docs(cicd): document user-scoped PR runner
ci / Compose (push) Skipped
ci / Workflows (push) Skipped
ci / Shell (push) Skipped
ci / Formatting (push) Skipped
ci / Python and tests (push) Skipped
ci / Dockerfiles (push) Skipped
ci / Workflows (pull_request) Successful in 14s
ci / Shell (pull_request) Successful in 33s
ci / Formatting (pull_request) Successful in 36s
ci / YAML (pull_request) Successful in 28s
ci / Kubernetes (pull_request) Successful in 11s
ci / YAML (push) Skipped
ci / Kubernetes (push) Skipped
ci / Compose (pull_request) Successful in 23s
ci / Python and tests (pull_request) Successful in 16s
ci / Dockerfiles (pull_request) Successful in 11s
ci / Image (${{ matrix.name }}) (pull_request) Skipped
ci / build (pull_request) Skipped
ci / image-plan (pull_request) Skipped

This commit is contained in:
forust committed 2026-10-07 14:50:32 +02:00
1 parent d7441bbbc2
commit 86df5d9048
2 files changed
+8 -5

No files matched your search

+7 -5
View File
@@ -3,8 +3,10 @@
The native Gitea runners run on **vps**; production runs on **workstation**. The native Gitea runners run on **vps**; production runs on **workstation**.
Main-branch checks and image builds use `homelab:host`. Pull request and Main-branch checks and image builds use `homelab:host`. Pull request and
non-main checks use `homelab-pr:host` under a separate account without Docker non-main checks use `homelab-pr:host` under a separate account without Docker
access. Each runner accepts one job at a time; the build waits for every check access. The `homelab-pr` runner is registered at User scope for `forust`, so
to pass. CI and deploy runs also show a summary with any repository under that account can schedule jobs that request this label.
Each runner accepts one job at a time; the build waits for every check to pass.
CI and deploy runs also show a summary with
the release SHA, image build or reuse results, deploy mode, selected services, the release SHA, image build or reuse results, deploy mode, selected services,
and image digests. Failed runs keep a summary of completed image builds, stage and image digests. Failed runs keep a summary of completed image builds, stage
results, apply results, and recorded Kubernetes recovery. The final deploy results, apply results, and recorded Kubernetes recovery. The final deploy
@@ -46,11 +48,11 @@ Install the unprivileged host runner on the VPS:
sudo bash .gitea/runner/setup-pr-runner.sh sudo bash .gitea/runner/setup-pr-runner.sh
``` ```
Get a registration token from the repository Actions runner settings. Run the Get a registration token from the user Actions runner settings. Run the
installer in a terminal. It asks for the token without echoing it, registers the installer in a terminal. It asks for the token without echoing it, registers the
runner as `homelab-pr` with label `homelab-pr:host`, then enables the service. runner as `homelab-pr` with label `homelab-pr:host`, then enables the service.
The work directory is `/var/lib/gitea-pr-runner`. Confirm that Gitea lists The work directory is `/var/lib/gitea-pr-runner`. Confirm that Gitea lists the
`homelab-pr:host` before merging the workflow change. An unmatched label can runner as User scope before merging the workflow change. An unmatched label can
fall back to the default job image. fall back to the default job image.
Renovate PR validation uses `pull_request_target`, which reads the workflow from Renovate PR validation uses `pull_request_target`, which reads the workflow from
+1
View File
@@ -48,6 +48,7 @@ if [ ! -f /var/lib/gitea-pr-runner/.runner ]; then
--no-interactive --no-interactive
unset GITEA_RUNNER_REGISTRATION_TOKEN unset GITEA_RUNNER_REGISTRATION_TOKEN
fi fi
chmod 0600 /var/lib/gitea-pr-runner/.runner
systemctl daemon-reload systemctl daemon-reload
systemctl enable --now gitea-pr-runner.service systemctl enable --now gitea-pr-runner.service