# Drop-in for gitbay-runner.service, installed by `make deploy-runner` to # /etc/systemd/system/gitbay-runner.service.d/override.conf. # # A build must never starve the host: the e2e suite alone starts sixty # daemon instances, and with nothing holding it back a deploy's scp on # the admin sshd stalled at 1%. Lower CPU and IO weight keep sshd, # gitbayd and the backup timers responsive while a build runs. # # These weights are for the service, not per build, so `-jobs N` divides # them among N builds rather than taking N times as much. Raising -jobs # does not need them raised; it makes each build slower, not the host # busier. # # A build runs whatever the repository's ci.yml says, as the runner's # own user. Keep that user unprivileged: its key is added with # `keys add --scope runner`, which confines it to the runner protocol # and read-only git, and the sandboxing below keeps a step from # touching the system outside its workspace. # # Delegate=yes and the storage path below are what rootless podman needs # (#144): it manages its own cgroups for a container, and its image and # container store lives under the runner's home, which ProtectSystem # would otherwise make read-only. Prepare the host with # deploy/runner-podman-setup.sh before deploying a runner that isolates. [Service] Nice=10 CPUWeight=30 IOWeight=30 NoNewPrivileges=yes ProtectSystem=full ProtectKernelTunables=yes ProtectControlGroups=yes RestrictSUIDSGID=yes Delegate=yes # The runner's home is /var/lib/gitbay-runner (see the Admin page), and # the leading - makes a missing path ignored rather than fatal: this # drop-in installs on hosts that have not been prepared for podman yet, # and a unit that refuses to start would stop every build on the # instance. ReadWritePaths=-/var/lib/gitbay-runner/.local/share/containers -/var/lib/gitbay-runner/.config/containers