ci / Compose (push) Skipped
ci / Workflows (push) Skipped
ci / Shell (push) Skipped
ci / Formatting (push) Skipped
ci / Python and tests (push) Skipped
ci / Dockerfiles (push) Skipped
ci / Workflows (pull_request) Successful in 14s
ci / Shell (pull_request) Successful in 33s
ci / Formatting (pull_request) Successful in 36s
ci / YAML (pull_request) Successful in 28s
ci / Kubernetes (pull_request) Successful in 11s
ci / YAML (push) Skipped
ci / Kubernetes (push) Skipped
ci / Compose (pull_request) Successful in 23s
ci / Python and tests (pull_request) Successful in 16s
ci / Dockerfiles (pull_request) Successful in 11s
ci / Image (${{ matrix.name }}) (pull_request) Skipped
ci / build (pull_request) Skipped
ci / image-plan (pull_request) Skipped
57 lines
2.2 KiB
Bash
Executable File
57 lines
2.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Install a native runner for untrusted PR jobs without Docker access.
|
|
set -euo pipefail
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
[ "$(id -u)" -eq 0 ] || { echo 'Run with sudo on the runner host' >&2; exit 1; }
|
|
for tool in cp cut date getent id install runuser systemctl useradd; do
|
|
command -v "$tool" >/dev/null || { echo "Install missing prerequisite: $tool" >&2; exit 1; }
|
|
done
|
|
command -v /usr/local/bin/gitea-runner >/dev/null || {
|
|
echo 'Install gitea-runner 3.0.2 at /usr/local/bin/gitea-runner first' >&2
|
|
exit 1
|
|
}
|
|
|
|
id gitea-pr-runner >/dev/null 2>&1 || \
|
|
useradd --system --create-home --home-dir /var/lib/gitea-pr-runner --shell /usr/bin/bash gitea-pr-runner
|
|
runner_home="$(getent passwd gitea-pr-runner | cut -d: -f6)"
|
|
[ "$runner_home" = /var/lib/gitea-pr-runner ] || {
|
|
echo 'Unexpected PR runner home; inspect the existing service first' >&2
|
|
exit 1
|
|
}
|
|
case " $(id -nG gitea-pr-runner) " in
|
|
*' docker '*)
|
|
echo 'The PR runner account must not belong to the docker group' >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
install -d -m 0755 /etc/gitea-pr-runner
|
|
stamp="$(date -u +%Y%m%dT%H%M%SZ)"
|
|
for existing in /etc/gitea-pr-runner/config.yaml /etc/systemd/system/gitea-pr-runner.service; do
|
|
[ ! -f "$existing" ] || cp -p "$existing" "$existing.before-$stamp"
|
|
done
|
|
install -m 0644 "$here/pr-config.yaml" /etc/gitea-pr-runner/config.yaml
|
|
install -m 0644 "$here/pr-runner.service" /etc/systemd/system/gitea-pr-runner.service
|
|
|
|
if [ ! -f /var/lib/gitea-pr-runner/.runner ]; then
|
|
read -r -s -p 'Enter the Gitea repository runner registration token: ' runner_token
|
|
printf '\n'
|
|
[ -n "$runner_token" ] || { echo 'Runner token is required' >&2; exit 1; }
|
|
export GITEA_RUNNER_REGISTRATION_TOKEN="$runner_token"
|
|
unset runner_token
|
|
runuser --preserve-environment -u gitea-pr-runner -- \
|
|
/usr/local/bin/gitea-runner register \
|
|
--config /etc/gitea-pr-runner/config.yaml \
|
|
--instance https://gitea.forust.xyz \
|
|
--name homelab-pr \
|
|
--labels homelab-pr:host \
|
|
--no-interactive
|
|
unset GITEA_RUNNER_REGISTRATION_TOKEN
|
|
fi
|
|
chmod 0600 /var/lib/gitea-pr-runner/.runner
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now gitea-pr-runner.service
|
|
systemctl restart gitea-pr-runner.service
|
|
echo "PR runner ready. Configuration backups: *.before-$stamp"
|