deploy, ci: gitbay-ci:2 carries python3-venv !361

merged merged by cmc on 2026-09-10 02:48 UTC · krz/gitbay:ci-image-2 into main

5 files changed, +18 −11

Layout: unified · split

.gitbay/ci.yml +4 −4
@@ -2,7 +2,7 @@ jobs:
2 # Fast feedback: this finishes in seconds, so it is not held behind the 2 # Fast feedback: this finishes in seconds, so it is not held behind the
3 # suite. 3 # suite.
4 build: 4 build:
5 image: localhost/gitbay-ci:1 5 image: localhost/gitbay-ci:2
6 steps: 6 steps:
7 - go build ./... 7 - go build ./...
8 - go vet ./... 8 - go vet ./...
@@ -13,7 +13,7 @@ jobs:
13 # The 20m is under the runner's own 30m limit, so go times out first and 13 # The 20m is under the runner's own 30m limit, so go times out first and
14 # says which test hung instead of the runner killing it blind. 14 # says which test hung instead of the runner killing it blind.
15 test: 15 test:
16 image: localhost/gitbay-ci:1 16 image: localhost/gitbay-ci:2
17 steps: 17 steps:
18 - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; } 18 - missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; }
19 - go test ./... -count=1 -timeout 20m 19 - go test ./... -count=1 -timeout 20m
@@ -33,7 +33,7 @@ jobs:
33 # `build trigger krz/gitbay vuln` runs it on demand before a release 33 # `build trigger krz/gitbay vuln` runs it on demand before a release
34 # (#177). 34 # (#177).
35 vuln: 35 vuln:
36 image: localhost/gitbay-ci:1 36 image: localhost/gitbay-ci:2
37 schedule: "0 3 * * *" 37 schedule: "0 3 * * *"
38 steps: 38 steps:
39 - go run golang.org/x/vuln/cmd/govulncheck@latest ./... 39 - go run golang.org/x/vuln/cmd/govulncheck@latest ./...
@@ -56,7 +56,7 @@ jobs:
56 # linux-x64 bundle carries its own JRE, which is why the host needs no 56 # linux-x64 bundle carries its own JRE, which is why the host needs no
57 # Java. 57 # Java.
58 sonar: 58 sonar:
59 image: localhost/gitbay-ci:1 59 image: localhost/gitbay-ci:2
60 schedule: "30 3 * * *" 60 schedule: "30 3 * * *"
61 steps: 61 steps:
62 - | 62 - |
.gitbay/wiki/Admin.org +2 −2
@@ -458,7 +458,7 @@ where every repository is trusted. There is no automatic fallback: a
458runner started with =-isolation podman= that cannot find a working 458runner started with =-isolation podman= that cannot find a working
459podman exits rather than running a build unsandboxed. 459podman exits rather than running a build unsandboxed.
460 460
461gitbay's own jobs name =localhost/gitbay-ci:1=, built from 461gitbay's own jobs name =localhost/gitbay-ci:2=, built from
462=deploy/Containerfile.ci= on the runner host. A job's image must carry 462=deploy/Containerfile.ci= on the runner host. A job's image must carry
463what its steps need: the suite drives real git, git-lfs, gpg and sshd and 463what its steps need: the suite drives real git, git-lfs, gpg and sshd and
464asserts they exist before running, so the stock runner default would fail 464asserts they exist before running, so the stock runner default would fail
@@ -467,7 +467,7 @@ it immediately. Build or rebuild it with:
467#+begin_src sh 467#+begin_src sh
468ssh -p 2222 root@<host> 'cat > /tmp/Containerfile.ci' < deploy/Containerfile.ci 468ssh -p 2222 root@<host> 'cat > /tmp/Containerfile.ci' < deploy/Containerfile.ci
469ssh -p 2222 root@<host> 'su - ci-runner -s /bin/sh -c \ 469ssh -p 2222 root@<host> 'su - ci-runner -s /bin/sh -c \
470 "podman build -t localhost/gitbay-ci:1 -f /tmp/Containerfile.ci /tmp"' 470 "podman build -t localhost/gitbay-ci:2 -f /tmp/Containerfile.ci /tmp"'
471#+end_src 471#+end_src
472 472
473The tag is deliberate rather than =:latest=: changing the file means 473The tag is deliberate rather than =:latest=: changing the file means
deploy/Containerfile.ci +8 −1
@@ -5,7 +5,7 @@
5# Build it on the runner host, where podman keeps it: 5# Build it on the runner host, where podman keeps it:
6# 6#
7# ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \ 7# ssh -p 2222 root@bay1 'su - ci-runner -s /bin/sh -c \
8# "podman build -t localhost/gitbay-ci:1 -f - ." ' < deploy/Containerfile.ci 8# "podman build -t localhost/gitbay-ci:2 -f - ." ' < deploy/Containerfile.ci
9# 9#
10# Tagged, not :latest, so a change to this file is a deliberate bump in 10# Tagged, not :latest, so a change to this file is a deliberate bump in
