deploy, wiki: the bay1 runner is bounded by its attachments !358

merged merged by cmc on 2026-09-10 01:36 UTC · krz/gitbay:runner-attach-only into main

2 files changed, +15 −10

Layout: unified · split

.gitbay/wiki/Admin.org +9 −6
@@ -383,9 +383,11 @@ daemon instances; without the drop-in a deploy's copy over the admin
383sshd stalled. Both deploy targets copy with =rsync --partial=, which 383sshd stalled. Both deploy targets copy with =rsync --partial=, which
384resumes a stalled transfer. 384resumes a stalled transfer.
385 385
386v1 runs steps directly on the host — no containers — so treat the 386Under =-isolation podman=, the default and what bay1 runs, each build
387runner machine as executing whatever your users push. Install the 387is confined to a container (see Container isolation below). Under
388toolchains your builds need on it. 388=-isolation none= steps run directly on the host as the runner's user,
389so treat that machine as executing whatever your users push, and
390install the toolchains your builds need on it.
389 391
390A runner claims the oldest pending build among the repositories its key 392A runner claims the oldest pending build among the repositories its key
391is attached to — for an admin key, the oldest in the instance. =-repos= 393is attached to — for an admin key, the oldest in the instance. =-repos=
@@ -411,9 +413,10 @@ gitbay-runner -remote git@gitbay.org -repos krz/site,krz/docs \
411 413
412Add =-untrusted= only with =-isolation podman=. 414Add =-untrusted= only with =-isolation podman=.
413 415
414gitbay.org's runner is scoped: it builds the forge's own repositories 416gitbay.org's runner is attached to the forge's own repositories and
415and the isolation canary, nothing else, because it shares the host with 417the isolation canary, nothing else, because it shares the host with
416the forge; any other repository builds on a runner its owner attaches. 418the forge; its unit names no =-repos=, the attachments are the
419boundary. Any other repository builds on a runner its owner attaches.
417 420
418=-repos= narrows an admin runner; for a runner key the attachments are 421=-repos= narrows an admin runner; for a runner key the attachments are
419the boundary, held by the server, and =-repos= may only name 422the boundary, held by the server, and =-repos= may only name
deploy/gitbay-runner.override.conf +6 −4
@@ -23,9 +23,11 @@
23# would otherwise make read-only. Prepare the host with 23# would otherwise make read-only. Prepare the host with
24# deploy/runner-podman-setup.sh before deploying a runner that isolates. 24# deploy/runner-podman-setup.sh before deploying a runner that isolates.
25[Service] 25[Service]
26# cmc/ci-smoke is the nightly isolation canary; a runner scoped to named 26# The runner polls as a non-admin account with a runner-scoped key, and
27# repositories never claims a build it is not scoped to, so the canary 27# claims only the repositories that key is attached to (`repo runner
28# must be listed or its scheduled build waits forever. 28# add`): krz/gitbay and cmc/ci-smoke. The attachments are the boundary,
29# so ExecStart names no -repos. cmc/ci-smoke is the nightly isolation
30# canary; keep it attached or its scheduled build waits forever.
29# 31#
30# Two layers of resource caps. MemoryMax and CPUQuota bound the unit — 32# Two layers of resource caps. MemoryMax and CPUQuota bound the unit —
31# the runner and every build together — which is what keeps the forge 33# the runner and every build together — which is what keeps the forge
@@ -73,7 +75,7 @@ KillMode=mixed
73# -untrusted: this runner isolates in podman, so it takes merge request 75# -untrusted: this runner isolates in podman, so it takes merge request
74# heads from forks; a runner without a container must not. 76# heads from forks; a runner without a container must not.
75ExecStart= 77ExecStart=
76ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -repos krz/gitbay,cmc/ci-smoke -isolation podman -image localhost/gitbay-ci:1 -cpus 3 -memory 6g -untrusted 78ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -isolation podman -image localhost/gitbay-ci:1 -cpus 3 -memory 6g -untrusted
77Nice=10 79Nice=10
78CPUWeight=30 80CPUWeight=30
79IOWeight=30 81IOWeight=30