The runner's job images were built by ansible into localhost/ only, so the nightly CI prune deleted them and every idle stretch ended with CI failing in under a second on `docker pull localhost/gitea-ci:latest` until someone re-ran the role and waited out a rebuild. The previous commit moved them to the Gitea registry; this moves the *build* off the deploy path entirely. - .gitea/workflows/ci-images.yml builds files/Containerfile.* and pushes to git.debyl.io/gitbot/. Per-image change detection, so an ESP-IDF pin bump does not rebuild the other two; weekly schedule for base-image updates; a workflow_dispatch selector. PRs build under a throwaway :pr-<n> tag and drop it -- the build lands in the live runner's store, and act_runner will not re-pull a tag it already has, so a PR using the real tag would hand every later job on this host an unmerged image. - The Containerfiles stop being ansible templates: their version vars are now --build-arg, read by the workflow out of the same defaults/main.yml the role interpolates, so CI and ansible build the same bytes from one set of pins. - LABEL io.debyl.ci-base moves into each Containerfile so neither builder can forget the prune exemption; the workflow re-checks it before pushing. - roles/gitea-actions pulls instead of building. gitea_ci_build_local=true restores the local build+push for seeding a cold registry or when CI is down -- the workflow that builds gitea-ci runs in gitea-ci. - Lint .gitea/ alongside ansible/, and document the flow in the role README. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
94 lines
3.2 KiB
YAML
94 lines
3.2 KiB
YAML
---
|
|
# CI job images. .gitea/workflows/ci-images.yml builds files/Containerfile.*
|
|
# and pushes them to the Gitea registry; this role only logs the runner in and
|
|
# makes sure the images are present, so a plain deploy never waits on a build.
|
|
#
|
|
# Set gitea_ci_build_local=true to build and push from here instead -- see the
|
|
# comment on that variable in defaults/main.yml.
|
|
- name: create gitea-runner registry auth directory
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
ansible.builtin.file:
|
|
path: "{{ gitea_ci_registry_authfile | dirname }}"
|
|
state: directory
|
|
mode: "0700"
|
|
tags: gitea-actions
|
|
|
|
# Docker-format path on purpose: act_runner reads ~/.docker/config.json to
|
|
# authenticate the job-image pull it does when a label's image is missing, and
|
|
# podman falls back to the same file. One login covers both.
|
|
- name: log gitea-runner in to the Gitea container registry
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
containers.podman.podman_login:
|
|
registry: "{{ gitea_ci_registry }}"
|
|
username: "{{ gitea_registry_username }}"
|
|
password: "{{ gitea_registry_token }}"
|
|
authfile: "{{ gitea_ci_registry_authfile }}"
|
|
environment:
|
|
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
|
|
no_log: true
|
|
tags: gitea-actions
|
|
|
|
- name: pull CI images from the registry
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
containers.podman.podman_image:
|
|
name: "{{ item.image }}"
|
|
auth_file: "{{ gitea_ci_registry_authfile }}"
|
|
environment:
|
|
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
|
|
loop: "{{ gitea_ci_images }}"
|
|
loop_control:
|
|
label: "{{ item.image }}"
|
|
when: not (gitea_ci_build_local | bool)
|
|
tags: gitea-actions
|
|
|
|
# --- local build fallback (gitea_ci_build_local=true) ------------------------
|
|
# Only reached when seeding a new namespace or when CI cannot build for us.
|
|
- name: create CI image build directory
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
ansible.builtin.file:
|
|
path: "{{ gitea_runner_home }}/ci-images"
|
|
state: directory
|
|
mode: "0755"
|
|
when: gitea_ci_build_local | bool
|
|
tags: gitea-actions
|
|
|
|
# copy, not template: these are plain Containerfiles that CI builds verbatim.
|
|
# Versions come in as --build-arg from the same defaults/main.yml the workflow
|
|
# reads, so neither builder can drift from the other.
|
|
- name: stage CI Containerfiles
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
ansible.builtin.copy:
|
|
src: "{{ item.containerfile }}"
|
|
dest: "{{ gitea_runner_home }}/ci-images/{{ item.containerfile }}"
|
|
mode: "0644"
|
|
loop: "{{ gitea_ci_images }}"
|
|
loop_control:
|
|
label: "{{ item.containerfile }}"
|
|
when: gitea_ci_build_local | bool
|
|
tags: gitea-actions
|
|
|
|
- name: build and push CI images
|
|
become: true
|
|
become_user: "{{ gitea_runner_user }}"
|
|
containers.podman.podman_image:
|
|
name: "{{ item.image }}"
|
|
path: "{{ gitea_runner_home }}/ci-images"
|
|
build:
|
|
file: "{{ gitea_runner_home }}/ci-images/{{ item.containerfile }}"
|
|
extra_args: "{{ item.build_args }}"
|
|
force: true
|
|
push: true
|
|
auth_file: "{{ gitea_ci_registry_authfile }}"
|
|
environment:
|
|
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
|
|
loop: "{{ gitea_ci_images }}"
|
|
loop_control:
|
|
label: "{{ item.image }}"
|
|
when: gitea_ci_build_local | bool
|
|
tags: gitea-actions
|