Commit 29051440c6
29051440c691412a0cc6dfaf57b1f10f3ad6ef83
parent: e3632a5503
Verified · cmc ci/build: success ci/test: failure
cmc <hello@cleberg.net> · 2026-09-06 22:27 UTC
ci, deploy, wiki: an image gitbay's own jobs can build in
Every job now names localhost/gitbay-ci:1, built from a Containerfile
carrying the toolchain the suite asserts: go, git, git-lfs, gpg, sshd.
Without it an isolated runner would run these jobs in a bare default
image and every build would fail on the prerequisite check.
Ref #144
Layout: unified · split
.gitbay/ci.yml
+4
| @@ -2,6 +2,7 @@ jobs: |
| 2 | # Fast feedback: this finishes in seconds, so it is not held behind the |
2 | # Fast feedback: this finishes in seconds, so it is not held behind the |
| 3 | # suite. |
3 | # suite. |
| 4 | build: |
4 | build: |
| |
5 | image: localhost/gitbay-ci:1 |
| 5 | steps: |
6 | steps: |
| 6 | - go build ./... |
7 | - go build ./... |
| 7 | - go vet ./... |
8 | - go vet ./... |
| @@ -12,6 +13,7 @@ jobs: |
| 12 | # The 20m is under the runner's own 30m limit, so go times out first and |
13 | # The 20m is under the runner's own 30m limit, so go times out first and |
| 13 | # says which test hung instead of the runner killing it blind. |
14 | # says which test hung instead of the runner killing it blind. |
| 14 | test: |
15 | test: |
| |
16 | image: localhost/gitbay-ci:1 |
| 15 | steps: |
17 | steps: |
| 16 | - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; } |
18 | - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; } |
| 17 | - go test ./... -count=1 -timeout 20m |
19 | - go test ./... -count=1 -timeout 20m |
| @@ -31,6 +33,7 @@ jobs: |
| 31 | # `build trigger krz/gitbay vuln` runs it on demand before a release |
33 | # `build trigger krz/gitbay vuln` runs it on demand before a release |
| 32 | # (#177). |
34 | # (#177). |
| 33 | vuln: |
35 | vuln: |
| |
36 | image: localhost/gitbay-ci:1 |
| 34 | schedule: "0 3 * * *" |
37 | schedule: "0 3 * * *" |
| 35 | steps: |
38 | steps: |
| 36 | - go run golang.org/x/vuln/cmd/govulncheck@latest ./... |
39 | - go run golang.org/x/vuln/cmd/govulncheck@latest ./... |
| @@ -53,6 +56,7 @@ jobs: |
| 53 | # linux-x64 bundle carries its own JRE, which is why the host needs no |
56 | # linux-x64 bundle carries its own JRE, which is why the host needs no |
| 54 | # Java. |
57 | # Java. |
| 55 | sonar: |
58 | sonar: |
| |
59 | image: localhost/gitbay-ci:1 |
| 56 | schedule: "30 3 * * *" |
60 | schedule: "30 3 * * *" |
| 57 | steps: |
61 | steps: |
| 58 | - | |
62 | - | |
.gitbay/wiki/Admin.org
+16
| @@ -416,6 +416,22 @@ where every repository is trusted. There is no automatic fallback: a |
| 416 | runner started with =-isolation podman= that cannot find a working |
416 | runner started with =-isolation podman= that cannot find a working |
| 417 | podman exits rather than running a build unsandboxed. |
417 | podman exits rather than running a build unsandboxed. |
| 418 | |
418 | |
| |
419 | gitbay's own jobs name =localhost/gitbay-ci:1=, built from |
| |
420 | =deploy/Containerfile.ci= on the runner host. A job's image must carry |
| |
421 | what its steps need: the suite drives real git, git-lfs, gpg and sshd and |
| |
422 | asserts they exist before running, so the stock runner default would fail |
| |
423 | it immediately. Build or rebuild it with: |
| |
424 | |
| |
425 | #+begin_src sh |
| |
426 | ssh -p 2222 root@<host> 'cat > /tmp/Containerfile.ci' < deploy/Containerfile.ci |
| |
427 | ssh -p 2222 root@<host> 'su - ci-runner -s /bin/sh -c \ |
| |
428 | "podman build -t localhost/gitbay-ci:1 -f /tmp/Containerfile.ci /tmp"' |
| |
429 | #+end_src |
| |
430 | |
| |
431 | The tag is deliberate rather than =:latest=: changing the file means |
| |
432 | bumping the tag in =.gitbay/ci.yml=, so a running branch's image does not |
| |
433 | change under it. |
| |
434 | |
| 419 | =-image= sets the default image for jobs that name none |
435 | =-image= sets the default image for jobs that name none |
| 420 | (=docker.io/library/debian:stable-slim= if unset); a job overrides it |
436 | (=docker.io/library/debian:stable-slim= if unset); a job overrides it |
| 421 | with =image:= in =.gitbay/ci.yml=, validated as a reference so a config |
437 | with =image:= in =.gitbay/ci.yml=, validated as a reference so a config |
deploy/Containerfile.ci
added
+30
| @@ -0,0 +1,30 @@ |
| |
1 | # The image gitbay's own CI jobs run in, once the runner isolates builds |
| |
2 | # (#144). Without it a job runs in the runner's default image, which has |
| |
3 | # no toolchain, and the suite's prerequisite check fails immediately. |
| |
4 | # |
| |
5 | # Build it on the runner host, where podman keeps it: |
| |
6 | # |
| |
7 | # ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \ |
| |
8 | # "podman build -t localhost/gitbay-ci:1 -f - ." ' < deploy/Containerfile.ci |
| |
9 | # |
| |
10 | # Tagged, not :latest, so a change to this file is a deliberate bump in |
| |
11 | # .gitbay/ci.yml rather than a silent change under a running branch. |
| |
12 | FROM docker.io/library/golang:1.27-trixie |
| |
13 | |
| |
14 | # The suite drives real git, ssh, sshd and gpg rather than mocking them, |
| |
15 | # and asserts they are present before running. git-lfs has its own tests; |
| |
16 | # sshd must be the binary at /usr/sbin/sshd that the tests exec. |
| |
17 | RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ |
| |
18 | git-lfs \ |
| |
19 | gnupg \ |
| |
20 | openssh-server \ |
| |
21 | openssh-client \ |
| |
22 | ca-certificates \ |
| |
23 | curl \ |
| |
24 | unzip \ |
| |
25 | && rm -rf /var/lib/apt/lists/* |
| |
26 | |
| |
27 | # A build runs as this image's root inside its own user namespace, mapped |
| |
28 | # to the runner's unprivileged user on the host. The workspace arrives |
| |
29 | # bind mounted at /workspace. |
| |
30 | WORKDIR /workspace |