fix: 镜像改走 NAS 内网仓库

Co-Authored-By: Codex <noreply@anthropic.com>
This commit is contained in:
2026-08-13 01:42:17 +08:00
co-authored by Codex
parent 2da4854a16
commit 981e42671f
5 changed files with 25 additions and 3 deletions
+4 -3
View File
@@ -12,7 +12,8 @@ jobs:
runs-on: plainleaf-release
timeout-minutes: 120
env:
IMAGE_REPOSITORY: gitea.aichickenfarm.cn/wushenghua/plainleaf
REGISTRY_ENDPOINT: 192.168.31.68:8092
IMAGE_REPOSITORY: 192.168.31.68:8092/wushenghua/plainleaf
REGISTRY_USERNAME: wushenghua
steps:
- name: 检出代码
@@ -34,7 +35,7 @@ jobs:
run: |
set -euo pipefail
printf '%s' "${REGISTRY_TOKEN}" | docker login \
gitea.aichickenfarm.cn \
"${REGISTRY_ENDPOINT}" \
--username "${REGISTRY_USERNAME}" \
--password-stdin
env:
@@ -92,4 +93,4 @@ jobs:
if: ${{ always() }}
run: |
rm -f "${HOME}/.ssh/plainleaf_deploy"
docker logout gitea.aichickenfarm.cn || true
docker logout "${REGISTRY_ENDPOINT}" || true
+14
View File
@@ -21,6 +21,7 @@ const releaseWorkflow = readFileSync(
"utf8",
);
const runnerCompose = readFileSync("deploy/runner/compose.yaml", "utf8");
const runnerDaemon = readFileSync("deploy/runner/daemon.json", "utf8");
const runnerConfig = readFileSync("deploy/runner/config.yaml", "utf8");
const runnerInstaller = readFileSync("deploy/runner/install-runner.sh", "utf8");
@@ -62,6 +63,13 @@ test("NAS deployment follows the Gitea edge image", () => {
expect(releaseWorkflow).toContain("runs-on: plainleaf-release");
expect(releaseWorkflow).toContain("REGISTRY_TOKEN");
expect(releaseWorkflow).toContain("NAS_DEPLOY_KEY");
expect(releaseWorkflow).toContain("REGISTRY_ENDPOINT: 192.168.31.68:8092");
expect(releaseWorkflow).toContain(
"IMAGE_REPOSITORY: 192.168.31.68:8092/wushenghua/plainleaf",
);
expect(releaseWorkflow).not.toContain(
"IMAGE_REPOSITORY: gitea.aichickenfarm.cn",
);
expect(releaseWorkflow).toContain("--platform linux/amd64");
expect(releaseWorkflow).toContain('--tag "${IMAGE_REPOSITORY}:edge"');
expect(releaseWorkflow).toContain("push_with_retry");
@@ -116,6 +124,12 @@ test("dedicated Actions runner is isolated from the NAS Docker daemon", () => {
expect(runnerCompose).not.toContain("PLAINLEAF_SERVER_PATH");
expect(runnerCompose).toContain("unix:///run/user/1000/docker.sock");
expect(runnerCompose).not.toContain("unix:///var/run/user/1000/docker.sock");
expect(runnerCompose).toContain(
"./daemon.json:/home/rootless/.config/docker/daemon.json:ro",
);
expect(JSON.parse(runnerDaemon)).toEqual({
"insecure-registries": ["192.168.31.68:8092"],
});
expect(runnerConfig).toContain("capacity: 1");
expect(runnerConfig).toContain("privileged: false");
expect(runnerConfig).toContain("valid_volumes: []");
+3
View File
@@ -11,10 +11,13 @@ Runner 使用固定版本 `gitea/runner:3.1.0-dind-rootless` 和独立的 Docker
- 任务容器禁止 privileged 模式和任意 volume 挂载
- 同时只执行一个任务,最多使用 3 核 CPU、8 GB 内存
- 不挂载 Plainleaf 的 `/data` 或 Markdown 目录
- 只将 NAS 内网 Gitea Registry `192.168.31.68:8092` 标记为 HTTP Registry
外层 rootless DinD 需要 `privileged: true` 才能创建用户命名空间和内部 Docker
守护进程。由于极空间没有 `rootlesskit` AppArmor profile,Runner 单独使用
`apparmor=unconfined`;它只挂载 Runner 自身的目录和命名卷,不挂载任何业务数据。
镜像登录和推送直接走 NAS 内网 Registry,避免大镜像经过公网 FRP;Gitea 中的包
仍可由 NAS 更新服务通过 `gitea.aichickenfarm.cn` 的 HTTPS 地址拉取。
## 一次性注册
+1
View File
@@ -19,6 +19,7 @@ services:
volumes:
- ./data:/data
- ./config.yaml:/config.yaml:ro
- ./daemon.json:/home/rootless/.config/docker/daemon.json:ro
- runner_docker:/home/rootless/.local/share/docker
cpus: 3.0
mem_limit: 8g
+3
View File
@@ -0,0 +1,3 @@
{
"insecure-registries": ["192.168.31.68:8092"]
}