Build egress by trust class, and the scratch test for #260.
- The runner starts each podman build under
builds/trustedorbuilds/untrustedin its service cgroup. It refuses to start without build cgroups when it sets limits, takes untrusted builds, or polls over loopback. deploy/gitbay-runner-builds.nft(tableinet gitbay_builds) matches build traffic by that cgroup: host loopback closed except DNS, private ranges closed; trusted builds keep the internet and the forge's public 22/80/443; untrusted builds get TCP 80/443 and DNS and not the forge. The drop-in creates the cgroups and loads the table on every start; the egress unit's reload loads it only when installed.make deploy-runnerships and checks it.deploy/runner-auth-flood-test.sh <repo> [--untrusted]: a build failing SSH logins beside the runner; passes only if the build log shows the policy's effect and the runner kept polling.- Admin (install, checks, rollback), CI, Threat-Model, Users, Architecture 03/04/07/09/10; CHANGELOG.
Nothing reaches bay1 until make deploy-runner. Validate on a scratch-scoped runner first; the Admin page has the steps and the rollback. #260 closes when the test's result is recorded.
Ref #260