Compare commits

...
Author SHA1 Message Date
dboreham 6a96b18f81 Update gitea image 2023-04-19 16:59:48 -06:00
telackey e94f634439 Update for latest act_runner. (#29)
* Update for latest act_runner.

* Update README
2023-04-11 15:04:59 -05:00
dboreham 945842e0b5 Merge pull request #28 from cerc-io/dboreham/fix-root-ownership
Fix directory name
2023-04-08 16:56:03 -06:00
dboreham 7c575e93ad Fix directory name 2023-04-08 16:55:23 -06:00
telackey 913c1f180d Support passing container options. (#23)
* Support passing container options.

* - vs _
2023-03-27 22:27:58 -05:00
dboreham 2fec943879 Merge pull request #20 from cerc-io/dboreham/fix-executor-container-name
Fix executor container name
2023-03-26 10:08:18 -06:00
dboreham 704176a80e Fix executor container name 2023-03-26 10:07:31 -06:00
dboreham 7f4bf0efbd Merge pull request #19 from cerc-io/telackey/act_runner
Add support for Gitea actions via act_runner.
2023-03-25 11:36:03 -06:00
telackey 48c5456107 Fix hostname 2023-03-24 23:11:33 -05:00
telackey 5aa2bfcf8b Redirect output 2023-03-24 22:28:50 -05:00
telackey 1a9c3b4ae5 Add support for Gitea actions via act_runner. 2023-03-24 22:21:44 -05:00
dboreham 16ce2e9bb2 Merge pull request #18 from cerc-io/dboreham/gitea-enable-actions
Enable CI/Actions in Gitea
2023-03-20 14:00:01 -06:00
dboreham 4908d65971 Enable CI/Actions in Gitea 2023-03-20 13:59:00 -06:00
dboreham c7b53d2707 Merge pull request #17 from cerc-io/dboreham/fix-for-gitea-1-19
Add token scope for Gitea 1.9
2023-03-20 13:05:11 -06:00
dboreham d9a568ea47 Add token scope for Gitea 1.9 2023-03-20 13:00:50 -06:00
dboreham e136ead3c7 Merge pull request #14 from cerc-io/dboreham/update-gitea-1-9
Update to Gitea 1.9
2023-03-20 09:54:58 -06:00
dboreham 60c10d68cb Update to Gitea 1.9 2023-03-20 09:54:26 -06:00
dboreham 2291b2be8f Merge pull request #12 from cerc-io/dboreham/postgres-container-uid-fix
Override uid/gid of files created in the data dir
2023-02-28 10:23:00 -07:00
dboreham 506f2d35bf Override uid/gid of files created in the data dir 2023-02-28 10:19:42 -07:00
dboreham d74a637189 Merge pull request #11 from cerc-io/dboreham/usability-fixes
Add helpful messages
2023-02-28 09:23:11 -07:00
dboreham 85f9bb3d26 Add helfup messages 2023-02-28 09:00:09 -07:00
dboreham 81f8fe7df0 Merge pull request #9 from cerc-io/dboreham/remove-container-name
Remove extraneous container name
2023-02-28 08:44:53 -07:00
dboreham f6c4d722ef Remove extraneous container name 2023-02-28 08:39:47 -07:00
dboreham aead04bae0 Add sleep hack for gitea 2023-02-17 15:30:55 -07:00
dboreham 3d5a23819b Merge pull request #8 from cerc-io/dboreham/so-integration
Integrate with stack orchestrator
2023-02-17 15:24:45 -07:00
dboreham 942f369f78 Integrate with stack orchestrator 2023-02-17 15:23:14 -07:00
dboreham 9b2bff61d8 Merge pull request #7 from cerc-io/dboreham/update-gitea-doc
Update gitea doc
2023-02-17 09:21:28 -07:00
dboreham 1c1b51d37e Update doc 2023-02-17 09:20:41 -07:00
dboreham 99e5b939d4 Merge pull request #6 from cerc-io/dboreham/gitea-initial-setup
gitea initial setup
2023-02-14 19:07:26 +00:00
dboreham c602ec6994 Full initialization script 2023-02-14 18:58:02 +00:00
dboreham 902e8517ff Initial commit 2023-02-14 13:22:03 +00:00
dboreham ecfd565a3b Merge pull request #5 from cerc-io/dboreham/gitea-unattended-install
Basic unattended install
2023-02-12 22:16:59 +00:00
dboreham 843f2e2c2a Basic unattended install 2023-02-12 22:15:47 +00:00
dboreham e580f90655 Merge pull request #4 from cerc-io/dboreham/fixes
Add host name
2023-01-06 15:50:19 -07:00
dboreham 86bb68fe74 Add host name 2023-01-06 15:49:36 -07:00
dboreham af71828317 Merge pull request #1 from cerc-io/dboreham/add-basic-pipeline
Add gitea
2022-12-14 13:18:11 -07:00
6 changed files with 198 additions and 6 deletions
+14
View File
@@ -0,0 +1,14 @@
FROM ubuntu:22.04
# Install basic tools
RUN apt update && apt install -y gpg curl apt-transport-https ca-certificates lsb-release build-essential
