Commit e6cd75b5f2

e6cd75b5f28bacf51620bb531320c30fd4e66bfd

parent: 0e82c39342

Verified · cmc ci/build: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-10-04 06:16 UTC

deploy: keep the locally built CI image when pruning

The weekly prune removed localhost/gitbay-ci:2 because it was created
more than 168h ago and no container held it. It cannot be pulled back,
so every job naming it failed. Label the image and exclude the label
from the prune.

Layout: unified · split

.gitbay/wiki/Admin.org +3
@@ -1295,6 +1295,9 @@ refused to start would stop every build.
1295=gitbay-runner-prune.timer= prunes unused images weekly, as the runner's 1295=gitbay-runner-prune.timer= prunes unused images weekly, as the runner's
1296user: rootless storage belongs to that user, and root's prune would not 1296user: rootless storage belongs to that user, and root's prune would not
1297see it. An unpruned image store on a 40GB host is a slow outage. 1297see it. An unpruned image store on a 40GB host is a slow outage.
1298Images labelled =org.gitbay.keep=true= are skipped, since a locally
1299built =localhost/= image cannot be pulled back; =deploy/Containerfile.ci=
1300sets it.
1298 1301
1299* LFS storage 1302* LFS storage
1300 1303
deploy/Containerfile.ci +4
@@ -15,6 +15,10 @@
15# .gitbay/ci.yml rather than a silent change under a running branch. 15# .gitbay/ci.yml rather than a silent change under a running branch.
16FROM docker.io/library/golang:1.27-trixie 16FROM docker.io/library/golang:1.27-trixie
17 17
18# gitbay-runner-prune.service skips images carrying this label. A localhost/
19# image cannot be pulled back, so pruning it fails every job that names it.
20LABEL org.gitbay.keep=true
21
18# The suite drives real git, ssh, sshd and gpg rather than mocking them, 22# The suite drives real git, ssh, sshd and gpg rather than mocking them,
19# and asserts they are present before running. git-lfs has its own tests; 23# and asserts they are present before running. git-lfs has its own tests;
20# sshd must be the binary at /usr/sbin/sshd that the tests exec. 24# sshd must be the binary at /usr/sbin/sshd that the tests exec.
deploy/gitbay-runner-prune.service +4 −3
@@ -10,7 +10,8 @@ User=ci-runner
10# Rootless podman reads storage.conf under HOME; a User= unit does not 10# Rootless podman reads storage.conf under HOME; a User= unit does not
11# set it. 11# set it.
12Environment=HOME=/var/lib/gitbay-runner 12Environment=HOME=/var/lib/gitbay-runner
13# Images not used by a container and older than a week. A build that 13# Images not used by a container and created more than a week ago. A
14# names an image again re-pulls it; the cost is one pull, not a failure. 14# registry image is pulled again on next use. A locally built image cannot
15ExecStart=/usr/bin/podman image prune --all --force --filter until=168h 15# be, so one labelled org.gitbay.keep=true (deploy/Containerfile.ci) is kept.
16ExecStart=/usr/bin/podman image prune --all --force --filter until=168h --filter label!=org.gitbay.keep=true
16ExecStart=/usr/bin/podman container prune --force 17ExecStart=/usr/bin/podman container prune --force