Commit 29051440c6

29051440c691412a0cc6dfaf57b1f10f3ad6ef83

parent: e3632a5503

Verified · cmc ci/build: success ci/test: failure

cmc <hello@cleberg.net> · 2026-09-06 22:27 UTC

ci, deploy, wiki: an image gitbay's own jobs can build in

Every job now names localhost/gitbay-ci:1, built from a Containerfile
carrying the toolchain the suite asserts: go, git, git-lfs, gpg, sshd.
Without it an isolated runner would run these jobs in a bare default
image and every build would fail on the prerequisite check.

Ref #144

Layout: unified · split

.gitbay/ci.yml +4
@@ -2,6 +2,7 @@ jobs:
2 # Fast feedback: this finishes in seconds, so it is not held behind the 2 # Fast feedback: this finishes in seconds, so it is not held behind the
3 # suite. 3 # suite.
4 build: 4 build:
5 image: localhost/gitbay-ci:1
5 steps: 6 steps:
6 - go build ./... 7 - go build ./...
7 - go vet ./... 8 - go vet ./...
@@ -12,6 +13,7 @@ jobs:
12 # The 20m is under the runner's own 30m limit, so go times out first and 13 # The 20m is under the runner's own 30m limit, so go times out first and
13 # says which test hung instead of the runner killing it blind. 14 # says which test hung instead of the runner killing it blind.
14 test: 15 test:
16 image: localhost/gitbay-ci:1
15 steps: 17 steps:
16 - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; } 18 - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; }
17 - go test ./... -count=1 -timeout 20m 19 - go test ./... -count=1 -timeout 20m
@@ -31,6 +33,7 @@ jobs:
31 # `build trigger krz/gitbay vuln` runs it on demand before a release 33 # `build trigger krz/gitbay vuln` runs it on demand before a release
32 # (#177). 34 # (#177).
33 vuln: 35 vuln:
36 image: localhost/gitbay-ci:1
34 schedule: "0 3 * * *" 37 schedule: "0 3 * * *"
35 steps: 38 steps:
36 - go run golang.org/x/vuln/cmd/govulncheck@latest ./... 39 - go run golang.org/x/vuln/cmd/govulncheck@latest ./...
@@ -53,6 +56,7 @@ jobs:
53 # linux-x64 bundle carries its own JRE, which is why the host needs no 56 # linux-x64 bundle carries its own JRE, which is why the host needs no
54 # Java. 57 # Java.
55 sonar: 58 sonar:
59 image: localhost/gitbay-ci:1
56 schedule: "30 3 * * *" 60 schedule: "30 3 * * *"
57 steps: 61 steps:
58 - | 62 - |
.gitbay/wiki/Admin.org +16
@@ -416,6 +416,22 @@ where every repository is trusted. There is no automatic fallback: a
416runner started with =-isolation podman= that cannot find a working 416runner started with =-isolation podman= that cannot find a working
417podman exits rather than running a build unsandboxed. 417podman exits rather than running a build unsandboxed.
418 418
419gitbay's own jobs name =localhost/gitbay-ci:1=, built from
420=deploy/Containerfile.ci= on the runner host. A job's image must carry
421what its steps need: the suite drives real git, git-lfs, gpg and sshd and
422asserts they exist before running, so the stock runner default would fail
423it immediately. Build or rebuild it with:
424
425#+begin_src sh
426ssh -p 2222 root@<host> 'cat > /tmp/Containerfile.ci' < deploy/Containerfile.ci
427ssh -p 2222 root@<host> 'su - ci-runner -s /bin/sh -c \
428 "podman build -t localhost/gitbay-ci:1 -f /tmp/Containerfile.ci /tmp"'
429#+end_src
430
431The tag is deliberate rather than =:latest=: changing the file means
432bumping the tag in =.gitbay/ci.yml=, so a running branch's image does not
433change under it.
434
419=-image= sets the default image for jobs that name none 435=-image= sets the default image for jobs that name none
420(=docker.io/library/debian:stable-slim= if unset); a job overrides it 436(=docker.io/library/debian:stable-slim= if unset); a job overrides it
421with =image:= in =.gitbay/ci.yml=, validated as a reference so a config 437with =image:= in =.gitbay/ci.yml=, validated as a reference so a config
deploy/Containerfile.ci added +30
@@ -0,0 +1,30 @@
1# The image gitbay's own CI jobs run in, once the runner isolates builds
2# (#144). Without it a job runs in the runner's default image, which has
3# no toolchain, and the suite's prerequisite check fails immediately.
4#
5# Build it on the runner host, where podman keeps it:
6#
7# ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \
8# "podman build -t localhost/gitbay-ci:1 -f - ." ' < deploy/Containerfile.ci
9#
10# Tagged, not :latest, so a change to this file is a deliberate bump in
11# .gitbay/ci.yml rather than a silent change under a running branch.
12FROM docker.io/library/golang:1.27-trixie
13
14# The suite drives real git, ssh, sshd and gpg rather than mocking them,
15# and asserts they are present before running. git-lfs has its own tests;
16# sshd must be the binary at /usr/sbin/sshd that the tests exec.
17RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
18 git-lfs \
19 gnupg \
20 openssh-server \
21 openssh-client \
22 ca-certificates \
23 curl \
24 unzip \
25 && rm -rf /var/lib/apt/lists/*
26
27# A build runs as this image's root inside its own user namespace, mapped
28# to the runner's unprivileged user on the host. The workspace arrives
29# bind mounted at /workspace.
30WORKDIR /workspace