3 Commits

4 changed files with 16 additions and 20 deletions
+7 -5
View File
@@ -29,11 +29,13 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
zstd \ zstd \
&& rm -rf /var/lib/apt/lists/* && rm -rf /var/lib/apt/lists/*
# Node.js 20 LTS — required to execute Forgejo JS actions (checkout, upload-artifact, cache, etc.) # Node.js 20 LTS via binary tarball (nodesource apt repo is unreliable on Ubuntu 24.04)
RUN curl -fsSL https://deb.nodesource.com/setup_20.x | bash - \ RUN NODE_VERSION=20.19.1 \
&& apt-get install -y nodejs \ && curl -fsSL "https://nodejs.org/dist/v${NODE_VERSION}/node-v${NODE_VERSION}-linux-x64.tar.xz" \
&& npm install -g yarn \ | tar -xJ -C /usr/local --strip-components=1 \
&& rm -rf /var/lib/apt/lists/* && node --version \
&& npm --version \
&& npm install -g yarn
# Python 3 + pip + venv # Python 3 + pip + venv
RUN apt-get update && apt-get install -y --no-install-recommends \ RUN apt-get update && apt-get install -y --no-install-recommends \
@@ -8,7 +8,7 @@ metadata:
labels: labels:
app: gitea-runner app: gitea-runner
annotations: annotations:
config-version: "2026-05-04-public-instance-url" config-version: "2026-05-04-docker-sock-fix"
spec: spec:
replicas: 1 replicas: 1
selector: selector:
@@ -19,7 +19,7 @@ spec:
labels: labels:
app: gitea-runner app: gitea-runner
annotations: annotations:
config-version: "2026-05-04-public-instance-url" config-version: "2026-05-04-docker-sock-fix"
spec: spec:
securityContext: securityContext:
runAsNonRoot: false runAsNonRoot: false
@@ -92,7 +92,7 @@ metadata:
labels: labels:
app: neuron-technologies-runner app: neuron-technologies-runner
annotations: annotations:
config-version: "2026-05-04-public-instance-url" config-version: "2026-05-04-docker-sock-fix"
spec: spec:
replicas: 2 replicas: 2
selector: selector:
@@ -103,7 +103,7 @@ spec:
labels: labels:
app: neuron-technologies-runner app: neuron-technologies-runner
annotations: annotations:
config-version: "2026-05-04-public-instance-url" config-version: "2026-05-04-docker-sock-fix"
spec: spec:
securityContext: securityContext:
runAsNonRoot: false runAsNonRoot: false
@@ -17,13 +17,7 @@ spec:
creationPolicy: Owner creationPolicy: Owner
template: template:
data: data:
# Public URL — the in-cluster name (gitea.git.svc.cluster.local) is GITEA_INSTANCE_URL: "http://gitea.git.svc.cluster.local:3000"
# not resolvable from build containers running with `network: host`,
# which causes `git fetch` to fail at the very first checkout step.
# The runner polls Gitea over Cloudflare; the latency cost is small
# and the build container's clone URL is derived from this instance,
# so it has to be a name the build container can resolve.
GITEA_INSTANCE_URL: "https://git.neuralplatform.ai"
GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}" GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}"
data: data:
- secretKey: runner_token - secretKey: runner_token
@@ -47,8 +41,7 @@ spec:
creationPolicy: Owner creationPolicy: Owner
template: template:
data: data:
# Public URL — see commentary on the gitea-runner-secret above. GITEA_INSTANCE_URL: "http://gitea.git.svc.cluster.local:3000"
GITEA_INSTANCE_URL: "https://git.neuralplatform.ai"
GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}" GITEA_RUNNER_REGISTRATION_TOKEN: "{{ .runner_token }}"
data: data:
- secretKey: runner_token - secretKey: runner_token
@@ -14,5 +14,6 @@ spec:
services: services:
- name: dharma - name: dharma
port: 8765 port: 8765
tls: # TLS terminates at Cloudflare; tunnel reaches Traefik with noTLSVerify.
certResolver: letsencrypt # Traefik websecure entrypoint has its own default cert (no resolver
# configured in this cluster), matching every other neuron-prod IngressRoute.