Compare commits
1 Commits
8690c4f8d3
...
ci-sysbox
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b438b6a053 |
15
deploy/runner/docker-compose.privileged.yml
Normal file
15
deploy/runner/docker-compose.privileged.yml
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
# ROLLBACK ONLY: the pre-Sysbox dind (privileged: true), kept one command away.
|
||||||
|
# Use it if CI breaks under Sysbox:
|
||||||
|
#
|
||||||
|
# cd /srv/windygit/src/deploy/runner
|
||||||
|
# sudo docker compose -f docker-compose.yml -f docker-compose.privileged.yml up -d dind
|
||||||
|
#
|
||||||
|
# (then restart the runners while idle). Compose merges `volumes` by container
|
||||||
|
# path, so this puts back the old `dind-storage` volume with its image cache.
|
||||||
|
# Going forward again: the same command without the second -f.
|
||||||
|
services:
|
||||||
|
dind:
|
||||||
|
runtime: runc
|
||||||
|
privileged: true
|
||||||
|
volumes:
|
||||||
|
- dind-storage:/var/lib/docker
|
||||||
@@ -26,8 +26,12 @@
|
|||||||
# * `dind` and every job container it spawns are UNTRUSTED. They are on a
|
# * `dind` and every job container it spawns are UNTRUSTED. They are on a
|
||||||
# private network with no access to the forge, its database, or its .env.
|
# private network with no access to the forge, its database, or its .env.
|
||||||
#
|
#
|
||||||
# dind itself is privileged — that is the cost, and it is the reason a job
|
# dind is NOT privileged (2026-09-23): it runs under the Sysbox runtime
|
||||||
# escape lands in a disposable daemon rather than on Grant's workstation.
|
# (sysbox-ce on Veron, `runtime: sysbox-runc`), a user-namespaced system
|
||||||
|
# container whose root is an unprivileged host uid. A job that escapes its own
|
||||||
|
# container lands in dind as a nobody on the host, not as root on Grant's
|
||||||
|
# workstation. Before Sysbox, dind was `privileged: true`; that config is kept
|
||||||
|
# as docker-compose.privileged.yml (ROLLBACK ONLY, one command, see that file).
|
||||||
#
|
#
|
||||||
# ⚠️ Do NOT "simplify" this by mounting the host docker socket.
|
# ⚠️ Do NOT "simplify" this by mounting the host docker socket.
|
||||||
|
|
||||||
@@ -36,13 +40,15 @@ name: windy-git-runner
|
|||||||
services:
|
services:
|
||||||
dind:
|
dind:
|
||||||
image: docker.io/library/docker:27-dind
|
image: docker.io/library/docker:27-dind
|
||||||
privileged: true
|
runtime: sysbox-runc # NOT privileged: see the I-5 note above
|
||||||
environment:
|
environment:
|
||||||
DOCKER_TLS_CERTDIR: "" # plain TCP on an isolated network, no host route
|
DOCKER_TLS_CERTDIR: "" # plain TCP on an isolated network, no host route
|
||||||
command: ["dockerd", "--host=tcp://0.0.0.0:2375", "--tls=false"]
|
command: ["dockerd", "--host=tcp://0.0.0.0:2375", "--tls=false"]
|
||||||
networks: [jobs]
|
networks: [jobs]
|
||||||
volumes:
|
volumes:
|
||||||
- dind-storage:/var/lib/docker
|
# A fresh volume: Sysbox shifts ownership to its own uid range. The old
|
||||||
|
# `dind-storage` is kept untouched for the privileged rollback.
|
||||||
|
- dind-storage-sysbox:/var/lib/docker
|
||||||
# G1.5 — bounded so a fork-bomb workflow cannot starve Grant's interactive
|
# G1.5 — bounded so a fork-bomb workflow cannot starve Grant's interactive
|
||||||
# session. Veron 1 is his workstation, not a dedicated build box.
|
# session. Veron 1 is his workstation, not a dedicated build box.
|
||||||
cpus: 12.0 # 12 of 24 cores
|
cpus: 12.0 # 12 of 24 cores
|
||||||
@@ -159,6 +165,7 @@ networks:
|
|||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
dind-storage:
|
dind-storage:
|
||||||
|
dind-storage-sysbox:
|
||||||
runner-data:
|
runner-data:
|
||||||
runner-data-2:
|
runner-data-2:
|
||||||
runner-data-3:
|
runner-data-3:
|
||||||
|
|||||||
Reference in New Issue
Block a user