Merge pull request 'Revert CI to host Docker socket, remove buildkitd' (#19) from feat/marketplace-postgres-infra into main
This commit is contained in:
@@ -1,7 +1,6 @@
|
|||||||
---
|
---
|
||||||
# Gitea CI runner — general-purpose (legion)
|
# Gitea CI runner — general-purpose (legion)
|
||||||
# Docker socket REMOVED. Builds go through buildkitd TCP endpoint.
|
# Uses host Docker socket for container management and docker build/push.
|
||||||
# Set DOCKER_HOST=tcp://buildkitd.ci.svc.cluster.local:1234 in build steps.
|
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
@@ -19,7 +18,7 @@ spec:
|
|||||||
labels:
|
labels:
|
||||||
app: gitea-runner
|
app: gitea-runner
|
||||||
annotations:
|
annotations:
|
||||||
config-version: "2026-04-25-buildkit-no-sock"
|
config-version: "2026-04-26-docker-sock"
|
||||||
spec:
|
spec:
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsNonRoot: false # act_runner needs root for container management
|
runAsNonRoot: false # act_runner needs root for container management
|
||||||
@@ -42,7 +41,7 @@ spec:
|
|||||||
timeout: 3h
|
timeout: 3h
|
||||||
container:
|
container:
|
||||||
network: host
|
network: host
|
||||||
docker_host: "tcp://buildkitd.ci.svc.cluster.local:1234"
|
docker_host: "unix:///var/run/docker.sock"
|
||||||
force_pull: false
|
force_pull: false
|
||||||
valid_volumes: []
|
valid_volumes: []
|
||||||
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
||||||
@@ -60,16 +59,14 @@ spec:
|
|||||||
image: registry.neuralplatform.ai/ci-base:latest
|
image: registry.neuralplatform.ai/ci-base:latest
|
||||||
workingDir: /data
|
workingDir: /data
|
||||||
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
|
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
|
||||||
env:
|
|
||||||
- name: DOCKER_HOST
|
|
||||||
value: "tcp://buildkitd.ci.svc.cluster.local:1234"
|
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: gitea-runner-secret
|
name: gitea-runner-secret
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: data
|
- name: data
|
||||||
mountPath: /data
|
mountPath: /data
|
||||||
# docker-sock volume intentionally removed — use buildkitd TCP instead
|
- name: docker-sock
|
||||||
|
mountPath: /var/run/docker.sock
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
@@ -80,7 +77,10 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: data
|
- name: data
|
||||||
emptyDir: {}
|
emptyDir: {}
|
||||||
# docker-sock hostPath intentionally removed
|
- name: docker-sock
|
||||||
|
hostPath:
|
||||||
|
path: /var/run/docker.sock
|
||||||
|
type: Socket
|
||||||
---
|
---
|
||||||
# Neuron Technologies CI runner
|
# Neuron Technologies CI runner
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
@@ -100,8 +100,10 @@ spec:
|
|||||||
labels:
|
labels:
|
||||||
app: neuron-technologies-runner
|
app: neuron-technologies-runner
|
||||||
annotations:
|
annotations:
|
||||||
config-version: "2026-04-25-buildkit-no-sock"
|
config-version: "2026-04-26-docker-sock"
|
||||||
spec:
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: false
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: register
|
- name: register
|
||||||
image: registry.neuralplatform.ai/ci-base:latest
|
image: registry.neuralplatform.ai/ci-base:latest
|
||||||
@@ -121,7 +123,7 @@ spec:
|
|||||||
timeout: 3h
|
timeout: 3h
|
||||||
container:
|
container:
|
||||||
network: host
|
network: host
|
||||||
docker_host: "tcp://buildkitd.ci.svc.cluster.local:1234"
|
docker_host: "unix:///var/run/docker.sock"
|
||||||
force_pull: false
|
force_pull: false
|
||||||
valid_volumes: []
|
valid_volumes: []
|
||||||
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
default_image: "registry.neuralplatform.ai/ci-base:latest"
|
||||||
@@ -139,15 +141,14 @@ spec:
|
|||||||
image: registry.neuralplatform.ai/ci-base:latest
|
image: registry.neuralplatform.ai/ci-base:latest
|
||||||
workingDir: /data
|
workingDir: /data
|
||||||
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
|
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
|
||||||
env:
|
|
||||||
- name: DOCKER_HOST
|
|
||||||
value: "tcp://buildkitd.ci.svc.cluster.local:1234"
|
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: neuron-technologies-runner-secret
|
name: neuron-technologies-runner-secret
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: data
|
- name: data
|
||||||
mountPath: /data
|
mountPath: /data
|
||||||
|
- name: docker-sock
|
||||||
|
mountPath: /var/run/docker.sock
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
@@ -158,3 +159,7 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: data
|
- name: data
|
||||||
emptyDir: {}
|
emptyDir: {}
|
||||||
|
- name: docker-sock
|
||||||
|
hostPath:
|
||||||
|
path: /var/run/docker.sock
|
||||||
|
type: Socket
|
||||||
|
|||||||
@@ -1,68 +0,0 @@
|
|||||||
---
|
|
||||||
# BuildKit daemon — privileged image builder for CI runners.
|
|
||||||
# Runs as root with privileged=true in the isolated ci namespace.
|
|
||||||
# Rootless mode (moby/buildkit:*-rootless) fails on k3s/containerd because
|
|
||||||
# rootlesskit cannot share mount propagation on the container root fs.
|
|
||||||
#
|
|
||||||
# Runners connect via TCP: DOCKER_HOST=tcp://buildkitd.ci.svc.cluster.local:1234
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: buildkitd
|
|
||||||
namespace: ci
|
|
||||||
labels:
|
|
||||||
app: buildkitd
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: buildkitd
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: buildkitd
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: buildkitd
|
|
||||||
image: moby/buildkit:v0.19.0
|
|
||||||
args:
|
|
||||||
- --addr
|
|
||||||
- tcp://0.0.0.0:1234
|
|
||||||
- --addr
|
|
||||||
- unix:///run/buildkit/buildkitd.sock
|
|
||||||
ports:
|
|
||||||
- name: tcp
|
|
||||||
containerPort: 1234
|
|
||||||
securityContext:
|
|
||||||
privileged: true
|
|
||||||
readinessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: 1234 # k3s/containerd can't exec into privileged containers
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 10
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 200m
|
|
||||||
memory: 256Mi
|
|
||||||
limits:
|
|
||||||
cpu: "4"
|
|
||||||
memory: 4Gi
|
|
||||||
volumeMounts:
|
|
||||||
- name: buildkit-storage
|
|
||||||
mountPath: /var/lib/buildkit
|
|
||||||
volumes:
|
|
||||||
- name: buildkit-storage
|
|
||||||
emptyDir: {}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: buildkitd
|
|
||||||
namespace: ci
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: buildkitd
|
|
||||||
ports:
|
|
||||||
- name: tcp
|
|
||||||
port: 1234
|
|
||||||
targetPort: 1234
|
|
||||||
Reference in New Issue
Block a user