ |
| 19 | gnupg \ |
| 20 | openssh-server \ |
| 21 | openssh-client \ |
| 22 | ca-certificates \ |
| 23 | curl \ |
| 24 | unzip \ |
| 25 | && rm -rf /var/lib/apt/lists/* |
| 26 | |
| 27 | # A build runs as this image's root inside its own user namespace, mapped |
| 28 | # to the runner's unprivileged user on the host. The workspace arrives |
| 29 | # bind mounted at /workspace. |
| 30 | WORKDIR /workspace |