Commit 41f52e0d70
Verified · cmc
Layout: unified · split
.gitbay/wiki/Admin.org +17
| @@ -469,6 +469,23 @@ cannot call =newuidmap= and the runner refuses to start. That is a | ||
| 469 | 469 | considered trade, explained in the file and in the Threat-Model; if you |
| 470 | 470 | run with =-isolation none=, set it back to =yes=. |
| 471 | 471 | |
| 472 | *Validate podman mode on a scratch repository before pointing the runner | |
| 473 | at real ones.* Every deploy that switched the whole instance to | |
| 474 | containers and failed took CI down with it. Instead: create a throwaway | |
| 475 | repository the runner account can read (public, or granted read — a | |
| 476 | private one is "not found" to the runner and the build stays pending), | |
| 477 | give it one job that names the CI image, and deploy the runner with | |
| 478 | =-repos= naming only that repository. The production unit, with its real | |
| 479 | hardening, then claims nothing else; other repositories' builds queue | |
| 480 | until =-repos= is switched back, which is a pause, not an outage. | |
| 481 | ||
| 482 | #+begin_src sh | |
| 483 | gitbay repo create cmc/ci-smoke # then push a .gitbay/ci.yml naming the image | |
| 484 | sed -i 's#-repos krz/gitbay #-repos cmc/ci-smoke #' /etc/systemd/system/gitbay-runner.service.d/override.conf | |
| 485 | systemctl daemon-reload && systemctl restart gitbay-runner | |
| 486 | gitbay build log cmc/ci-smoke 1 # green: switch -repos back, redeploy | |
| 487 | #+end_src | |
| 488 | ||
| 472 | 489 | *Do not deploy an isolating runner to a host that has not been |
| 473 | 490 | prepared.* The runner is specified to refuse to start without a working |
| 474 | 491 | podman rather than fall back to running builds unsandboxed — a fallback |