From 8e9fa3116cc8e41f020b8450ac491d5626f7eb2d Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Wed, 23 Sep 2026 02:51:56 -0400 Subject: [PATCH] ci: six runners; SSO #8 Gitea sign-in hardening (staged) - runner-5/6: 50+ jobs were queued with ~11 private repos onboarded. dind keeps the 12-core ceiling, so this adds concurrency, not CPU. - Gitea: password + passkey sign-in forms off (break-glass = CLI), and ACCOUNT_LINKING auto -> login. auto linked any hub login whose email matched an existing account, and SITE ADMIN windyadmin carries Grant's email. Grant is linked by the hub's stable sub, which matches first. Co-Authored-By: Claude Opus 5.5 --- deploy/runner/config.yaml | 2 +- deploy/runner/docker-compose.yml | 19 +++++++++++++++++++ docker-compose.yml | 16 +++++++++++++++- 3 files changed, 35 insertions(+), 2 deletions(-) diff --git a/deploy/runner/config.yaml b/deploy/runner/config.yaml index 769c279..50d66ef 100644 --- a/deploy/runner/config.yaml +++ b/deploy/runner/config.yaml @@ -11,7 +11,7 @@ log: runner: file: /data/.runner - capacity: 1 # per runner; parallelism = number of runner services (4). See docker-compose.yml + capacity: 1 # per runner; parallelism = number of runner services (6). See docker-compose.yml timeout: 30m shutdown_timeout: 3m insecure: false diff --git a/deploy/runner/docker-compose.yml b/deploy/runner/docker-compose.yml index 69c5396..ab7295f 100644 --- a/deploy/runner/docker-compose.yml +++ b/deploy/runner/docker-compose.yml @@ -134,6 +134,23 @@ services: <<: *env2 GITEA_RUNNER_NAME: veron-1-4 volumes: [./config.yaml:/config.yaml:ro, runner-data-4:/data] + # 5 and 6 added the same day: with ~11 private repos onboarded (windy-chat + # alone queues ~24 jobs per push) four runners left 50+ jobs waiting. The + # CPU ceiling is dind's (12 of 24 cores, G1.5), not the runner count, so more + # runners add concurrency for I/O-bound jobs (npm ci, uv sync) without + # taking more of Grant's workstation. + runner-5: + <<: *runner + environment: + <<: *env2 + GITEA_RUNNER_NAME: veron-1-5 + volumes: [./config.yaml:/config.yaml:ro, runner-data-5:/data] + runner-6: + <<: *runner + environment: + <<: *env2 + GITEA_RUNNER_NAME: veron-1-6 + volumes: [./config.yaml:/config.yaml:ro, runner-data-6:/data] networks: jobs: @@ -146,4 +163,6 @@ volumes: runner-data-2: runner-data-3: runner-data-4: + runner-data-5: + runner-data-6: diff --git a/docker-compose.yml b/docker-compose.yml index 7cb4502..89dd6d4 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -57,12 +57,26 @@ services: # G2.2 — OIDC only. No local password login, no self-registration. GITEA__service__DISABLE_REGISTRATION: "true" GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true" + # SSO #8 (2026-09-23): the password and passkey forms are OFF. windyadmin + # is site admin with a local password; leaving the form up made that + # password a second, phishable way into the whole forge. Break-glass is + # the CLI on Veron (`docker exec -u git windy-git-gitea-1 gitea admin ...`). + GITEA__service__ENABLE_PASSWORD_SIGNIN_FORM: "false" + GITEA__service__ENABLE_PASSKEY_AUTHENTICATION: "false" # G3.1 — a Windy account IS the account. Signing in with Windy provisions # the Gitea user on first arrival; nobody is asked to invent a second # identity for the same person, and no local password ever exists. GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true" GITEA__oauth2_client__USERNAME: email - GITEA__oauth2_client__ACCOUNT_LINKING: auto + # 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL + # matched an existing account — and windyadmin (SITE ADMIN) carries Grant's + # email, so the forge's admin rights rested on the hub never letting anyone + # else hold that address. `login` makes an email match prove possession of + # the existing account first. Grant is unaffected: his account is already + # linked by the hub's stable `sub`, which is matched before email. + # ⚠️ env-to-ini SETS but never UNSETS — this value must also be edited in + # /srv/windygit/git/gitea/conf/app.ini if it is ever removed from here. + GITEA__oauth2_client__ACCOUNT_LINKING: login # The email is asserted by account-server, which is the authority on it. # Asking the user to re-verify an address their identity provider already # verified is friction that buys nothing.