Commit 8ae7a036fb

8ae7a036fb3b2c8208d58cebf7248745ef689f29

parent: e98a837815

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-31 21:35 UTC

Admin: runner repository scoping

Layout: unified · split

Admin.org +17
@@ -211,6 +211,23 @@ v1 runs steps directly on the host — no containers — so treat the
211211runner machine as executing whatever your users push. Install the
212212toolchains your builds need on it.
213213
214A runner claims the oldest pending build in the queue, whichever
215repository it belongs to. =-repos= narrows that to named repositories,
216which is what makes a runner outside the server practical — one on a
217machine that should build a single project, or that holds credentials for
218one deployment, no longer picks up a build belonging to someone else. With
219open registration that someone need not be anyone you know.
220
221#+begin_src sh
222gitbay-runner -remote git@gitbay.org -repos krz/site,krz/docs \
223 -workdir /var/lib/gitbay-runner/work
224#+end_src
225
226Naming no repositories is the old behaviour and stays the right choice for
227the runner on the server itself. The scoping is what the runner asks for,
228not an ACL the server holds over it: a runner account is admin by
229necessity, so the boundary is you choosing how to start it.
230
214231Instance admin on the runner account only authorizes the claim/report
215232protocol; it grants no repo access. A build that pushes back — a pages
216233deploy, an archive publish, an automated MR branch — needs an explicit