# Paired with gitbay-runner-prune.timer. Runs as the runner's own user, # because rootless podman's store belongs to that user and root's prune # would not see it. [Unit] Description=Prune unused podman images on the CI runner [Service] Type=oneshot User=ci-runner # Rootless podman reads storage.conf under HOME; a User= unit does not # set it. Environment=HOME=/var/lib/gitbay-runner # Images not used by a container and created more than a week ago. A # registry image is pulled again on next use. A locally built image cannot # be, so one labelled org.gitbay.keep=true (deploy/Containerfile.ci) is kept. ExecStart=/usr/bin/podman image prune --all --force --filter until=168h --filter label!=org.gitbay.keep=true ExecStart=/usr/bin/podman container prune --force