Compare commits
27
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6a96b18f81 | ||
|
|
e94f634439 | ||
|
|
945842e0b5 | ||
|
|
7c575e93ad | ||
|
|
913c1f180d | ||
|
|
2fec943879 | ||
|
|
704176a80e | ||
|
|
7f4bf0efbd | ||
|
|
48c5456107 | ||
|
|
5aa2bfcf8b | ||
|
|
1a9c3b4ae5 | ||
|
|
16ce2e9bb2 | ||
|
|
4908d65971 | ||
|
|
c7b53d2707 | ||
|
|
d9a568ea47 | ||
|
|
e136ead3c7 | ||
|
|
60c10d68cb | ||
|
|
2291b2be8f | ||
|
|
506f2d35bf | ||
|
|
d74a637189 | ||
|
|
85f9bb3d26 | ||
|
|
81f8fe7df0 | ||
|
|
f6c4d722ef | ||
|
|
aead04bae0 | ||
|
|
3d5a23819b | ||
|
|
942f369f78 | ||
|
|
9b2bff61d8 |
@@ -0,0 +1,14 @@
|
|||||||
|
FROM ubuntu:22.04
|
||||||
|
|
||||||
|
# Install basic tools
|
||||||
|
RUN apt update && apt install -y gpg curl apt-transport-https ca-certificates lsb-release build-essential
|
||||||
|
|
||||||
|
# Add Docker repo
|
||||||
|
RUN curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
|
||||||
|
RUN echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
|
||||||
|
|
||||||
|
# Add NodeJS repo
|
||||||
|
RUN curl -fsSL https://deb.nodesource.com/setup_18.x | bash -
|
||||||
|
|
||||||
|
# Install Docker and NodeJS packages.
|
||||||
|
RUN apt update && apt install -y docker-ce nodejs && rm -rf /var/lib/apt/lists/*
|
||||||
+12
-1
@@ -1,6 +1,17 @@
|
|||||||
## Deployment notes
|
## Deployment Notes
|
||||||
### Gitea
|
### Gitea
|
||||||
|
|
||||||
|
#### Build gitea/act_runner Docker Container
|
||||||
|
1. To build the `act_runner` container from Gitea, in another directory run:
|
||||||
|
```
|
||||||
|
git clone https://gitea.com/gitea/act_runner
|
||||||
|
cd act_runner
|
||||||
|
docker build -t cerc/act-runner:local .
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Deploy Gitea Stack
|
||||||
1. `cd ./gitea`
|
1. `cd ./gitea`
|
||||||
|
1. Build the task executor container: `docker build -t cerc/act-runner-task-executor:local -f Dockerfile.task-executor .`
|
||||||
1. Run the script `./run-this-first.sh`
|
1. Run the script `./run-this-first.sh`
|
||||||
1. Bring up the gitea cluster `docker compose up -d`
|
1. Bring up the gitea cluster `docker compose up -d`
|
||||||
1. Run the script `./initialize-gitea.sh`
|
1. Run the script `./initialize-gitea.sh`
|
||||||
|
|||||||
@@ -0,0 +1,50 @@
|
|||||||
|
# Example configuration file, it's safe to copy this as the default config file without any modification.
|
||||||
|
|
||||||
|
log:
|
||||||
|
# The level of logging, can be trace, debug, info, warn, error, fatal
|
||||||
|
level: info
|
||||||
|
|
||||||
|
runner:
