@@ -12,7 +12,8 @@ jobs:
|
||||
runs-on: plainleaf-release
|
||||
timeout-minutes: 120
|
||||
env:
|
||||
IMAGE_REPOSITORY: gitea.aichickenfarm.cn/wushenghua/plainleaf
|
||||
REGISTRY_ENDPOINT: 192.168.31.68:8092
|
||||
IMAGE_REPOSITORY: 192.168.31.68:8092/wushenghua/plainleaf
|
||||
REGISTRY_USERNAME: wushenghua
|
||||
steps:
|
||||
- name: 检出代码
|
||||
@@ -34,7 +35,7 @@ jobs:
|
||||
run: |
|
||||
set -euo pipefail
|
||||
printf '%s' "${REGISTRY_TOKEN}" | docker login \
|
||||
gitea.aichickenfarm.cn \
|
||||
"${REGISTRY_ENDPOINT}" \
|
||||
--username "${REGISTRY_USERNAME}" \
|
||||
--password-stdin
|
||||
env:
|
||||
@@ -92,4 +93,4 @@ jobs:
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
rm -f "${HOME}/.ssh/plainleaf_deploy"
|
||||
docker logout gitea.aichickenfarm.cn || true
|
||||
docker logout "${REGISTRY_ENDPOINT}" || true
|
||||
|
||||
@@ -21,6 +21,7 @@ const releaseWorkflow = readFileSync(
|
||||
"utf8",
|
||||
);
|
||||
const runnerCompose = readFileSync("deploy/runner/compose.yaml", "utf8");
|
||||
const runnerDaemon = readFileSync("deploy/runner/daemon.json", "utf8");
|
||||
const runnerConfig = readFileSync("deploy/runner/config.yaml", "utf8");
|
||||
const runnerInstaller = readFileSync("deploy/runner/install-runner.sh", "utf8");
|
||||
|
||||
@@ -62,6 +63,13 @@ test("NAS deployment follows the Gitea edge image", () => {
|
||||
expect(releaseWorkflow).toContain("runs-on: plainleaf-release");
|
||||
expect(releaseWorkflow).toContain("REGISTRY_TOKEN");
|
||||
expect(releaseWorkflow).toContain("NAS_DEPLOY_KEY");
|
||||
expect(releaseWorkflow).toContain("REGISTRY_ENDPOINT: 192.168.31.68:8092");
|
||||
expect(releaseWorkflow).toContain(
|
||||
"IMAGE_REPOSITORY: 192.168.31.68:8092/wushenghua/plainleaf",
|
||||
);
|
||||
expect(releaseWorkflow).not.toContain(
|
||||
"IMAGE_REPOSITORY: gitea.aichickenfarm.cn",
|
||||
);
|
||||
expect(releaseWorkflow).toContain("--platform linux/amd64");
|
||||
expect(releaseWorkflow).toContain('--tag "${IMAGE_REPOSITORY}:edge"');
|
||||
expect(releaseWorkflow).toContain("push_with_retry");
|
||||
@@ -116,6 +124,12 @@ test("dedicated Actions runner is isolated from the NAS Docker daemon", () => {
|
||||
expect(runnerCompose).not.toContain("PLAINLEAF_SERVER_PATH");
|
||||
expect(runnerCompose).toContain("unix:///run/user/1000/docker.sock");
|
||||
expect(runnerCompose).not.toContain("unix:///var/run/user/1000/docker.sock");
|
||||
expect(runnerCompose).toContain(
|
||||
"./daemon.json:/home/rootless/.config/docker/daemon.json:ro",
|
||||
);
|
||||
expect(JSON.parse(runnerDaemon)).toEqual({
|
||||
"insecure-registries": ["192.168.31.68:8092"],
|
||||
});
|
||||
expect(runnerConfig).toContain("capacity: 1");
|
||||
expect(runnerConfig).toContain("privileged: false");
|
||||
expect(runnerConfig).toContain("valid_volumes: []");
|
||||
|
||||
@@ -11,10 +11,13 @@ Runner 使用固定版本 `gitea/runner:3.1.0-dind-rootless` 和独立的 Docker
|
||||
- 任务容器禁止 privileged 模式和任意 volume 挂载
|
||||
- 同时只执行一个任务,最多使用 3 核 CPU、8 GB 内存
|
||||
- 不挂载 Plainleaf 的 `/data` 或 Markdown 目录
|
||||
- 只将 NAS 内网 Gitea Registry `192.168.31.68:8092` 标记为 HTTP Registry
|
||||
|
||||
外层 rootless DinD 需要 `privileged: true` 才能创建用户命名空间和内部 Docker
|
||||
守护进程。由于极空间没有 `rootlesskit` AppArmor profile,Runner 单独使用
|
||||
`apparmor=unconfined`;它只挂载 Runner 自身的目录和命名卷,不挂载任何业务数据。
|
||||
镜像登录和推送直接走 NAS 内网 Registry,避免大镜像经过公网 FRP;Gitea 中的包
|
||||
仍可由 NAS 更新服务通过 `gitea.aichickenfarm.cn` 的 HTTPS 地址拉取。
|
||||
|
||||
## 一次性注册
|
||||
|
||||
|
||||
@@ -19,6 +19,7 @@ services:
|
||||
volumes:
|
||||
- ./data:/data
|
||||
- ./config.yaml:/config.yaml:ro
|
||||
- ./daemon.json:/home/rootless/.config/docker/daemon.json:ro
|
||||
- runner_docker:/home/rootless/.local/share/docker
|
||||
cpus: 3.0
|
||||
mem_limit: 8g
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
{
|
||||
"insecure-registries": ["192.168.31.68:8092"]
|
||||
}
|
||||
Reference in New Issue
Block a user