Compare commits

...

6 Commits

Author SHA1 Message Date
ef3002e328 environment
Some checks failed
Apply Kuberentes Configs / test-environment (push) Failing after 1s
Apply Kuberentes Configs / update-repo (push) Failing after 1s
Apply Kuberentes Configs / update-infrastructure (push) Has been skipped
2026-02-07 14:12:24 -07:00
6e9d586b9c gitea runner 2026-02-07 14:10:20 -07:00
78bf6e2cce gitea runner 2026-02-07 14:08:10 -07:00
91e94da379 gitea runner 2026-02-07 14:07:16 -07:00
3d9a162b1c gitea runner 2026-02-07 14:05:25 -07:00
2f176f9474 gitea runner 2026-02-07 14:03:42 -07:00
2 changed files with 103 additions and 91 deletions

View File

@@ -1,6 +1,19 @@
name: Apply Kuberentes Configs name: Apply Kuberentes Configs
on: [push, workflow_dispatch] on: [push, workflow_dispatch]
jobs: jobs:
test-environment:
runs-on: home-server
steps:
- name: test basic commands
run: |
echo "=== Environment Info ==="
whoami
pwd
echo "=== Test bash ==="
bash --version
echo "=== Test git ==="
git --version
echo "=== Success ==="
update-repo: update-repo:
runs-on: home-server runs-on: home-server
steps: steps:

View File

@@ -7,7 +7,7 @@
url = "https://git.alexmickelson.guru"; url = "https://git.alexmickelson.guru";
tokenFile = "/data/runner/gitea-infrastructure-token.txt"; tokenFile = "/data/runner/gitea-infrastructure-token.txt";
labels = [ labels = [
"home-server" "home-server:host"
"native:host" "native:host"
]; ];
hostPackages = with pkgs; [ hostPackages = with pkgs; [
@@ -25,16 +25,18 @@
kubernetes-helm kubernetes-helm
]; ];
settings = { settings = {
container = { enabled = false; }; container = {
enabled = false;
}; };
}; };
}; };
};
environment.pathsToLink = [ environment.pathsToLink = [
"/bin" "/bin"
]; ];
users.users.gitea-runner = { users.users.gitea-runner = {
isNormalUser = true; isNormalUser = true;
description = "Gitea Actions Runner"; description = "Gitea Actions Runner";
home = "/home/gitea-runner"; home = "/home/gitea-runner";
@@ -45,30 +47,27 @@
kubernetes-helm kubernetes-helm
]; ];
shell = pkgs.bash; shell = pkgs.bash;
}; };
users.groups.gitea-runner = { }; users.groups.gitea-runner = { };
systemd.tmpfiles.rules = [ systemd.tmpfiles.rules = [
"d /data/runner 0755 gitea-runner gitea-runner -" "d /data/runner 0755 gitea-runner gitea-runner -"
"f /data/runner/gitea-infrastructure-token.txt 0600 gitea-runner gitea-runner -" "f /data/runner/gitea-infrastructure-token.txt 0600 gitea-runner gitea-runner -"
]; "d /var/lib/gitea-runner 0755 gitea-runner gitea-runner -"
"d /var/lib/gitea-runner/infrastructure 0755 gitea-runner gitea-runner -"
];
systemd.services.gitea-runner-infrastructure.serviceConfig = { # Override only the sandboxing settings, keep ExecStart from the module
# Use the actual location where the module creates the .runner file systemd.services.gitea-runner-infrastructure.serviceConfig = {
# Keep the working directory
WorkingDirectory = lib.mkForce "/var/lib/gitea-runner/infrastructure"; WorkingDirectory = lib.mkForce "/var/lib/gitea-runner/infrastructure";
ReadWritePaths = lib.mkForce [ # Override user/group
"/var/lib/gitea-runner" User = lib.mkForce "gitea-runner";
"/data/cloudflare/" Group = lib.mkForce "gitea-runner";
"/data/runner/infrastructure"
"/data/runner" # Remove ALL sandboxing - run as a normal user process
"/home/github/infrastructure"
];
BindReadOnlyPaths = [
"/nix/store"
];
# Disable all sandboxing features
DynamicUser = lib.mkForce false; DynamicUser = lib.mkForce false;
PrivateDevices = lib.mkForce false; PrivateDevices = lib.mkForce false;
PrivateMounts = lib.mkForce false; PrivateMounts = lib.mkForce false;
@@ -91,13 +90,13 @@
LockPersonality = lib.mkForce false; LockPersonality = lib.mkForce false;
SystemCallFilter = lib.mkForce [ ]; SystemCallFilter = lib.mkForce [ ];
RestrictAddressFamilies = lib.mkForce [ ]; RestrictAddressFamilies = lib.mkForce [ ];
ReadWritePaths = lib.mkForce [ ];
BindReadOnlyPaths = lib.mkForce [ ];
User = lib.mkForce "gitea-runner"; # Allow access to devices
Group = lib.mkForce "gitea-runner";
DeviceAllow = lib.mkForce [ "/dev/zfs rw" ]; DeviceAllow = lib.mkForce [ "/dev/zfs rw" ];
DevicePolicy = lib.mkForce "auto"; DevicePolicy = lib.mkForce "auto";
Restart = lib.mkForce "always"; Restart = lib.mkForce "always";
}; };
} }