|
||||||
|
# Where to store the registration result.
|
||||||
|
file: /data/.runner
|
||||||
|
# Execute how many tasks concurrently at the same time.
|
||||||
|
capacity: 1
|
||||||
|
# # Extra environment variables to run jobs.
|
||||||
|
# envs:
|
||||||
|
# A_TEST_ENV_NAME_1: a_test_env_value_1
|
||||||
|
# A_TEST_ENV_NAME_2: a_test_env_value_2
|
||||||
|
# # Extra environment variables to run jobs from a file.
|
||||||
|
# # It will be ignored if it's empty or the file doesn't exist.
|
||||||
|
# env_file: .env
|
||||||
|
# # The timeout for a job to be finished.
|
||||||
|
# # Please note that the Gitea instance also has a timeout (3h by default) for the job.
|
||||||
|
# # So the job could be stopped by the Gitea instance if it's timeout is shorter than this.
|
||||||
|
timeout: 3h
|
||||||
|
# Whether skip verifying the TLS certificate of the Gitea instance.
|
||||||
|
insecure: false
|
||||||
|
# The timeout for fetching the job from the Gitea instance.
|
||||||
|
fetch_timeout: 5s
|
||||||
|
# The interval for fetching the job from the Gitea instance.
|
||||||
|
fetch_interval: 2s
|
||||||
|
|
||||||
|
cache:
|
||||||
|
# Enable cache server to use actions/cache.
|
||||||
|
enabled: true
|
||||||
|
# The directory to store the cache data.
|
||||||
|
# If it's empty, the cache data will be stored in $HOME/.cache/actcache.
|
||||||
|
dir: ""
|
||||||
|
# The host of the cache server.
|
||||||
|
# It's not for the address to listen, but the address to connect from job containers.
|
||||||
|
# So 0.0.0.0 is a bad choice, leave it empty to detect automatically.
|
||||||
|
host: ""
|
||||||
|
# The port of the cache server.
|
||||||
|
# 0 means to use a random available port.
|
||||||
|
port: 0
|
||||||
|
|
||||||
|
container:
|
||||||
|
# Which network to use for the job containers. Could be bridge, host, none, or the name of a custom network.
|
||||||
|
network_mode: bridge
|
||||||
|
# Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker).
|
||||||
|
privileged: true
|
||||||
|
# And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway).
|
||||||
|
options: --add-host=gitea.local:host-gateway
|
||||||
@@ -6,8 +6,7 @@ networks:
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: gitea/gitea:1.18.3
|
image: gitea/gitea:1.19.1
|
||||||
container_name: gitea
|
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -19,6 +18,7 @@ services:
|
|||||||
- GITEA__server__HTTP_PORT=3000
|
- GITEA__server__HTTP_PORT=3000
|
||||||
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
|
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
|
||||||
- GITEA__server__ROOT_URL=http://gitea.local:3000/
|
- GITEA__server__ROOT_URL=http://gitea.local:3000/
|
||||||
|
- GITEA__actions__ENABLED=true
|
||||||
- GITEA__security__INSTALL_LOCK=true
|
- GITEA__security__INSTALL_LOCK=true
|
||||||
restart: always
|
restart: always
|
||||||
networks:
|
networks:
|
||||||
@@ -41,7 +41,27 @@ services:
|
|||||||
- POSTGRES_USER=gitea
|
- POSTGRES_USER=gitea
|
||||||
- POSTGRES_PASSWORD=gitea
|
- POSTGRES_PASSWORD=gitea
|
||||||
- POSTGRES_DB=gitea
|
- POSTGRES_DB=gitea
|
||||||
|
# Workaround below for lack of docker uid mapping. Change the container's postgres user's uid/gid to match the host user's
|
||||||
|
entrypoint: bash
|
||||||
|
command: -c 'usermod -u ${CERC_HOST_UID:-1000} postgres;groupmod -g ${CERC_HOST_GID:-1000} postgres;exec /usr/local/bin/docker-entrypoint.sh postgres'
|
||||||
networks:
|
networks:
|
||||||
- gitea
|
- gitea
|
||||||
volumes:
|
volumes:
|
||||||
- ./postgres:/var/lib/postgresql/data
|
- ./postgres:/var/lib/postgresql/data
|
||||||
|
|
||||||
|
runner:
|
||||||
|
image: cerc/act-runner:local
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
- GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
|
||||||
|
- GITEA_INSTANCE_URL=http://gitea.local:3000
|
||||||
|
- GITEA_RUNNER_LABELS=ubuntu-latest:docker://cerc/act-runner-task-executor:local,ubuntu-22.04:docker://cerc/act-runner-task-executor:local
|
||||||
|
- CONFIG_FILE=/config/act-runner-config.yml
|
||||||
|
networks:
|
||||||
|
- gitea
|
||||||
|
extra_hosts:
|
||||||
|
- "gitea.local:host-gateway"
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
- ./act-runner:/data
|
||||||
|
- ./config:/config:ro
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# Run this script once after bringing up gitea in docker compose
|
# Run this script once after bringing up gitea in docker compose
|
||||||
# TODO: add a check to detect that gitea has not fully initialized yet (no user relation error)
|
# TODO: add a check to detect that gitea has not fully initialized yet (no user relation error)
|
||||||
GITEA_USER=gitea_admin
|
GITEA_USER=gitea_admin
|
||||||
@@ -7,19 +7,36 @@ GITEA_USER_EMAIL=${GITEA_USER}@example.com
|
|||||||
