Files
infrastructure/servers/legion/k8s/gitea-runner/deployment.yaml
Will Anderson 5868607c27 fix(ci): point Gitea Actions runners at public instance URL
The in-cluster service DNS (`gitea.git.svc.cluster.local`) is not
resolvable from build containers running with `network: host`. The
runner config has an `extra_hosts` mapping for this name, but `host`
networking shares the host's network namespace and bypasses the
container-level hosts file — which silently nullifies the mapping.

Symptom: every Gitea Actions run on `dharma-el` (and any other
neuron-technologies repo that has CI defined) failed at the first
`actions/checkout` step with `Could not resolve host:
gitea.git.svc.cluster.local`. CI had never actually validated for
that org.

Fix: register both the `will` and `neuron-technologies` runners with
the public URL `https://git.neuralplatform.ai`. The runner polls Gitea
over Cloudflare, and the build container's clone URL is derived from
the runner's instance URL, so it inherits a name the build container
can resolve.

Also bumped `config-version` annotations on both runner deployments
to force a rolling restart — the init container needs to re-register
with the new URL.

Trade-off: the runner now polls Gitea over Cloudflare instead of
directly on the cluster network. Latency cost is small relative to
build time, and the failure mode is gone.
2026-05-04 15:52:10 -05:00

169 lines
5.2 KiB
YAML

---
# Gitea Actions runner — will org
apiVersion: apps/v1
kind: Deployment
metadata:
name: gitea-runner
namespace: ci
labels:
app: gitea-runner
annotations:
config-version: "2026-05-04-public-instance-url"
spec:
replicas: 1
selector:
matchLabels:
app: gitea-runner
template:
metadata:
labels:
app: gitea-runner
annotations:
config-version: "2026-05-04-public-instance-url"
spec:
securityContext:
runAsNonRoot: false
initContainers:
- name: register
image: registry.neuralplatform.ai/ci-base:latest
command: ["/bin/sh", "-c"]
args:
- |
act_runner register \
--instance "$GITEA_INSTANCE_URL" \
--token "$GITEA_RUNNER_REGISTRATION_TOKEN" \
--name legion \
--labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \
--no-interactive
cat > /data/config.yaml << 'EOF'
runner:
capacity: 2
timeout: 3h
container:
network: host
docker_host: "unix:///var/run/docker.sock"
force_pull: false
valid_volumes: []
default_image: "registry.neuralplatform.ai/ci-base:latest"
extra_hosts:
- "gitea.git.svc.cluster.local:10.43.1.53"
EOF
envFrom:
- secretRef:
name: gitea-runner-secret
volumeMounts:
- mountPath: /data
name: data
workingDir: /data
containers:
- name: runner
image: registry.neuralplatform.ai/ci-base:latest
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
envFrom:
- secretRef:
name: gitea-runner-secret
resources:
requests:
cpu: "250m"
memory: "512Mi"
limits:
cpu: "4"
memory: "4Gi"
volumeMounts:
- mountPath: /data
name: data
- mountPath: /var/run/docker.sock
name: docker-sock
workingDir: /data
volumes:
- name: data
emptyDir: {}
- name: docker-sock
hostPath:
path: /var/run/docker.sock
type: Socket
---
# Gitea Actions runner — neuron-technologies org
apiVersion: apps/v1
kind: Deployment
metadata:
name: neuron-technologies-runner
namespace: ci
labels:
app: neuron-technologies-runner
annotations:
config-version: "2026-05-04-public-instance-url"
spec:
replicas: 2
selector:
matchLabels:
app: neuron-technologies-runner
template:
metadata:
labels:
app: neuron-technologies-runner
annotations:
config-version: "2026-05-04-public-instance-url"
spec:
securityContext:
runAsNonRoot: false
initContainers:
- name: register
image: registry.neuralplatform.ai/ci-base:latest
command: ["/bin/sh", "-c"]
args:
- |
act_runner register \
--instance "$GITEA_INSTANCE_URL" \
--token "$GITEA_RUNNER_REGISTRATION_TOKEN" \
--name "legion-nt-$(hostname)" \
--labels "self-hosted:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-latest:docker://registry.neuralplatform.ai/ci-base:latest,ubuntu-24.04:docker://registry.neuralplatform.ai/ci-base:latest,linux,x64" \
--no-interactive
cat > /data/config.yaml << 'EOF'
runner:
capacity: 2
timeout: 3h
container:
network: host
docker_host: "unix:///var/run/docker.sock"
force_pull: false
valid_volumes: []
default_image: "registry.neuralplatform.ai/ci-base:latest"
extra_hosts:
- "gitea.git.svc.cluster.local:10.43.1.53"
EOF
envFrom:
- secretRef:
name: neuron-technologies-runner-secret
volumeMounts:
- mountPath: /data
name: data
workingDir: /data
containers:
- name: runner
image: registry.neuralplatform.ai/ci-base:latest
command: ["act_runner", "daemon", "--config", "/data/config.yaml"]
envFrom:
- secretRef:
name: neuron-technologies-runner-secret
resources:
requests:
cpu: "250m"
memory: "512Mi"
limits:
cpu: "4"
memory: "4Gi"
volumeMounts:
- mountPath: /data
name: data
- mountPath: /var/run/docker.sock
name: docker-sock
workingDir: /data
volumes:
- name: data
emptyDir: {}
- name: docker-sock
hostPath:
path: /var/run/docker.sock
type: Socket