Commit 8ae7a036fb
Verified · cmc
Layout: unified · split
Admin.org +17
| @@ -211,6 +211,23 @@ v1 runs steps directly on the host — no containers — so treat the | ||
| 211 | 211 | runner machine as executing whatever your users push. Install the |
| 212 | 212 | toolchains your builds need on it. |
| 213 | 213 | |
| 214 | A runner claims the oldest pending build in the queue, whichever | |
| 215 | repository it belongs to. =-repos= narrows that to named repositories, | |
| 216 | which is what makes a runner outside the server practical — one on a | |
| 217 | machine that should build a single project, or that holds credentials for | |
| 218 | one deployment, no longer picks up a build belonging to someone else. With | |
| 219 | open registration that someone need not be anyone you know. | |
| 220 | ||
| 221 | #+begin_src sh | |
| 222 | gitbay-runner -remote git@gitbay.org -repos krz/site,krz/docs \ | |
| 223 | -workdir /var/lib/gitbay-runner/work | |
| 224 | #+end_src | |
| 225 | ||
| 226 | Naming no repositories is the old behaviour and stays the right choice for | |
| 227 | the runner on the server itself. The scoping is what the runner asks for, | |
| 228 | not an ACL the server holds over it: a runner account is admin by | |
| 229 | necessity, so the boundary is you choosing how to start it. | |
| 230 | ||
| 214 | 231 | Instance admin on the runner account only authorizes the claim/report |
| 215 | 232 | protocol; it grants no repo access. A build that pushes back — a pages |
| 216 | 233 | deploy, an archive publish, an automated MR branch — needs an explicit |