11# .gitbay/ci.yml rather than a silent change under a running branch. 11# .gitbay/ci.yml rather than a silent change under a running branch.
@@ -14,6 +14,10 @@ FROM docker.io/library/golang:1.27-trixie
14# The suite drives real git, ssh, sshd and gpg rather than mocking them, 14# The suite drives real git, ssh, sshd and gpg rather than mocking them,
15# and asserts they are present before running. git-lfs has its own tests; 15# and asserts they are present before running. git-lfs has its own tests;
16# sshd must be the binary at /usr/sbin/sshd that the tests exec. 16# sshd must be the binary at /usr/sbin/sshd that the tests exec.
17# python3-venv: this is also the default image for every repository the
18# bay1 runner is attached to, and a lint job that makes a venv for ruff
19# fails without ensurepip (gitbay-ci:2). sqlite3: the same reason, for
20# a job that maintains an archive database.
17RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ 21RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
18 git-lfs \ 22 git-lfs \
19 gnupg \ 23 gnupg \
@@ -22,6 +26,9 @@ RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-ins
22 ca-certificates \ 26 ca-certificates \
23 curl \ 27 curl \
24 unzip \ 28 unzip \
29 python3 \
30 python3-venv \
31 sqlite3 \
25 && rm -rf /var/lib/apt/lists/* 32 && rm -rf /var/lib/apt/lists/*
26 33
27# A build runs as this image's root inside its own user namespace, mapped 34# A build runs as this image's root inside its own user namespace, mapped
deploy/gitbay-runner.override.conf +1 −1
@@ -75,7 +75,7 @@ KillMode=mixed
75# -untrusted: this runner isolates in podman, so it takes merge request 75# -untrusted: this runner isolates in podman, so it takes merge request
76# heads from forks; a runner without a container must not. 76# heads from forks; a runner without a container must not.
77ExecStart= 77ExecStart=
78ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -isolation podman -image localhost/gitbay-ci:1 -cpus 3 -memory 6g -untrusted 78ExecStart=/usr/local/bin/gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work -poll 5s -timeout 45m -isolation podman -image localhost/gitbay-ci:2 -cpus 3 -memory 6g -untrusted
79Nice=10 79Nice=10
80CPUWeight=30 80CPUWeight=30
81IOWeight=30 81IOWeight=30
e2e/isolation_podman_test.go +3 −3
@@ -17,13 +17,13 @@ import (
17// same rule builds follow. 17// same rule builds follow.
18func provisionedImage(t *testing.T) string { 18func provisionedImage(t *testing.T) string {
19 t.Helper() 19 t.Helper()
20 for _, img := range []string{"localhost/gitbay-ci:1", "docker.io/library/debian:stable-slim", "docker.io/library/alpine:latest"} { 20 for _, img := range []string{"localhost/gitbay-ci:2", "docker.io/library/debian:stable-slim", "docker.io/library/alpine:latest"} {
21 if err := exec.Command("podman", "image", "exists", img).Run(); err == nil { 21 if err := exec.Command("podman", "image", "exists", img).Run(); err == nil {
22 return img 22 return img
23 } 23 }
24 } 24 }
25 t.Log("SKIPPING ISOLATION TEST: podman has no image this test can use. " + 25 t.Log("SKIPPING ISOLATION TEST: podman has no image this test can use. " +
26 "Provision one (podman build -t localhost/gitbay-ci:1 -f deploy/Containerfile.ci). " + 26 "Provision one (podman build -t localhost/gitbay-ci:2 -f deploy/Containerfile.ci). " +
27 "The container path is NOT covered by this run.") 27 "The container path is NOT covered by this run.")
28 return "" 28 return ""
29} 29}
@@ -179,7 +179,7 @@ func runnerPodmanOnce(t *testing.T, inst *instance, key string) {
179 "-remote", "git@127.0.0.1", 179 "-remote", "git@127.0.0.1",
180 "-ssh-opts", opts, 180 "-ssh-opts", opts,
181 "-isolation", "podman", 181 "-isolation", "podman",
182 "-image", "localhost/gitbay-ci:1", 182 "-image", "localhost/gitbay-ci:2",
183 "-clone-base", fmt.Sprintf("ssh://git@127.0.0.1:%d", inst.port), 183 "-clone-base", fmt.Sprintf("ssh://git@127.0.0.1:%d", inst.port),
184 "-workdir", t.TempDir()) 184 "-workdir", t.TempDir())
185 cmd.Env = append(os.Environ(), "XDG_CONFIG_HOME="+t.TempDir(), "GIT_CONFIG_NOSYSTEM=1", "GIT_CONFIG_GLOBAL=/dev/null") 185 cmd.Env = append(os.Environ(), "XDG_CONFIG_HOME="+t.TempDir(), "GIT_CONFIG_NOSYSTEM=1", "GIT_CONFIG_GLOBAL=/dev/null")