route runner build container clones via public URL with CF Access (#7)
This commit is contained in:
@@ -8,7 +8,7 @@ metadata:
|
||||
labels:
|
||||
app: gitea-runner
|
||||
annotations:
|
||||
config-version: "2026-05-04-docker-sock-fix"
|
||||
config-version: "2026-05-04-cf-access-public-url"
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
@@ -19,7 +19,7 @@ spec:
|
||||
labels:
|
||||
app: gitea-runner
|
||||
annotations:
|
||||
config-version: "2026-05-04-docker-sock-fix"
|
||||
config-version: "2026-05-04-cf-access-public-url"
|
||||
spec:
|
||||
securityContext:
|
||||
runAsNonRoot: false
|
||||
@@ -35,7 +35,7 @@ spec:
|
||||
--name legion \
|
||||
--labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \
|
||||
--no-interactive
|
||||
cat > /data/config.yaml << 'EOF'
|
||||
cat > /data/config.yaml << EOF
|
||||
runner:
|
||||
capacity: 2
|
||||
timeout: 3h
|
||||
@@ -45,6 +45,16 @@ spec:
|
||||
force_pull: false
|
||||
valid_volumes: []
|
||||
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
||||
# Build containers run with network: host. The in-cluster
|
||||
# gitea name does not resolve there, so we redirect git
|
||||
# operations to https://git.neuralplatform.ai using CF
|
||||
# Access service-token headers. BASH_ENV makes bash source
|
||||
# /usr/local/bin/git-cf-access-init.sh before every step,
|
||||
# which sets up the redirect + headers.
|
||||
env:
|
||||
CF_ACCESS_CLIENT_ID: "${CF_ACCESS_CLIENT_ID}"
|
||||
CF_ACCESS_CLIENT_SECRET: "${CF_ACCESS_CLIENT_SECRET}"
|
||||
BASH_ENV: "/usr/local/bin/git-cf-access-init.sh"
|
||||
extra_hosts:
|
||||
- "gitea.git.svc.cluster.local:10.43.1.53"
|
||||
EOF
|
||||
@@ -92,7 +102,7 @@ metadata:
|
||||
labels:
|
||||
app: neuron-technologies-runner
|
||||
annotations:
|
||||
config-version: "2026-05-04-docker-sock-fix"
|
||||
config-version: "2026-05-04-cf-access-public-url"
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
@@ -103,7 +113,7 @@ spec:
|
||||
labels:
|
||||
app: neuron-technologies-runner
|
||||
annotations:
|
||||
config-version: "2026-05-04-docker-sock-fix"
|
||||
config-version: "2026-05-04-cf-access-public-url"
|
||||
spec:
|
||||
securityContext:
|
||||
runAsNonRoot: false
|
||||
@@ -119,7 +129,7 @@ spec:
|
||||
--name "legion-nt-$(hostname)" \
|
||||
--labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \
|
||||
--no-interactive
|
||||
cat > /data/config.yaml << 'EOF'
|
||||
cat > /data/config.yaml << EOF
|
||||
runner:
|
||||
capacity: 2
|
||||
timeout: 3h
|
||||
@@ -129,6 +139,16 @@ spec:
|
||||
force_pull: false
|
||||
valid_volumes: []
|
||||
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
||||
# Build containers run with network: host. The in-cluster
|
||||
# gitea name does not resolve there, so we redirect git
|
||||
# operations to https://git.neuralplatform.ai using CF
|
||||
# Access service-token headers. BASH_ENV makes bash source
|
||||
# /usr/local/bin/git-cf-access-init.sh before every step,
|
||||
# which sets up the redirect + headers.
|
||||
env:
|
||||
CF_ACCESS_CLIENT_ID: "${CF_ACCESS_CLIENT_ID}"
|
||||
CF_ACCESS_CLIENT_SECRET: "${CF_ACCESS_CLIENT_SECRET}"
|
||||
BASH_ENV: "/usr/local/bin/git-cf-access-init.sh"
|
||||
extra_hosts:
|
||||
- "gitea.git.svc.cluster.local:10.43.1.53"
|
||||
EOF
|
||||
|
||||
Reference in New Issue
Block a user