diff --git a/README.md b/README.md index c6c8010..83ef518 100644 --- a/README.md +++ b/README.md @@ -24,6 +24,8 @@ ssh openpunk 'touch /root/.deadtrigger' Some DNS records also need to be set: - an A record with a `git.*` subdomain +A Gitea Act Runner is also setup if the `giteaRunnerToken` variable is defined in your hosts file. + ## Usage First, make sure to install the requirements: ```sh @@ -52,5 +54,5 @@ ansible-playbook -i hosts run.yml --tags restore ## Example hosts file ``` [hosts] -openpunk-vps ansible_host=104.238.138.76 ansible_user=root ansible_connection=ssh +openpunk-vps ansible_host=104.238.138.76 ansible_user=root ansible_connection=ssh giteaRunnerToken=my-token-yayy ``` \ No newline at end of file diff --git a/roles/gitea/defaults/main.yml b/roles/gitea/defaults/main.yml index 6b516f5..12f3fc5 100644 --- a/roles/gitea/defaults/main.yml +++ b/roles/gitea/defaults/main.yml @@ -1,3 +1,4 @@ --- giteaPort: 3000 -giteaBackup: backups/gitea-dump.zip \ No newline at end of file +giteaBackup: backups/gitea-dump.zip # local path +runnerPath: "{{ ansible_env.HOME }}/runner" \ No newline at end of file diff --git a/roles/gitea/files/runner-config.yml b/roles/gitea/files/runner-config.yml new file mode 100644 index 0000000..60fbcd4 --- /dev/null +++ b/roles/gitea/files/runner-config.yml @@ -0,0 +1,94 @@ +# Example configuration file, it's safe to copy this as the default config file without any modification. + +# You don't have to copy this file to your instance, +# just run `./act_runner generate-config > config.yaml` to generate a config file. + +log: + # The level of logging, can be trace, debug, info, warn, error, fatal + level: info + +runner: + # Where to store the registration result. + file: .runner + # Execute how many tasks concurrently at the same time. + capacity: 2 + # Extra environment variables to run jobs from a file. + # It will be ignored if it's empty or the file doesn't exist. + env_file: .env + # The timeout for a job to be finished. + # Please note that the Gitea instance also has a timeout (3h by default) for the job. + # So the job could be stopped by the Gitea instance if it's timeout is shorter than this. + timeout: 3h + # Whether skip verifying the TLS certificate of the Gitea instance. + insecure: false + # The timeout for fetching the job from the Gitea instance. + fetch_timeout: 5s + # The interval for fetching the job from the Gitea instance. + fetch_interval: 2s + # The labels of a runner are used to determine which jobs the runner can run, and how to run them. + # Like: "macos-arm64:host" or "ubuntu-latest:docker://gitea/runner-images:ubuntu-latest" + # Find more images provided by Gitea at https://gitea.com/gitea/runner-images . + # If it's empty when registering, it will ask for inputting labels. + # If it's empty when execute `daemon`, will use labels in `.runner` file. + labels: + - "ubuntu-latest:docker://gitea/runner-images:ubuntu-latest" + - "ubuntu-22.04:docker://gitea/runner-images:ubuntu-22.04" + - "ubuntu-20.04:docker://gitea/runner-images:ubuntu-20.04" + +cache: + # Enable cache server to use actions/cache. + enabled: true + # The directory to store the cache data. + # If it's empty, the cache data will be stored in $HOME/.cache/actcache. + dir: "/data" + # The host of the cache server. + # It's not for the address to listen, but the address to connect from job containers. + # So 0.0.0.0 is a bad choice, leave it empty to detect automatically. + host: "" + # The port of the cache server. + # 0 means to use a random available port. + port: 18088 + # The external cache server URL. Valid only when enable is true. + # If it's specified, act_runner will use this URL as the ACTIONS_CACHE_URL rather than start a server by itself. + # The URL should generally end with "/". + external_server: "" + +container: + # Specifies the network to which the container will connect. + # Could be host, bridge or the name of a custom network. + # If it's empty, act_runner will create