ci: mount windy-pro's read-only build inputs into dind; allow exactly that path for jobs
Non-secret inputs git-ignored in windy-pro (models, linux-x64 portable bundle, enter-monitor build) that build-desktop needs. Mounted :ro into dind; valid_volumes allows only /ci-inputs/windy-pro; refresh-ci-inputs.sh copies them from the frozen release clone (read-only on the source). Invariant I-5 narrowed, not dropped: exactly that one path, read-only in dind, no other service mounts it, still no docker socket (proven to fail on :rw). Orchestrator-approved (option a). Applied in an idle window. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -54,6 +54,9 @@ container:
|
||||
privileged: false
|
||||
options:
|
||||
workdir_parent: /workspace
|
||||
valid_volumes: [] # a job cannot bind-mount anything from the daemon host
|
||||
# A job may bind-mount exactly ONE daemon path: the read-only windy-pro build
|
||||
# inputs (mounted :ro into dind itself). Per-runner, not per-repo (act_runner
|
||||
# limit): any windyadmin repo could mount it; it is non-secret and read-only.
|
||||
valid_volumes: ["/ci-inputs/windy-pro"]
|
||||
docker_host: "-" # do NOT expose the runner's own docker socket to jobs
|
||||
force_pull: false
|
||||
|
||||
Reference in New Issue
Block a user