Commit e6cd75b5f2
e6cd75b5f28bacf51620bb531320c30fd4e66bfd
parent: 0e82c39342
Verified · cmc ci/build: success ci/test: success ci/vuln: success
cmc <hello@cleberg.net> · 2026-10-04 06:16 UTC
deploy: keep the locally built CI image when pruning
The weekly prune removed localhost/gitbay-ci:2 because it was created
more than 168h ago and no container held it. It cannot be pulled back,
so every job naming it failed. Label the image and exclude the label
from the prune.
Layout: unified · split
.gitbay/wiki/Admin.org
+3
| @@ -1295,6 +1295,9 @@ refused to start would stop every build. |
| 1295 | 1295 | =gitbay-runner-prune.timer= prunes unused images weekly, as the runner's |
| 1296 | 1296 | user: rootless storage belongs to that user, and root's prune would not |
| 1297 | 1297 | see it. An unpruned image store on a 40GB host is a slow outage. |
| 1298 | Images labelled =org.gitbay.keep=true= are skipped, since a locally |
| 1299 | built =localhost/= image cannot be pulled back; =deploy/Containerfile.ci= |
| 1300 | sets it. |
| 1298 | 1301 | |
| 1299 | 1302 | * LFS storage |
| 1300 | 1303 | |
deploy/Containerfile.ci
+4
| @@ -15,6 +15,10 @@ |
| 15 | 15 | # .gitbay/ci.yml rather than a silent change under a running branch. |
| 16 | 16 | FROM docker.io/library/golang:1.27-trixie |
| 17 | 17 | |
| 18 | # gitbay-runner-prune.service skips images carrying this label. A localhost/ |
| 19 | # image cannot be pulled back, so pruning it fails every job that names it. |
| 20 | LABEL org.gitbay.keep=true |
| 21 | |
| 18 | 22 | # The suite drives real git, ssh, sshd and gpg rather than mocking them, |
| 19 | 23 | # and asserts they are present before running. git-lfs has its own tests; |
| 20 | 24 | # sshd must be the binary at /usr/sbin/sshd that the tests exec. |
deploy/gitbay-runner-prune.service
+4 −3
| @@ -10,7 +10,8 @@ User=ci-runner |
| 10 | 10 | # Rootless podman reads storage.conf under HOME; a User= unit does not |
| 11 | 11 | # set it. |
| 12 | 12 | Environment=HOME=/var/lib/gitbay-runner |
| 13 | | # Images not used by a container and older than a week. A build that |
| 14 | | # names an image again re-pulls it; the cost is one pull, not a failure. |
| 15 | | ExecStart=/usr/bin/podman image prune --all --force --filter until=168h |
| 13 | # Images not used by a container and created more than a week ago. A |
| 14 | # registry image is pulled again on next use. A locally built image cannot |
| 15 | # be, so one labelled org.gitbay.keep=true (deploy/Containerfile.ci) is kept. |
| 16 | ExecStart=/usr/bin/podman image prune --all --force --filter until=168h --filter label!=org.gitbay.keep=true |
| 16 | 17 | ExecStart=/usr/bin/podman container prune --force |