ci: bound CI storage; don't bridge image-build jobs
- deploy/runner/prune.sh + windygit-ci-prune.timer (6h): age-based prune of the CI-only dind (containers, finished-job volumes, images/builder cache >7d) plus a hard 60 GB cap. Only that daemon, over its own TCP socket; never the host's Docker. It was 38 GB and unbounded — the same class of growth that filled Kit 0 on 09-01. - pr_status_bridge: jobs named *docker* are not posted. Job containers have no daemon by design (I-5), so they are red on every commit; a permanent red X teaches everyone to ignore red. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
28
deploy/runner/prune.sh
Executable file
28
deploy/runner/prune.sh
Executable file
@@ -0,0 +1,28 @@
|
||||
#!/usr/bin/env bash
|
||||
# Keep CI storage bounded (2026-09-23).
|
||||
#
|
||||
# Kit 0's 09-01 wipe began with CI `_work` dirs (74 GB) + Docker filling the
|
||||
# disk. Windy Git's runners have no host `_work` dir — every job runs in a
|
||||
# container inside the CI-only dind — so the thing that grows here is dind's
|
||||
# image/volume store (38 GB when this was written, never pruned). This prunes
|
||||
# ONLY that daemon, over its own socket. It never touches the host's Docker.
|
||||
#
|
||||
# In-use images/volumes are never removed, so a running job is safe.
|
||||
set -euo pipefail
|
||||
CAP_GB="${CI_STORAGE_CAP_GB:-60}"
|
||||
D=(docker exec windy-git-runner-dind-1 docker)
|
||||
|
||||
"${D[@]}" container prune -f --filter until=6h >/dev/null
|
||||
"${D[@]}" volume prune -af >/dev/null # job workspaces of finished jobs
|
||||
"${D[@]}" image prune -af --filter until=168h >/dev/null
|
||||
"${D[@]}" builder prune -af --filter until=168h >/dev/null 2>&1 || true
|
||||
|
||||
used_gb=$(du -s --block-size=1G /var/lib/docker/volumes/windy-git-runner_dind-storage | cut -f1)
|
||||
if (( used_gb > CAP_GB )); then
|
||||
# Over the cap even after the age-based pass: drop every unused image. The
|
||||
# next jobs re-pull (the act image is ~2 GB) — slower, never wrong.
|
||||
"${D[@]}" image prune -af >/dev/null
|
||||
used_gb=$(du -s --block-size=1G /var/lib/docker/volumes/windy-git-runner_dind-storage | cut -f1)
|
||||
fi
|
||||
echo "ci storage ${used_gb}G (cap ${CAP_GB}G)"
|
||||
(( used_gb <= CAP_GB )) || { echo "STILL OVER CAP"; exit 1; }
|
||||
6
deploy/runner/windygit-ci-prune.service
Normal file
6
deploy/runner/windygit-ci-prune.service
Normal file
@@ -0,0 +1,6 @@
|
||||
[Unit]
|
||||
Description=Windy Git - prune CI-only dind storage (bounded, never the host daemon)
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
ExecStart=/srv/windygit/src/deploy/runner/prune.sh
|
||||
9
deploy/runner/windygit-ci-prune.timer
Normal file
9
deploy/runner/windygit-ci-prune.timer
Normal file
@@ -0,0 +1,9 @@
|
||||
[Unit]
|
||||
Description=Windy Git - prune CI storage every 6 hours
|
||||
|
||||
[Timer]
|
||||
OnCalendar=*-*-* 00/6:37:00
|
||||
Persistent=true
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
Reference in New Issue
Block a user