feat: the release runner fabrikk-release, defined here and nowhere else #14
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "release-runner"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome.
release.yamlneeds a runner labelledfabrikk-release; none existed.swamp workflow run fabrikk-runnernow creates it inforgejo-runnersondataverket-prod, and it is live: runnerfabrikk-release, repo scoped on this repository, jobs ingolang:1.25-bookworm.What is in the change
workflows/workflow-fabrikk-runner.yaml: registration token into the vault, init and config secrets, one Cinder volume, and a Deployment that is a Kata VM with docker-in-docker. Every step is guarded by its record, so a re-run creates only what is missing. Flux does not know these objects; this repository owns them.dataverket-prod-{pods,secrets,pvcs,deployments}for namespaceforgejo-runners.forgejo_actions.ts:runner_prunedeletes the offline runners of one name (with a test);runner_listtolerates runners sharing a name.Found on the way. Every job on the org runner failed at image pull, not because of nested virt: a Kata guest's volumes are virtiofs and Talos starts virtiofsd without
--xattr, so docker cannot register layers with file capabilities. The pod annotationio.katacontainers.config.hypervisor.virtio_fs_extra_args: '["--xattr"]'fixes it, verified with a test pod. The org runner's copy is fabrikk-infra PR #6; the release runner carries it from the start.Not in this PR. The cosign key and the seeding sidecar (README, Release signing key). Runner images are referenced from their upstream registries, pinned by digest, like the org runner in fabrikk-infra; mirroring them into the Dataverket registry is a follow-up. No product code, so no ADR. Protected paths touched:
workflows/,extensions/.