GITEA_NEW_ORGANIZATION=cerc-io
|
GITEA_NEW_ORGANIZATION=cerc-io
|
||||||
GITEA_URL_PREFIX=http://localhost:3000
|
GITEA_URL_PREFIX=http://localhost:3000
|
||||||
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
|
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
|
||||||
|
CERC_GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
|
||||||
|
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||||
|
set -x
|
||||||
|
fi
|
||||||
# Create admin user
|
# Create admin user
|
||||||
# First check if it already exists
|
# First check if it already exists
|
||||||
docker compose exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
|
if [[ -z ${CERC_SO_COMPOSE_PROJECT} ]] ; then
|
||||||
|
compose_command="docker compose"
|
||||||
|
else
|
||||||
|
compose_command="docker compose -p ${CERC_SO_COMPOSE_PROJECT}"
|
||||||
|
fi
|
||||||
|
sleep 15
|
||||||
|
${compose_command} exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
|
||||||
if [[ $? == 1 ]] ; then
|
if [[ $? == 1 ]] ; then
|
||||||
# Then create if it wasn't found
|
# Then create if it wasn't found
|
||||||
docker compose exec --user git server gitea admin user create --admin --username ${GITEA_USER} --password ${GITEA_PASSWORD} --email ${GITEA_USER_EMAIL}
|
${compose_command} exec --user git server gitea admin user create --admin --username ${GITEA_USER} --password ${GITEA_PASSWORD} --email ${GITEA_USER_EMAIL}
|
||||||
fi
|
fi
|
||||||
|
# HACK: sleep a bit because if we don't gitea will return empty responses
|
||||||
|
sleep 5
|
||||||
# Check if the token already exists
|
# Check if the token already exists
|
||||||
curl -s "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
token_response=$( curl -s "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
||||||
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json")
|
||||||
| jq --exit-status -r 'to_entries[] | select(.value.name == "'${CERC_GITEA_TOKEN_NAME}'")' > /dev/null
|
if [[ -n ${token_response} ]] ; then
|
||||||
if [[ $? != 0 ]] ; then
|
echo ${token_response} | jq --exit-status -r 'to_entries[] | select(.value.name == "'${CERC_GITEA_TOKEN_NAME}'")'
|
||||||
|
if [[ $? == 0 ]] ; then
|
||||||
|
token_found=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
if [[ ${token_found} != 1 ]] ; then
|
||||||
# Create access token if not found
|
# Create access token if not found
|
||||||
# Note that we either create the token here, or we needed to be passed
|
# Note that we either create the token here, or we needed to be passed
|
||||||
# the token by the caller. This is because gitea won't release the token
|
# the token by the caller. This is because gitea won't release the token
|
||||||
@@ -27,9 +44,10 @@ if [[ $? != 0 ]] ; then
|
|||||||
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
||||||
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json" \
|
||||||
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'"}' \
|
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'", "scopes": [ "sudo" ] }' \
|
||||||
| jq -r .sha1 )
|
| jq -r .sha1 )
|
||||||
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
|
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
|
||||||
|
echo "To use with laconic-so set this environment variable: export CERC_NPM_AUTH_TOKEN=${new_gitea_token}"
|
||||||
CERC_GITEA_AUTH_TOKEN=${new_gitea_token}
|
CERC_GITEA_AUTH_TOKEN=${new_gitea_token}
|
||||||
else
|
else
|
||||||
# If the token exists, then we must have been passed its value.
|
# If the token exists, then we must have been passed its value.
|
||||||
@@ -58,4 +76,10 @@ if [[ $? != 0 ]] ; then
|
|||||||
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
|
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
|
||||||
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
|
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
# Seed a token for act_runner registration.
|
||||||
|
docker compose -p ${CERC_SO_COMPOSE_PROJECT} exec db psql -U gitea -d gitea -c "INSERT INTO public.action_runner_token(token, owner_id, repo_id, is_active, created, updated, deleted) VALUES('${CERC_GITEA_RUNNER_REGISTRATION_TOKEN}', 0, 0, 'f', 1679000000, 1679000000, NULL);" >/dev/null
|
||||||
|
|
||||||
|
echo "Gitea was configured to use host name: gitea.local, ensure that this resolves to localhost, e.g. with sudo vi /etc/hosts"
|
||||||
echo "Success, gitea is properly initialized"
|
echo "Success, gitea is properly initialized"
|
||||||
|
|||||||
@@ -1,4 +1,7 @@
|
|||||||
#!/bin/env bash
|
#!/usr/bin/env bash
|
||||||
|
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||||
|
set -x
|
||||||
|
fi
|
||||||
mkdir -p ./gitea
|
mkdir -p ./gitea
|
||||||
mkdir -p ./gitea/ssh
|
mkdir -p ./gitea/ssh
|
||||||
mkdir -p ./postgres
|
mkdir -p ./act-runner
|
||||||
|
|||||||
Reference in New Issue
Block a user