Compare commits
2 Commits
fe3bce39ff
...
fdb0f5989e
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fdb0f5989e | ||
|
|
9be2952ff8 |
15
deploy/runner/docker-compose.privileged.yml
Normal file
15
deploy/runner/docker-compose.privileged.yml
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
# ROLLBACK ONLY: the pre-Sysbox dind (privileged: true), kept one command away.
|
||||||
|
# Use it if CI breaks under Sysbox:
|
||||||
|
#
|
||||||
|
# cd /srv/windygit/src/deploy/runner
|
||||||
|
# sudo docker compose -f docker-compose.yml -f docker-compose.privileged.yml up -d dind
|
||||||
|
#
|
||||||
|
# (then restart the runners while idle). Compose merges `volumes` by container
|
||||||
|
# path, so this puts back the old `dind-storage` volume with its image cache.
|
||||||
|
# Going forward again: the same command without the second -f.
|
||||||
|
services:
|
||||||
|
dind:
|
||||||
|
runtime: runc
|
||||||
|
privileged: true
|
||||||
|
volumes:
|
||||||
|
- dind-storage:/var/lib/docker
|
||||||
@@ -26,8 +26,12 @@
|
|||||||
# * `dind` and every job container it spawns are UNTRUSTED. They are on a
|
# * `dind` and every job container it spawns are UNTRUSTED. They are on a
|
||||||
# private network with no access to the forge, its database, or its .env.
|
# private network with no access to the forge, its database, or its .env.
|
||||||
#
|
#
|
||||||
# dind itself is privileged — that is the cost, and it is the reason a job
|
# dind is NOT privileged (2026-09-23): it runs under the Sysbox runtime
|
||||||
# escape lands in a disposable daemon rather than on Grant's workstation.
|
# (sysbox-ce on Veron, `runtime: sysbox-runc`), a user-namespaced system
|
||||||
|
# container whose root is an unprivileged host uid. A job that escapes its own
|
||||||
|
# container lands in dind as a nobody on the host, not as root on Grant's
|
||||||
|
# workstation. Before Sysbox, dind was `privileged: true`; that config is kept
|
||||||
|
# as docker-compose.privileged.yml (ROLLBACK ONLY, one command, see that file).
|
||||||
#
|
#
|
||||||
# ⚠️ Do NOT "simplify" this by mounting the host docker socket.
|
# ⚠️ Do NOT "simplify" this by mounting the host docker socket.
|
||||||
|
|
||||||
@@ -36,13 +40,15 @@ name: windy-git-runner
|
|||||||
services:
|
services:
|
||||||
dind:
|
dind:
|
||||||
image: docker.io/library/docker:27-dind
|
image: docker.io/library/docker:27-dind
|
||||||
privileged: true
|
runtime: sysbox-runc # NOT privileged: see the I-5 note above
|
||||||
environment:
|
environment:
|
||||||
DOCKER_TLS_CERTDIR: "" # plain TCP on an isolated network, no host route
|
DOCKER_TLS_CERTDIR: "" # plain TCP on an isolated network, no host route
|
||||||
command: ["dockerd", "--host=tcp://0.0.0.0:2375", "--tls=false"]
|
command: ["dockerd", "--host=tcp://0.0.0.0:2375", "--tls=false"]
|
||||||
networks: [jobs]
|
networks: [jobs]
|
||||||
volumes:
|
volumes:
|
||||||
- dind-storage:/var/lib/docker
|
# A fresh volume: Sysbox shifts ownership to its own uid range. The old
|
||||||
|
# `dind-storage` is kept untouched for the privileged rollback.
|
||||||
|
- dind-storage-sysbox:/var/lib/docker
|
||||||
# G1.5 — bounded so a fork-bomb workflow cannot starve Grant's interactive
|
# G1.5 — bounded so a fork-bomb workflow cannot starve Grant's interactive
|
||||||
# session. Veron 1 is his workstation, not a dedicated build box.
|
# session. Veron 1 is his workstation, not a dedicated build box.
|
||||||
cpus: 12.0 # 12 of 24 cores
|
cpus: 12.0 # 12 of 24 cores
|
||||||
@@ -159,6 +165,7 @@ networks:
|
|||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
dind-storage:
|
dind-storage:
|
||||||
|
dind-storage-sysbox:
|
||||||
runner-data:
|
runner-data:
|
||||||
runner-data-2:
|
runner-data-2:
|
||||||
runner-data-3:
|
runner-data-3:
|
||||||
|
|||||||
@@ -22,7 +22,11 @@ head=$($G rev-parse "refs/heads/${branch}")
|
|||||||
[[ "$head" == "$want"* ]] || { echo "refusing: ${branch} is at ${head:0:7}, not ${want}"; exit 1; }
|
[[ "$head" == "$want"* ]] || { echo "refusing: ${branch} is at ${head:0:7}, not ${want}"; exit 1; }
|
||||||
parent=$($G rev-parse "${head}^")
|
parent=$($G rev-parse "${head}^")
|
||||||
|
|
||||||
while systemctl is-active -q windygit-sync; do sleep 5; done
|
# NOT `systemctl is-active`: the sync is Type=oneshot, which reads "activating"
|
||||||
|
# (exit 3) for its whole run, so is-active says "idle" mid-run.
|
||||||
|
busy() { case "$(systemctl show windygit-sync -p ActiveState --value)" in
|
||||||
|
activating|active|deactivating|reloading) return 0;; esac; return 1; }
|
||||||
|
while busy; do sleep 5; done
|
||||||
$G update-ref "refs/heads/${branch}" "$parent" "$head"
|
$G update-ref "refs/heads/${branch}" "$parent" "$head"
|
||||||
mark=$(awk '{print int($1*1000000)}' /proc/uptime)
|
mark=$(awk '{print int($1*1000000)}' /proc/uptime)
|
||||||
echo "rewound ${repo}:${branch} ${head:0:7} -> ${parent:0:7}"
|
echo "rewound ${repo}:${branch} ${head:0:7} -> ${parent:0:7}"
|
||||||
|
|||||||
Reference in New Issue
Block a user