ci: mount windy-pro's read-only build inputs into dind; allow exactly that path for jobs
Non-secret inputs git-ignored in windy-pro (models, linux-x64 portable bundle, enter-monitor build) that build-desktop needs. Mounted :ro into dind; valid_volumes allows only /ci-inputs/windy-pro; refresh-ci-inputs.sh copies them from the frozen release clone (read-only on the source). Invariant I-5 narrowed, not dropped: exactly that one path, read-only in dind, no other service mounts it, still no docker socket (proven to fail on :rw). Orchestrator-approved (option a). Applied in an idle window. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -49,6 +49,11 @@ services:
|
||||
# A fresh volume: Sysbox shifts ownership to its own uid range. The old
|
||||
# `dind-storage` is kept untouched for the privileged rollback.
|
||||
- dind-storage-sysbox:/var/lib/docker
|
||||
# READ-ONLY, non-secret build inputs for windy-pro's desktop jobs (models,
|
||||
# linux-x64 portable bundle, enter-monitor build), copied from the frozen
|
||||
# release clone by deploy/runner/refresh-ci-inputs.sh. Jobs may mount ONLY
|
||||
# this path (config.yaml valid_volumes). Orchestrator-approved 09-23.
|
||||
- /home/user1-gpu/ci-inputs/windy-pro:/ci-inputs/windy-pro:ro
|
||||
# G1.5 — bounded so a fork-bomb workflow cannot starve Grant's interactive
|
||||
# session. Veron 1 is his workstation, not a dedicated build box.
|
||||
cpus: 12.0 # 12 of 24 cores
|
||||
|
||||
Reference in New Issue
Block a user