Commit 41f52e0d70

41f52e0d70c23bb207145aee0f35ecdb74aa25be

parent: 94bf85e690

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-07 01:25 UTC

wiki: validate podman mode on a scratch repository first

Ref #144

Layout: unified · split

.gitbay/wiki/Admin.org +17
@@ -469,6 +469,23 @@ cannot call =newuidmap= and the runner refuses to start. That is a
469469considered trade, explained in the file and in the Threat-Model; if you
470470run with =-isolation none=, set it back to =yes=.
471471
472*Validate podman mode on a scratch repository before pointing the runner
473at real ones.* Every deploy that switched the whole instance to
474containers and failed took CI down with it. Instead: create a throwaway
475repository the runner account can read (public, or granted read — a
476private one is "not found" to the runner and the build stays pending),
477give it one job that names the CI image, and deploy the runner with
478=-repos= naming only that repository. The production unit, with its real
479hardening, then claims nothing else; other repositories' builds queue
480until =-repos= is switched back, which is a pause, not an outage.
481
482#+begin_src sh
483gitbay repo create cmc/ci-smoke # then push a .gitbay/ci.yml naming the image
484sed -i 's#-repos krz/gitbay #-repos cmc/ci-smoke #' /etc/systemd/system/gitbay-runner.service.d/override.conf
485systemctl daemon-reload && systemctl restart gitbay-runner
486gitbay build log cmc/ci-smoke 1 # green: switch -repos back, redeploy
487#+end_src
488
472489*Do not deploy an isolating runner to a host that has not been
473490prepared.* The runner is specified to refuse to start without a working
474491podman rather than fall back to running builds unsandboxed — a fallback