# Add Docker repo
RUN curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
RUN echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
# Add NodeJS repo
RUN curl -fsSL https://deb.nodesource.com/setup_18.x | bash -
# Install Docker and NodeJS packages.
RUN apt update && apt install -y docker-ce nodejs && rm -rf /var/lib/apt/lists/*
+17 -2
View File
@@ -1,3 +1,18 @@
## Manual deployment notes
## Deployment Notes
### Gitea
1. Create admin user in web UI on initial setup
#### Build gitea/act_runner Docker Container
1. To build the `act_runner` container from Gitea, in another directory run:
```
git clone https://gitea.com/gitea/act_runner
cd act_runner
docker build -t cerc/act-runner:local .
```
#### Deploy Gitea Stack
1. `cd ./gitea`
1. Build the task executor container: `docker build -t cerc/act-runner-task-executor:local -f Dockerfile.task-executor .`
1. Run the script `./run-this-first.sh`
1. Bring up the gitea cluster `docker compose up -d`
1. Run the script `./initialize-gitea.sh`
1. Note the access token printed, it will be needed to publish packages.
+50
View File
@@ -0,0 +1,50 @@
# Example configuration file, it's safe to copy this as the default config file without any modification.
log:
# The level of logging, can be trace, debug, info, warn, error, fatal
level: info
runner:
# Where to store the registration result.
file: /data/.runner
# Execute how many tasks concurrently at the same time.
capacity: 1
# # Extra environment variables to run jobs.
# envs:
# A_TEST_ENV_NAME_1: a_test_env_value_1
# A_TEST_ENV_NAME_2: a_test_env_value_2
# # Extra environment variables to run jobs from a file.
# # It will be ignored if it's empty or the file doesn't exist.
# env_file: .env
# # The timeout for a job to be finished.
# # Please note that the Gitea instance also has a timeout (3h by default) for the job.
# # So the job could be stopped by the Gitea instance if it's timeout is shorter than this.
timeout: 3h
# Whether skip verifying the TLS certificate of the Gitea instance.
insecure: false
# The timeout for fetching the job from the Gitea instance.
fetch_timeout: 5s
# The interval for fetching the job from the Gitea instance.
fetch_interval: 2s
cache:
# Enable cache server to use actions/cache.
enabled: true
# The directory to store the cache data.
# If it's empty, the cache data will be stored in $HOME/.cache/actcache.
dir: ""
# The host of the cache server.
# It's not for the address to listen, but the address to connect from job containers.
# So 0.0.0.0 is a bad choice, leave it empty to detect automatically.
host: ""
# The port of the cache server.
# 0 means to use a random available port.
port: 0
container:
# Which network to use for the job containers. Could be bridge, host, none, or the name of a custom network.
network_mode: bridge
# Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker).
privileged: true
# And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway).
options: --add-host=gitea.local:host-gateway
+26 -2
View File
@@ -6,8 +6,7 @@ networks:
services:
server:
image: gitea/gitea:1.17.1
container_name: gitea
image: gitea/gitea:1.19.1
environment:
- USER_UID=1000
- USER_GID=1000
@@ -16,6 +15,11 @@ services:
- GITEA__database__NAME=gitea
- GITEA__database__USER=gitea
- GITEA__database__PASSWD=gitea
- GITEA__server__HTTP_PORT=3000
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
- GITEA__server__ROOT_URL=http://gitea.local:3000/
- GITEA__actions__ENABLED=true
- GITEA__security__INSTALL_LOCK=true
restart: always
networks:
- gitea
@@ -37,7 +41,27 @@ services:
- POSTGRES_USER=gitea
- POSTGRES_PASSWORD=gitea
- POSTGRES_DB=gitea
# Workaround below for lack of docker uid mapping. Change the container's postgres user's uid/gid to match the host user's
entrypoint: bash
command: -c 'usermod -u ${CERC_HOST_UID:-1000} postgres;groupmod -g ${CERC_HOST_GID:-1000} postgres;exec /usr/local/bin/docker-entrypoint.sh postgres'
networks:
- gitea
volumes:
- ./postgres:/var/lib/postgresql/data
runner:
image: cerc/act-runner:local
restart: always
environment:
- GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
- GITEA_INSTANCE_URL=http://gitea.local:3000
- GITEA_RUNNER_LABELS=ubuntu-latest:docker://cerc/act-runner-task-executor:local,ubuntu-22.04:docker://cerc/act-runner-task-executor:local
