Commit 94bf85e690
Verified · cmc
Layout: unified · split
deploy/gitbay-runner.override.conf +9 −5
| @@ -27,11 +27,15 @@ | |||
| 27 | # and the sandboxing that has to match them live in one file: -isolation | 27 | # and the sandboxing that has to match them live in one file: -isolation |
| 28 | # podman needs NoNewPrivileges=no below, and -image needs an image the | 28 | # podman needs NoNewPrivileges=no below, and -image needs an image the |
| 29 | # host has been given (deploy/runner-podman-setup.sh, Containerfile.ci). | 29 | # host has been given (deploy/runner-podman-setup.sh, Containerfile.ci). |
| 30 | # Deliberately no XDG_RUNTIME_DIR. podman records its run root in its | 30 | # podman's run root is pinned under the runner's home by storage.conf |
| 31 | # database at first use, so setting one later fails with "database | 31 | # (runner-podman-setup.sh), not taken from XDG_RUNTIME_DIR or /tmp: this |
| 32 | # configuration mismatch"; the runner's storage was initialised without | 32 | # unit has PrivateTmp, so a /tmp run root is a per-instance tmpfs. |
| 33 | # it and works. Change it only together with `podman system reset` and a | 33 | # |
| 34 | # rebuild of the images (#144). | 34 | # The cgroupfs manager puts podman's pause process under the user slice, |
| 35 | # outside this unit's cgroup, so a stop does not end it and the next | ||
| 36 | # start joins its namespaces — including a /tmp that no longer exists. | ||
| 37 | # End it with the service. | ||
| 38 | ExecStopPost=-/usr/bin/pkill -u ci-runner -x catatonit | ||
| 35 | ExecStart= | 39 | ExecStart= |
| 36 | ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -repos krz/gitbay -isolation podman -image localhost/gitbay-ci:1 | 40 | ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -repos krz/gitbay -isolation podman -image localhost/gitbay-ci:1 |
| 37 | Nice=10 | 41 | Nice=10 |
deploy/runner-podman-setup.sh +27 −4
| @@ -52,13 +52,36 @@ if [ "$max_ns" -lt 1 ]; then | |||
| 52 | fi | 52 | fi |
| 53 | echo " max_user_namespaces=$max_ns" | 53 | echo " max_user_namespaces=$max_ns" |
| 54 | 54 | ||
| 55 | # Lingering keeps the user's systemd session — and so podman's storage | 55 | # podman's storage paths are pinned in storage.conf, both graphroot and |
| 56 | # and any running container — alive when nobody is logged in. | 56 | # runroot, under the runner's home. Left to podman, the run root is |
| 57 | # $XDG_RUNTIME_DIR or /tmp/storage-run-<uid>; the service runs with | ||
| 58 | # PrivateTmp, so that is a per-instance tmpfs, and podman's pause process | ||
| 59 | # (which the cgroupfs manager places outside the service cgroup) can | ||
| 60 | # outlive a restart holding a dead /tmp — after which every podman | ||
| 61 | # command, in any context, fails with "mkdir ...: no such file or | ||
| 62 | # directory". A run root under the home directory is valid in every | ||
| 63 | # namespace and needs neither lingering nor /tmp. | ||
| 64 | # | ||
| 65 | # podman records the run root at first use. Changing it later needs | ||
| 66 | # `podman system reset --force` as the runner user and a rebuild of the | ||
| 67 | # images; this script does not do that for you. | ||
| 68 | home=$(getent passwd "$RUNNER_USER" | cut -d: -f6) | ||
| 69 | conf="$home/.config/containers/storage.conf" | ||
| 70 | echo "==> storage config in $conf" | ||
| 71 | install -d -o "$RUNNER_USER" -g "$RUNNER_USER" -m 700 "$home/.config/containers" | ||
| 72 | printf '[storage]\ndriver = "overlay"\ngraphroot = "%s/.local/share/containers/storage"\nrunroot = "%s/.local/share/containers/run"\n' "$home" "$home" >"$conf" | ||
| 73 | chown "$RUNNER_USER:$RUNNER_USER" "$conf" | ||
| 74 | echo " written" | ||
| 75 | |||
| 76 | # Lingering keeps the user's systemd session alive when nobody is logged | ||
| 77 | # in, which podman's pause process relies on. | ||
| 57 | echo "==> lingering for $RUNNER_USER" | 78 | echo "==> lingering for $RUNNER_USER" |
| 58 | loginctl enable-linger "$RUNNER_USER" | 79 | loginctl enable-linger "$RUNNER_USER" |
| 59 | 80 | ||
| 60 | echo "==> verifying rootless podman as $RUNNER_USER" | 81 | echo "==> verifying rootless podman as $RUNNER_USER" |
| 61 | su - "$RUNNER_USER" -s /bin/sh -c 'podman info --format "{{.Host.Security.Rootless}}"' | 82 | # The verification fails rather than passing with || true: a host that |
| 83 | # reports ready and is not is the outage this script exists to prevent. | ||
| 84 | su - "$RUNNER_USER" -s /bin/sh -c "podman info --format 'rootless={{.Host.Security.Rootless}} runroot={{.Store.RunRoot}}'" | ||
| 62 | 85 | ||
| 63 | echo | 86 | echo |
| 64 | echo "host is ready; now: make deploy-runner" | 87 | echo "host is ready. Build the CI image (deploy/Containerfile.ci), then: make deploy-runner" |