Commit d4c806be81

d4c806be810fafea97f712142e82b36f5e237988

parent: c14c881e38

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-07 20:48 UTC

deploy: ProtectControlGroups=no so the runner can write its build cgroups

The flag mounts /sys/fs/cgroup read-only in the unit's namespace, so the
delegated service cgroup is unwritable and the runner refuses to start
with a limit set.

Ref #188
deploy/gitbay-runner.override.conf +9 −1
@@ -103,7 +103,15 @@ ProtectSystem=full
103103# as this user — the container now covers: a build gets its own proc,
104104# with those paths masked by the runtime. Under -isolation none, set it
105105# back to yes.
106ProtectControlGroups=yes
106# ProtectControlGroups is off because the runner writes cgroups: it
107# creates one per build under this unit's delegated cgroup to carry
108# -memory and -cpus (#188). The flag mounts /sys/fs/cgroup read-only in
109# the unit's namespace, which makes even a delegated cgroup unwritable,
110# and the runner then refuses to start when a limit is set. Delegate=yes
111# already hands this unit its subtree; what the flag protected beyond
112# that is other units' cgroups, which are root-owned and not writable
113# by this user regardless.
114ProtectControlGroups=no
107115RestrictSUIDSGID=yes
108116Delegate=yes
109117# The runner's home is /var/lib/gitbay-runner (see the Admin page), and