--- # Gitea Actions runner — will org apiVersion: apps/v1 kind: Deployment metadata: name: gitea-runner namespace: ci labels: app: gitea-runner annotations: config-version: "2026-05-04-cf-access-public-url" spec: replicas: 1 selector: matchLabels: app: gitea-runner template: metadata: labels: app: gitea-runner annotations: config-version: "2026-05-04-cf-access-public-url" spec: securityContext: runAsNonRoot: false initContainers: - name: register image: registry.neuralplatform.ai/ci-base:latest command: ["/bin/sh", "-c"] args: - | act_runner register \ --instance "$GITEA_INSTANCE_URL" \ --token "$GITEA_RUNNER_REGISTRATION_TOKEN" \ --name legion \ --labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \ --no-interactive cat > /data/config.yaml << EOF runner: capacity: 2 timeout: 3h container: network: host docker_host: "unix:///var/run/docker.sock" force_pull: false valid_volumes: [] default_image: "registry.neuralplatform.ai/ci-base:latest" # Build containers run with network: host. The in-cluster # gitea name does not resolve there, so we redirect git # operations to https://git.neuralplatform.ai using CF # Access service-token headers. BASH_ENV makes bash source # /usr/local/bin/git-cf-access-init.sh before every step, # which sets up the redirect + headers. env: CF_ACCESS_CLIENT_ID: "${CF_ACCESS_CLIENT_ID}" CF_ACCESS_CLIENT_SECRET: "${CF_ACCESS_CLIENT_SECRET}" BASH_ENV: "/usr/local/bin/git-cf-access-init.sh" extra_hosts: - "gitea.git.svc.cluster.local:10.43.1.53" EOF envFrom: - secretRef: name: gitea-runner-secret volumeMounts: - mountPath: /data name: data workingDir: /data containers: - name: runner image: registry.neuralplatform.ai/ci-base:latest command: ["act_runner", "daemon", "--config", "/data/config.yaml"] envFrom: - secretRef: name: gitea-runner-secret resources: requests: cpu: "250m" memory: "512Mi" limits: cpu: "4" memory: "4Gi" volumeMounts: - mountPath: /data name: data - mountPath: /var/run/docker.sock name: docker-sock workingDir: /data volumes: - name: data emptyDir: {} - name: docker-sock hostPath: path: /var/run/docker.sock type: Socket --- # Gitea Actions runner — neuron-technologies org apiVersion: apps/v1 kind: Deployment metadata: name: neuron-technologies-runner namespace: ci labels: app: neuron-technologies-runner annotations: config-version: "2026-05-04-cf-access-public-url" spec: replicas: 2 selector: matchLabels: app: neuron-technologies-runner template: metadata: labels: app: neuron-technologies-runner annotations: config-version: "2026-05-04-cf-access-public-url" spec: securityContext: runAsNonRoot: false initContainers: - name: register image: registry.neuralplatform.ai/ci-base:latest command: ["/bin/sh", "-c"] args: - | act_runner register \ --instance "$GITEA_INSTANCE_URL" \ --token "$GITEA_RUNNER_REGISTRATION_TOKEN" \ --name "legion-nt-$(hostname)" \ --labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \ --no-interactive cat > /data/config.yaml << EOF runner: capacity: 2 timeout: 3h container: network: host docker_host: "unix:///var/run/docker.sock" force_pull: false valid_volumes: [] default_image: "registry.neuralplatform.ai/ci-base:latest" # Build containers run with network: host. The in-cluster # gitea name does not resolve there, so we redirect git # operations to https://git.neuralplatform.ai using CF # Access service-token headers. BASH_ENV makes bash source # /usr/local/bin/git-cf-access-init.sh before every step, # which sets up the redirect + headers. env: CF_ACCESS_CLIENT_ID: "${CF_ACCESS_CLIENT_ID}" CF_ACCESS_CLIENT_SECRET: "${CF_ACCESS_CLIENT_SECRET}" BASH_ENV: "/usr/local/bin/git-cf-access-init.sh" extra_hosts: - "gitea.git.svc.cluster.local:10.43.1.53" EOF envFrom: - secretRef: name: neuron-technologies-runner-secret volumeMounts: - mountPath: /data name: data workingDir: /data containers: - name: runner image: registry.neuralplatform.ai/ci-base:latest command: ["act_runner", "daemon", "--config", "/data/config.yaml"] envFrom: - secretRef: name: neuron-technologies-runner-secret resources: requests: cpu: "250m" memory: "512Mi" limits: cpu: "4" memory: "4Gi" volumeMounts: - mountPath: /data name: data - mountPath: /var/run/docker.sock name: docker-sock workingDir: /data volumes: - name: data emptyDir: {} - name: docker-sock hostPath: path: /var/run/docker.sock type: Socket