From 86df5d904807c871e78c5574f3c8a0ddbc21ce94 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Wed, 7 Oct 2026 14:50:32 +0200 Subject: [PATCH] docs(cicd): document user-scoped PR runner --- .gitea/runner/README.md | 12 +++++++----- .gitea/runner/setup-pr-runner.sh | 1 + 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/.gitea/runner/README.md b/.gitea/runner/README.md index 7a2375e..194b559 100644 --- a/.gitea/runner/README.md +++ b/.gitea/runner/README.md @@ -3,8 +3,10 @@ The native Gitea runners run on **vps**; production runs on **workstation**. Main-branch checks and image builds use `homelab:host`. Pull request and non-main checks use `homelab-pr:host` under a separate account without Docker -access. Each runner accepts one job at a time; the build waits for every check -to pass. CI and deploy runs also show a summary with +access. The `homelab-pr` runner is registered at User scope for `forust`, so +any repository under that account can schedule jobs that request this label. +Each runner accepts one job at a time; the build waits for every check to pass. +CI and deploy runs also show a summary with the release SHA, image build or reuse results, deploy mode, selected services, and image digests. Failed runs keep a summary of completed image builds, stage results, apply results, and recorded Kubernetes recovery. The final deploy @@ -46,11 +48,11 @@ Install the unprivileged host runner on the VPS: sudo bash .gitea/runner/setup-pr-runner.sh ``` -Get a registration token from the repository Actions runner settings. Run the +Get a registration token from the user Actions runner settings. Run the installer in a terminal. It asks for the token without echoing it, registers the runner as `homelab-pr` with label `homelab-pr:host`, then enables the service. -The work directory is `/var/lib/gitea-pr-runner`. Confirm that Gitea lists -`homelab-pr:host` before merging the workflow change. An unmatched label can +The work directory is `/var/lib/gitea-pr-runner`. Confirm that Gitea lists the +runner as User scope before merging the workflow change. An unmatched label can fall back to the default job image. Renovate PR validation uses `pull_request_target`, which reads the workflow from diff --git a/.gitea/runner/setup-pr-runner.sh b/.gitea/runner/setup-pr-runner.sh index a476b88..7c71679 100755 --- a/.gitea/runner/setup-pr-runner.sh +++ b/.gitea/runner/setup-pr-runner.sh @@ -48,6 +48,7 @@ if [ ! -f /var/lib/gitea-pr-runner/.runner ]; then --no-interactive unset GITEA_RUNNER_REGISTRATION_TOKEN fi +chmod 0600 /var/lib/gitea-pr-runner/.runner systemctl daemon-reload systemctl enable --now gitea-pr-runner.service