- CONFIG_FILE=/config/act-runner-config.yml
networks:
- gitea
extra_hosts:
- "gitea.local:host-gateway"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./act-runner:/data
- ./config:/config:ro
+85
View File
@@ -0,0 +1,85 @@
#!/usr/bin/env bash
# Run this script once after bringing up gitea in docker compose
# TODO: add a check to detect that gitea has not fully initialized yet (no user relation error)
GITEA_USER=gitea_admin
GITEA_PASSWORD=admin1234
GITEA_USER_EMAIL=${GITEA_USER}@example.com
GITEA_NEW_ORGANIZATION=cerc-io
GITEA_URL_PREFIX=http://localhost:3000
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
CERC_GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
set -x
fi
# Create admin user
# First check if it already exists
if [[ -z ${CERC_SO_COMPOSE_PROJECT} ]] ; then
compose_command="docker compose"
else
compose_command="docker compose -p ${CERC_SO_COMPOSE_PROJECT}"
fi
sleep 15
${compose_command} exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
if [[ $? == 1 ]] ; then
# Then create if it wasn't found
${compose_command} exec --user git server gitea admin user create --admin --username ${GITEA_USER} --password ${GITEA_PASSWORD} --email ${GITEA_USER_EMAIL}
fi
# HACK: sleep a bit because if we don't gitea will return empty responses
sleep 5
# Check if the token already exists
token_response=$( curl -s "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
-u ${GITEA_USER}:${GITEA_PASSWORD} \
-H "Content-Type: application/json")
if [[ -n ${token_response} ]] ; then
echo ${token_response} | jq --exit-status -r 'to_entries[] | select(.value.name == "'${CERC_GITEA_TOKEN_NAME}'")'
if [[ $? == 0 ]] ; then
token_found=1
fi
fi
if [[ ${token_found} != 1 ]] ; then
# Create access token if not found
# Note that we either create the token here, or we needed to be passed
# the token by the caller. This is because gitea won't release the token
# plaintext post-creation.
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
-u ${GITEA_USER}:${GITEA_PASSWORD} \
-H "Content-Type: application/json" \
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'", "scopes": [ "sudo" ] }' \
| jq -r .sha1 )
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
echo "To use with laconic-so set this environment variable: export CERC_NPM_AUTH_TOKEN=${new_gitea_token}"
CERC_GITEA_AUTH_TOKEN=${new_gitea_token}
else
# If the token exists, then we must have been passed its value.
# If we were not, then we fail hard here.
if [[ -z ${CERC_GITEA_AUTH_TOKEN} ]] ; then
echo "FATAL error: gitea auth token \"${CERC_GITEA_TOKEN_NAME}\" already exists but no CERC_GITEA_AUTH_TOKEN was provided"
exit 1
fi
fi
# Now that we're sure the token exists and is set in CERC_GITEA_AUTH_TOKEN,
# we can proceed with token-authenticated API requests below
# Create org
# First check if it already exists
curl -s "${GITEA_URL_PREFIX}/api/v1/admin/users/${GITEA_USER}/orgs" \
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
-H "Content-Type: application/json" \
-H "accept: application/json" \
| jq --exit-status -r 'to_entries[] | select(.value.name == "'${GITEA_NEW_ORGANIZATION}'")' > /dev/null
if [[ $? != 0 ]] ; then
# If it doesn't exist, create it
# See: https://discourse.gitea.io/t/create-remove-organization-through-api/478
curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/admin/users/${GITEA_USER}/orgs" \
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
-H "Content-Type: application/json" \
-H "accept: application/json" \
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
fi
# Seed a token for act_runner registration.
docker compose -p ${CERC_SO_COMPOSE_PROJECT} exec db psql -U gitea -d gitea -c "INSERT INTO public.action_runner_token(token, owner_id, repo_id, is_active, created, updated, deleted) VALUES('${CERC_GITEA_RUNNER_REGISTRATION_TOKEN}', 0, 0, 'f', 1679000000, 1679000000, NULL);" >/dev/null
echo "Gitea was configured to use host name: gitea.local, ensure that this resolves to localhost, e.g. with sudo vi /etc/hosts"
echo "Success, gitea is properly initialized"
+6 -2
View File
@@ -1,3 +1,7 @@
#!/bin/sh
#!/usr/bin/env bash
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
set -x
fi
mkdir -p ./gitea
mkdir -p ./postgres
mkdir -p ./gitea/ssh
mkdir -p ./act-runner