No description
  • Dockerfile 100%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kolumdium 658b217bfe feat: rewrite to work around swarm
- Swarm does not support image builds or privileged docker-in-docker
2026-09-30 14:10:07 +02:00
.gitignore feat: rewrite to work around swarm 2026-09-30 14:10:07 +02:00
compose.yml feat: rewrite to work around swarm 2026-09-30 14:10:07 +02:00
Dockerfile feat: Initial commit 2026-09-30 13:46:11 +02:00
README.md feat: rewrite to work around swarm 2026-09-30 14:10:07 +02:00
runner-config.yml feat: rewrite to work around swarm 2026-09-30 14:10:07 +02:00

Hyperion CI Base

Runner config for Hyperion CI. This is the base image for all Hyperion CI jobs.

Usage

name: CI

on:
  push:
    branches:
      - main

jobs:
  build:
    runs-on: ci

Deploy

On the Docker host (plain Docker Compose, not Swarm):

git clone https://git.hyperion.dev/hyperion-ci/forgejo-runner.git
cd forgejo-runner

# The runner runs as UID 10xx and must be able to write data/ and read the token.
# Create the token file first: if it is missing, Docker creates a directory there instead.
mkdir -p data/.cache

chown -R 10xx:10xx data
chmod 775 data/.cache
chmod g+s data/.cache

sudo mkdir -p /etc/forgejo-runner
printf '%s' 'RUNNER_TOKEN' | sudo tee /etc/forgejo-runner/runner-token > /dev/null
sudo chown 10xx:10xx data /etc/forgejo-runner/runner-token
sudo chmod 600 /etc/forgejo-runner/runner-token

docker compose up -d

data/ only holds the job cache; deleting it loses nothing else.

To apply changes to compose.yml or runner-config.yml:

git pull
docker compose up -d --force-recreate runner

The runner pulls ci-base without logging in, so the hyperion-ci organisation must stay public.

Update ci-base

Versions are whole numbers (1, 2, 3, ...). Never push over an existing tag.

  1. Build and push the next version:

    docker login git.hyperion.dev
    docker build -t git.hyperion.dev/hyperion-ci/ci-base:VERSION .
    docker push git.hyperion.dev/hyperion-ci/ci-base:VERSION
    docker logout git.hyperion.dev
    
  2. Copy the digest from the docker push output (VERSION: digest: sha256:...), or look it up afterwards:

    docker buildx imagetools inspect git.hyperion.dev/hyperion-ci/ci-base:VERSION
    

    Use the top-level Digest:, not a per-platform one.

  3. Update the ci label in runner-config.yml:

    - ci:docker://git.hyperion.dev/hyperion-ci/ci-base:VERSION@sha256:DIGEST
    
  4. Push the change, then on the host run git pull and docker compose up -d --force-recreate runner.