runner: -cpus and -memory cap a build's container !315

closed closed without merging by cmc on 2026-09-07 03:10 UTC, in favour of !313 · krz/gitbay:runner-build-limits into main

Discussion

cmc

The runner isolation design listed per-build resource limits as a separate decision. With builds in containers they are one podman flag each, and the threat model's not-audited list still names resource exhaustion.

-cpus and -memory are passed to podman run only when set; unset means uncapped rather than a default that could kill a job. bay1's drop-in sets -cpus 3 of the host's 4, leaving a core for gitbayd and sshd during a build, and no memory cap: the e2e suite peaks past 5GB of the 7GB, and a cap that kills the suite is an outage, not a limit.

TestLimitArgs pins the unset-means-absent behaviour.

Ref #144

cmc 2026-09-07 03:10 UTC

Closing: empty. The commit this was opened for (89eba6a, -cpus and -memory) reached main underneath !313 when that branch was rebased and fast-forwarded, so this merge request's head is now an ancestor of main with nothing to merge. The change is on main and covered by main's own run at c8bc377 (build 1034).