# Loads the CI runner's host egress rule (#260, # deploy/gitbay-runner-egress.nft). gitbay-runner.service requires this # unit, so the runner starts only with the rule in force; stopping this # unit removes the table and stops the runner with it. # # Ordered after nftables.service and ufw.service: either may rewrite the # ruleset at boot, and nftables.service's default config starts with # flush ruleset. A missing unit in After= is ignored. # # Reload re-reads the file and replaces the table in one transaction; it # does not restart the runner, which a restart of this unit would # (Requires= propagates restarts). `make deploy-runner` reloads. # # Stop uses destroy, which succeeds when the table is already gone (a # flush ruleset removes it); delete would fail and leave the unit failed. # # The builds table (gitbay-runner-builds.nft) is loaded by the runner's # own start, against its cgroups. Reload loads it again when the file is # installed and those cgroups exist, so after a restart of # nftables.service one reload puts both tables back; without the file # (taken out per the Admin page) the reload skips it and succeeds. [Unit] Description=Host egress rule for CI builds After=nftables.service ufw.service Before=gitbay-runner.service [Service] Type=oneshot RemainAfterExit=yes ExecStart=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft ExecReload=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft ExecReload=/bin/sh -c 'if [ -f /etc/gitbay-runner/builds.nft ] && [ -d /sys/fs/cgroup/system.slice/gitbay-runner.service/builds/untrusted ]; then exec /usr/sbin/nft -f /etc/gitbay-runner/builds.nft; fi' ExecStop=/usr/sbin/nft destroy table inet gitbay_runner ExecStop=/usr/sbin/nft destroy table inet gitbay_builds [Install] WantedBy=multi-user.target