No description
- Dockerfile 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
|
||
| .gitignore | ||
| compose.yml | ||
| Dockerfile | ||
| README.md | ||
| runner-config.yml | ||
Hyperion CI Base
Runner config for Hyperion CI. This is the base image for all Hyperion CI jobs.
Usage
name: CI
on:
push:
branches:
- main
jobs:
build:
runs-on: ci
Deploy
On the Docker host (plain Docker Compose, not Swarm):
git clone https://git.hyperion.dev/hyperion-ci/forgejo-runner.git
cd forgejo-runner
# The runner runs as UID 10xx and must be able to write data/ and read the token.
# Create the token file first: if it is missing, Docker creates a directory there instead.
mkdir -p data/.cache
chown -R 10xx:10xx data
chmod 775 data/.cache
chmod g+s data/.cache
sudo mkdir -p /etc/forgejo-runner
printf '%s' 'RUNNER_TOKEN' | sudo tee /etc/forgejo-runner/runner-token > /dev/null
sudo chown 10xx:10xx data /etc/forgejo-runner/runner-token
sudo chmod 600 /etc/forgejo-runner/runner-token
docker compose up -d
data/ only holds the job cache; deleting it loses nothing else.
To apply changes to compose.yml or runner-config.yml:
git pull
docker compose up -d --force-recreate runner
The runner pulls ci-base without logging in, so the hyperion-ci organisation
must stay public.
Update ci-base
Versions are whole numbers (1, 2, 3, ...). Never push over an existing tag.
-
Build and push the next version:
docker login git.hyperion.dev docker build -t git.hyperion.dev/hyperion-ci/ci-base:VERSION . docker push git.hyperion.dev/hyperion-ci/ci-base:VERSION docker logout git.hyperion.dev -
Copy the digest from the
docker pushoutput (VERSION: digest: sha256:...), or look it up afterwards:docker buildx imagetools inspect git.hyperion.dev/hyperion-ci/ci-base:VERSIONUse the top-level
Digest:, not a per-platform one. -
Update the
cilabel inrunner-config.yml:- ci:docker://git.hyperion.dev/hyperion-ci/ci-base:VERSION@sha256:DIGEST -
Push the change, then on the host run
git pullanddocker compose up -d --force-recreate runner.