Commit 8ab6240513

8ab62405132a89cc9b2c19486c47684d2f6b9fe9

parent: fb6e9dcfa4

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 00:07 UTC

deploy: runner comment and Admin procedure name the real attachments

cmc/ci-smoke no longer exists and ExecStart carries no -repos; the
scratch-repository check attaches the key and adds -repos for the run.

Closes #287

Layout: unified · split

.gitbay/wiki/Admin.org +10 −9
@@ -925,16 +925,19 @@ at real ones.* Every deploy that switched the whole instance to
925925containers and failed took CI down with it. Instead: create a throwaway
926926repository the runner account can read (public, or granted read — a
927927private one is "not found" to the runner and the build stays pending),
928give it one job that names the CI image, and deploy the runner with
929=-repos= naming only that repository. The production unit, with its real
930hardening, then claims nothing else; other repositories' builds queue
931until =-repos= is switched back, which is a pause, not an outage.
928give it one job that names the CI image, attach the runner's key to it,
929and deploy the runner with =-repos= naming only that repository. The
930production unit, with its real hardening, then claims nothing else;
931other repositories' builds queue until =-repos= is removed again, which
932is a pause, not an outage.
932933
933934#+begin_src sh
934gitbay repo create cmc/ci-smoke # then push a .gitbay/ci.yml naming the image
935sed -i 's#-repos krz/gitbay #-repos cmc/ci-smoke #' /etc/systemd/system/gitbay-runner.service.d/override.conf
935gitbay repo create cmc/runner-scratch # then push a .gitbay/ci.yml naming the image
936# on the host:
937gitbay repo runner add cmc/runner-scratch < /var/lib/gitbay-runner/.ssh/id_ed25519.pub
938sed -i 's#^ExecStart=/usr/local/bin/gitbay-runner #&-repos cmc/runner-scratch #' /etc/systemd/system/gitbay-runner.service.d/override.conf
936939systemctl daemon-reload && systemctl restart gitbay-runner
937gitbay build log cmc/ci-smoke 1 # green: switch -repos back, redeploy
940gitbay build log cmc/runner-scratch 1 # green: remove -repos, redeploy, delete the scratch repository
938941#+end_src
939942
940943*Do not deploy an isolating runner to a host that has not been
@@ -950,8 +953,6 @@ management and =ReadWritePaths= for podman's store under
950953make read-only. Those paths are prefixed =-= so they are ignored when
951954absent: the drop-in installs on unprepared hosts too, and a unit that
952955refused to start would stop every build.
953The nightly canary on =cmc/ci-smoke= only runs if the runner's =-repos=
954names that repository too; a scoped runner claims nothing else.
955956=gitbay-runner-prune.timer= prunes unused images weekly, as the runner's
956957user: rootless storage belongs to that user, and root's prune would not
957958see it. An unpruned image store on a 40GB host is a slow outage.
deploy/gitbay-runner.override.conf +5 −3
@@ -34,9 +34,11 @@ After=gitbay-runner-egress.service
3434[Service]
3535# The runner polls as a non-admin account with a runner-scoped key, and
3636# claims only the repositories that key is attached to (`repo runner
37# add`): krz/gitbay and cmc/ci-smoke. The attachments are the boundary,
38# so ExecStart names no -repos. cmc/ci-smoke is the nightly isolation
39# canary; keep it attached or its scheduled build waits forever.
37# add`): krz/gitbay, krz/hutch, krz/keycask, krz/orgo, krz/skunky-art
38# and cmc/cleberg.net. The attachments are the boundary, so ExecStart
39# names no -repos. To validate a runner change, create a scratch
40# repository, attach this key to it, and run with -repos naming only
41# that repository until the change is proven (Admin wiki, CI runner).
4042#
4143# Two layers of resource caps. MemoryMax and CPUQuota bound the unit —
4244# the runner and every build together — which is what keeps the forge