--- # Gitea CI runner — general-purpose (legion) # Docker socket REMOVED. Builds go through buildkitd TCP endpoint. # Set DOCKER_HOST=tcp://buildkitd.ci.svc.cluster.local:1234 in build steps. apiVersion: apps/v1 kind: Deployment metadata: name: gitea-runner namespace: ci labels: app: gitea-runner spec: replicas: 1 selector: matchLabels: app: gitea-runner template: metadata: labels: app: gitea-runner annotations: config-version: "2026-04-25-buildkit-no-sock" spec: securityContext: runAsNonRoot: false # act_runner needs root for container management initContainers: - name: register image: registry.neuralplatform.ai/ci-base:latest workingDir: /data command: ["/bin/sh", "-c"] args: - | act_runner register \ --instance "$GITEA_INSTANCE_URL" \ --token "$GITEA_RUNNER_REGISTRATION_TOKEN" \ --name legion \ --labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \ --no-interactive cat > /data/config.yaml << 'EOF' runner: capacity: 2 timeout: 3h container: network: host docker_host: "tcp://buildkitd.ci.svc.cluster.local:1234" force_pull: false valid_volumes: [] default_image: "registry.neuralplatform.ai/ci-base:latest" extra_hosts: - "gitea.git.svc.cluster.local:10.43.1.53" EOF envFrom: - secretRef: name: gitea-runner-secret volumeMounts: - name: data mountPath: /data containers: - name: runner image: registry.neuralplatform.ai/ci-base:latest workingDir: /data command: ["act_runner", "daemon", "--config", "/data/config.yaml"] env: - name: DOCKER_HOST value: "tcp://buildkitd.ci.svc.cluster.local:1234" envFrom: - secretRef: name: gitea-runner-secret volumeMounts: - name: data mountPath: /data # docker-sock volume intentionally removed — use buildkitd TCP instead resources: requests: memory: 512Mi cpu: 250m limits: memory: 4Gi cpu: "4" volumes: - name: data emptyDir: {} # docker-sock hostPath intentionally removed --- # Neuron Technologies CI runner apiVersion: apps/v1 kind: Deployment metadata: name: neuron-technologies-runner namespace: ci labels: app: neuron-technologies-runner spec: replicas: 1 selector: matchLabels: app: neuron-technologies-runner template: metadata: labels: app: neuron-technologies-runner annotations: config-version: "2026-04-25-buildkit-no-sock" spec: initContainers: - name: register image: registry.neuralplatform.ai/ci-base:latest workingDir: /data command: ["/bin/sh", "-c"] args: - | act_runner register \ --instance "$GITEA_INSTANCE_URL" \ --token "$GITEA_RUNNER_REGISTRATION_TOKEN" \ --name neuron-technologies \ --labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \ --no-interactive cat > /data/config.yaml << 'EOF' runner: capacity: 2 timeout: 3h container: network: host docker_host: "tcp://buildkitd.ci.svc.cluster.local:1234" force_pull: false valid_volumes: [] default_image: "registry.neuralplatform.ai/ci-base:latest" extra_hosts: - "gitea.git.svc.cluster.local:10.43.1.53" EOF envFrom: - secretRef: name: neuron-technologies-runner-secret volumeMounts: - name: data mountPath: /data containers: - name: runner image: registry.neuralplatform.ai/ci-base:latest workingDir: /data command: ["act_runner", "daemon", "--config", "/data/config.yaml"] env: - name: DOCKER_HOST value: "tcp://buildkitd.ci.svc.cluster.local:1234" envFrom: - secretRef: name: neuron-technologies-runner-secret volumeMounts: - name: data mountPath: /data resources: requests: memory: 512Mi cpu: 250m limits: memory: 4Gi cpu: "4" volumes: - name: data emptyDir: {}