# The image gitbay's own CI jobs run in, once the runner isolates builds # (#144). Without it a job runs in the runner's default image, which has # no toolchain, and the suite's prerequisite check fails immediately. # # Build it on the runner host, where podman keeps it. The file is staged in # the runner user's home first: a login shell under su cannot read root's # stdin, and root's session does not share /tmp with it. # # scp -P 2222 deploy/Containerfile.ci root@gitbay.org:/var/lib/gitbay-runner/gitbay-ci.Containerfile # ssh -p 2222 root@gitbay.org 'chown ci-runner /var/lib/gitbay-runner/gitbay-ci.Containerfile \ # && su - ci-runner -s /bin/sh -c "podman build -t localhost/gitbay-ci:2 -f gitbay-ci.Containerfile ." \ # && rm /var/lib/gitbay-runner/gitbay-ci.Containerfile' # # Tagged, not :latest, so a change to this file is a deliberate bump in # .gitbay/ci.yml rather than a silent change under a running branch. FROM docker.io/library/golang:1.27-trixie # The suite drives real git, ssh, sshd and gpg rather than mocking them, # and asserts they are present before running. git-lfs has its own tests; # sshd must be the binary at /usr/sbin/sshd that the tests exec. # python3-venv: this is also the default image for every repository the # bay1 runner is attached to, and a lint job that makes a venv for ruff # fails without ensurepip (gitbay-ci:2). sqlite3: the same reason, for # a job that maintains an archive database. RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ git-lfs \ gnupg \ openssh-server \ openssh-client \ ca-certificates \ curl \ unzip \ python3 \ python3-venv \ sqlite3 \ && rm -rf /var/lib/apt/lists/* # A build runs as this image's root inside its own user namespace, mapped # to the runner's unprivileged user on the host. The workspace arrives # bind mounted at /workspace. WORKDIR /workspace