ci: run dind under Sysbox, not privileged (rollback override kept)
dind was privileged: true, so a job that escaped into dind was root on Veron 1, which is Grant's workstation. Under sysbox-runc (sysbox-ce 0.7.1, installed 09-23 with no docker restart) dind root is an unprivileged host uid. Smoke-tested standalone: nested containers, internet, a services-style postgres on a private network and a python image all pass unprivileged. Fresh volume dind-storage-sysbox; the old dind-storage stays for docker-compose.privileged.yml, the one-command rollback. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
15
deploy/runner/docker-compose.privileged.yml
Normal file
15
deploy/runner/docker-compose.privileged.yml
Normal file
@@ -0,0 +1,15 @@
|
||||
# ROLLBACK ONLY: the pre-Sysbox dind (privileged: true), kept one command away.
|
||||
# Use it if CI breaks under Sysbox:
|
||||
#
|
||||
# cd /srv/windygit/src/deploy/runner
|
||||
# sudo docker compose -f docker-compose.yml -f docker-compose.privileged.yml up -d dind
|
||||
#
|
||||
# (then restart the runners while idle). Compose merges `volumes` by container
|
||||
# path, so this puts back the old `dind-storage` volume with its image cache.
|
||||
# Going forward again: the same command without the second -f.
|
||||
services:
|
||||
dind:
|
||||
runtime: runc
|
||||
privileged: true
|
||||
volumes:
|
||||
- dind-storage:/var/lib/docker
|
||||
Reference in New Issue
Block a user