a network automatically. + network: "runner-cache" + # Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker). + privileged: false + # And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway). + options: + # The parent directory of a job's working directory. + # NOTE: There is no need to add the first '/' of the path as act_runner will add it automatically. + # If the path starts with '/', the '/' will be trimmed. + # For example, if the parent directory is /path/to/my/dir, workdir_parent should be path/to/my/dir + # If it's empty, /workspace will be used. + workdir_parent: + # Volumes (including bind mounts) can be mounted to containers. Glob syntax is supported, see https://github.com/gobwas/glob + # You can specify multiple volumes. If the sequence is empty, no volumes can be mounted. + # For example, if you only allow containers to mount the `data` volume and all the json files in `/src`, you should change the config to: + # valid_volumes: + # - data + # - /src/*.json + # If you want to allow any volume, please use the following configuration: + # valid_volumes: + # - '**' + valid_volumes: [] + # overrides the docker client host with the specified one. + # If it's empty, act_runner will find an available docker host automatically. + # If it's "-", act_runner will find an available docker host automatically, but the docker host won't be mounted to the job containers and service containers. + # If it's not empty or "-", the specified docker host will be used. An error will be returned if it doesn't work. + docker_host: "" + # Pull docker image(s) even if already present + force_pull: true + # Rebuild docker image(s) even if already present + force_rebuild: false + +host: + # The parent directory of a job's working directory. + # If it's empty, $HOME/.cache/act/ will be used. + workdir_parent: diff --git a/roles/gitea/tasks/main.yml b/roles/gitea/tasks/main.yml index 159ce46..7605829 100644 --- a/roles/gitea/tasks/main.yml +++ b/roles/gitea/tasks/main.yml @@ -17,6 +17,10 @@ gitea_require_signin: false gitea_lfs_server_enabled: true +- name: "Start Gitea Act Runner" + include_tasks: runner.yml + when: giteaRunnerToken is defined + - name: Backup db include_tasks: backup.yml tags: diff --git a/roles/gitea/tasks/runner.yml b/roles/gitea/tasks/runner.yml new file mode 100644 index 0000000..77c5cc5 --- /dev/null +++ b/roles/gitea/tasks/runner.yml @@ -0,0 +1,27 @@ +- name: Make dirs for runner + file: + path: "{{ item }}" + state: directory + loop: + - "{{ runnerPath }}" + - "{{ runnerPath }}/data" + +- name: Copy docker-compose.yml to server + template: + src: ./templates/runner-docker-compose.yml + dest: "{{ runnerPath }}/docker-compose.yml" + +- name: Copy runner.env to server + template: + src: ./templates/runner.env + dest: "{{ runnerPath }}/runner.env" + +- name: Copy runner-config.yml to server + copy: + src: ./files/runner-config.yml + dest: "{{ runnerPath }}/config.yaml" + +- name: Start Gitea runner service + community.docker.docker_compose_v2: + project_src: "{{ runnerPath }}" + state: present \ No newline at end of file diff --git a/roles/gitea/templates/runner-docker-compose.yml b/roles/gitea/templates/runner-docker-compose.yml new file mode 100644 index 0000000..8a97ba5 --- /dev/null +++ b/roles/gitea/templates/runner-docker-compose.yml @@ -0,0 +1,21 @@ +services: + runner: + image: gitea/act_runner:latest + environment: + CONFIG_FILE: /config.yaml + GITEA_INSTANCE_URL: "https://git.{{ domain }}" + env_file: + - ./runner.env + volumes: + - ./config.yaml:/config.yaml + - ./data:/data + - /var/run/docker.sock:/var/run/docker.sock + ports: + - 18088:18088 + networks: + - runner-cache + +networks: + runner-cache: + name: runner-cache + driver: bridge diff --git a/roles/gitea/templates/runner.env b/roles/gitea/templates/runner.env new file mode 100644 index 0000000..be10320 --- /dev/null +++ b/roles/gitea/templates/runner.env @@ -0,0 +1 @@ +GITEA_RUNNER_REGISTRATION_TOKEN="{{ giteaRunnerToken }}"