feat: the release runner fabrikk-release, defined here and nowhere else #14

Merged
beddari merged 1 commit from release-runner into main 2026-09-18 09:08:32 +00:00
Owner

Outcome. release.yaml needs a runner labelled fabrikk-release; none existed. swamp workflow run fabrikk-runner now creates it in forgejo-runners on dataverket-prod, and it is live: runner fabrikk-release, repo scoped on this repository, jobs in golang:1.25-bookworm.

What is in the change

  • workflows/workflow-fabrikk-runner.yaml: registration token into the vault, init and config secrets, one Cinder volume, and a Deployment that is a Kata VM with docker-in-docker. Every step is guarded by its record, so a re-run creates only what is missing. Flux does not know these objects; this repository owns them.
  • Four admin-context models dataverket-prod-{pods,secrets,pvcs,deployments} for namespace forgejo-runners.
  • forgejo_actions.ts: runner_prune deletes the offline runners of one name (with a test); runner_list tolerates runners sharing a name.
  • README and code map updated; the vault carries the registration token.

Found on the way. Every job on the org runner failed at image pull, not because of nested virt: a Kata guest's volumes are virtiofs and Talos starts virtiofsd without --xattr, so docker cannot register layers with file capabilities. The pod annotation io.katacontainers.config.hypervisor.virtio_fs_extra_args: '["--xattr"]' fixes it, verified with a test pod. The org runner's copy is fabrikk-infra PR #6; the release runner carries it from the start.

Not in this PR. The cosign key and the seeding sidecar (README, Release signing key). Runner images are referenced from their upstream registries, pinned by digest, like the org runner in fabrikk-infra; mirroring them into the Dataverket registry is a follow-up. No product code, so no ADR. Protected paths touched: workflows/, extensions/.

**Outcome.** `release.yaml` needs a runner labelled `fabrikk-release`; none existed. `swamp workflow run fabrikk-runner` now creates it in `forgejo-runners` on `dataverket-prod`, and it is live: runner `fabrikk-release`, repo scoped on this repository, jobs in `golang:1.25-bookworm`. **What is in the change** - `workflows/workflow-fabrikk-runner.yaml`: registration token into the vault, init and config secrets, one Cinder volume, and a Deployment that is a Kata VM with docker-in-docker. Every step is guarded by its record, so a re-run creates only what is missing. Flux does not know these objects; this repository owns them. - Four admin-context models `dataverket-prod-{pods,secrets,pvcs,deployments}` for namespace `forgejo-runners`. - `forgejo_actions.ts`: `runner_prune` deletes the offline runners of one name (with a test); `runner_list` tolerates runners sharing a name. - README and code map updated; the vault carries the registration token. **Found on the way.** Every job on the org runner failed at image pull, not because of nested virt: a Kata guest's volumes are virtiofs and Talos starts virtiofsd without `--xattr`, so docker cannot register layers with file capabilities. The pod annotation `io.katacontainers.config.hypervisor.virtio_fs_extra_args: '["--xattr"]'` fixes it, verified with a test pod. The org runner's copy is fabrikk-infra PR #6; the release runner carries it from the start. **Not in this PR.** The cosign key and the seeding sidecar (README, Release signing key). Runner images are referenced from their upstream registries, pinned by digest, like the org runner in fabrikk-infra; mirroring them into the Dataverket registry is a follow-up. No product code, so no ADR. Protected paths touched: `workflows/`, `extensions/`.
feat: the release runner fabrikk-release, defined here and nowhere else
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m47s
e931d7586d
release.yaml runs on a runner labelled fabrikk-release that did not
exist. `swamp workflow run fabrikk-runner` now creates it in
forgejo-runners on dataverket-prod through admin-context models
(dataverket-prod-secrets, -pvcs, -deployments, -pods): a repo-scoped
registration token into the vault, the init and config secrets, one
Cinder volume for docker's images and the runner state, and a
Deployment that is a Kata VM with docker-in-docker. Flux does not
know it. Every step is guarded by its record, so a re-run creates
only what is missing. Jobs run in golang:1.25-bookworm.

Debugging the org runner on the way found why every job there
failed: a Kata guest's volumes are virtiofs and Talos starts
virtiofsd without --xattr, so docker cannot register image layers
that carry file capabilities. The pod annotation
io.katacontainers.config.hypervisor.virtio_fs_extra_args: ["--xattr"]
fixes it (verified with a test pod); the org runner's copy of it is
a fabrikk-infra change (PR #6).

forgejo_actions gains runner_prune, deleting the offline runners of
one name, because a runner that registers and dies before saving
.runner leaves a record on every restart (the first pod did, six
times: the volume was root's and the image runs as 1000). runner_list
now tolerates runners that share a name. Images pinned by digest.
beddari deleted branch release-runner 2026-09-18 09:08:32 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!14
No description provided.