Commit a869e55ced

a869e55cedfc2d279bbaba2e2a0a02eb1114d9b7

parent: 5ffa892991

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-07 07:10 UTC

CHANGELOG: v1.15.0

Layout: unified · split

CHANGELOG.org +70
@@ -4,6 +4,76 @@ Versioning follows semver from v0.1.0. Database migrations run
4automatically on daemon start; upgrade notes appear per release when 4automatically on daemon start; upgrade notes appear per release when
5anything beyond "replace the binary and restart" is needed. 5anything beyond "replace the binary and restart" is needed.
6 6
7* v1.15.0 — 2026-09-07
8
9Builds run in containers, a rebase is not rebuilt, and a runner restart
10no longer strands the build it was running.
11
12** CI
13
14- A build's steps run in a rootless podman container, one per job. The
15 runner clones outside the container with its key and bind-mounts the
16 workspace in, so a step cannot reach the key, the runner's environment,
17 or another build's workspace. =image:= is required per job and is
18 validated as a reference, never pulled: an operator provisions images
19 on the host. A runner configured for podman that has none refuses to
20 start rather than fall back to the host. =-isolation none= is the
21 explicit host-execution mode. =-cpus= and =-memory= cap a build's
22 container. #144
23- Builds have a home directory that outlives the build, so the Go module
24 cache and the sonar scanner survive between runs. It is mounted into
25 the container at the same path, and only that directory. Ref #144
26- The host preparation script, the unit drop-in and the weekly image
27 prune ship with =make deploy-runner=; each hardening flag the drop-in
28 relaxes carries the reason in place. Ref #144
29- A nightly canary on the runner host proves the boundary holds:
30 =cmc/ci-smoke= runs a job that tries to read the key and list sibling
31 workspaces, and fails if either succeeds. Ref #144
32- Dedupe keys on the commit's tree, not its sha. A rebase that changes
33 nothing is not rebuilt: the new commit gets the earlier success as its
34 status, naming the build. Scheduled and tag builds carry no tree and
35 are never reused. #177
36- =vuln= and =sonar= run nightly on =main= rather than on every push;
37 neither could inform a merge. Branches run =build= and =test=. #177
38- A rewritten branch is filtered against the merge base rather than the
39 old tip, so a rebased branch whose own commits change code no longer
40 reads as a docs-only push and skips its jobs. #176
41- A build whose runner's log stream ended with no outcome is failed two
42 minutes later, instead of sitting =running= until a fixed deadline.
43 Migration 0046. Ref #179
44- The runner retries reporting a finished build's outcome, four times
45 over about thirty seconds, when the server is unreachable. A gitbayd
46 restart at that moment used to lose the result. Ref #179
47- The runner drains on SIGTERM: it claims nothing more, finishes and
48 reports the build in flight, then exits. A second signal exits at once.
49 The unit allows fifty minutes. #179
50
51** Repositories
52
53- =repo show= reports the caller's watch and bookmark state, and the
54 parent of a fork when the caller can read it. #178
55- =repo unwatch= clears the row from either state; =repo mute= is the
56 explicit silence. Watch then unwatch used to leave an account below
57 the default with no way back. The web header toggle follows. #180
58
59** Upgrading
60
61Replace the binary and reinstall the CLI. One migration (0046, the
62build log's close time), applied on start.
63
64The runner now defaults to =-isolation podman= and refuses to start
65without a working podman and a named image. Prepare the host with
66=deploy/runner-podman-setup.sh= and build =localhost/gitbay-ci:1= from
67=deploy/Containerfile.ci= before deploying it, or pass =-isolation
68none= to keep running steps on the host. Validate on a scratch
69repository with =-repos= scoped to it first; the wiki's Admin page has
70the procedure.
71
72The runner's unit gains =TimeoutStopSec=50min= and =KillMode=mixed= so
73a stop reaches the runner alone and it can drain; under the default
74kill mode systemd ends the build's container with the runner.
75=make deploy-runner= therefore waits for a build in flight.
76
7* v1.14.0 — 2026-09-06 77* v1.14.0 — 2026-09-06
8 78
9Logging into the web without an SSH key, wikis inside the repository, 79Logging into the web without an SSH key, wikis inside the repository,