- Shell 68.6%
- Dockerfile 31.4%
|
All checks were successful
Build runner images / Build runner:ubuntu-26.04 (push) Successful in 23m52s
decsys needs podman 5 for its layer cache: 4.9.3, which Ubuntu 24.04 and catthehacker's act-24.04 ship, never reuses a BlueBuild module step. Installing podman and the job tools at the start of every job took ~10 minutes on the runner, so they are baked into a job image here instead. Everything comes from the Ubuntu archive on Canonical's ubuntu:26.04: no PPAs, vendor repositories, curl-to-bash installers or release tarballs, because jobs on this image hold signing keys. The README lists where it differs from act-24.04 (node 22, no npm or mikefarah yq). The workflow builds it on ubuntu-latest through the runner's own docker daemon, so the ubuntu-26.04 label picks it up without a pull. It runs a privileged smoke test (including a nested podman build) and pushes a moving tag plus a dated tag for rollback. Rebuilt weekly for security updates. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RC7Dz4RcTZyrr4AQdHSTKD |
||
|---|---|---|
| .forgejo/workflows | ||
| ubuntu-26.04 | ||
| .gitignore | ||
| README.md | ||
runner-images
Job container images for this Forgejo instance's Actions runners.
| image | runner label | built from |
|---|---|---|
git.itsnisu.xyz/nisu/runner:ubuntu-26.04 |
ubuntu-26.04 |
ubuntu-26.04/ |
Dated tags (ubuntu-26.04-YYYYMMDD) stay in the registry for rollback. Point
the label at one to pin it.
ubuntu-26.04
Ubuntu 26.04 LTS with the tooling workflows expect from
catthehacker/ubuntu:act-24.04: git, git-lfs, node, the docker CLI with
buildx and compose, python3 with pip/venv/pipx, jq, curl, wget, zstd, zip,
sudo, openssh-client. It adds podman 5.7.0.
Every package comes from the Ubuntu archive, on Canonical's official
ubuntu:26.04 image. act-24.04 installs git from a PPA, git-lfs from
packagecloud, node from nodejs.org tarballs, docker from Microsoft's repository
and jq from a GitHub release. Jobs on this image hold signing keys, so none of
that is used here.
Why it exists: decsys builds its OS images with podman so the layer cache survives between runs. podman 4.9.3, which is Ubuntu 24.04's and so act-24.04's, never reuses a build step that bind-mounts another stage, and BlueBuild puts that mount on every module. 26.04 is the first LTS with podman 5. Installing the tools at the start of each job instead took about 10 minutes on the runner.
Differences from act-24.04
| act-24.04 | this image | |
|---|---|---|
| node | 20 and 24, nodejs.org tarballs under /opt/acttoolcache |
22 (nodejs, universe). Actions declaring node24 run on it; actions/setup-node still works for other versions |
| npm | bundled with node | not installed: Ubuntu's npm pulls in ~340 more packages. apt-get install npm, or use actions/setup-node |
| yq | mikefarah/yq | not installed: Ubuntu's yq package is a different tool (kislyuk/yq, a jq wrapper) |
| ssh | ssh (client and server) |
openssh-client only |
| known_hosts | github.com and dev.azure.com keyscanned at build time | none |
| podman | none | 5.7.0 |
podman, nodejs, docker.io, docker-buildx, docker-compose-v2, git-lfs and pipx are
in universe: built and signed by Ubuntu, but with best-effort rather than
guaranteed security maintenance. docker.io also installs dockerd and
containerd; the base image's policy-rc.d stops package scripts from starting
them (the smoke test checks it).
Build and update
.forgejo/workflows/build.yml rebuilds on a push to ubuntu-26.04/, weekly
(Monday 03:00 UTC) for security updates, and on demand. It runs on
ubuntu-latest, not on the label it produces, so a broken image cannot
block its own fix.
The build goes through the runner's own docker daemon via the job's mounted
socket. That daemon also starts job containers, and with the runner's default
force_pull: false it uses the image it already has. The build gets a dated tag
first, and the moving ubuntu-26.04 tag is applied only after the smoke test
passes. From that point the next ubuntu-26.04 job runs the new build without
pulling. A build that fails the test is removed and never touches the label. The push to the registry is
what lets a pruned or different runner fetch it; anonymous pulls work, so
runners need no registry credentials.
Needs one secret: REGISTRY_TOKEN, a personal access token with
write:package. Forgejo's automatic Actions token cannot push packages.
Locally:
docker build --pull -t git.itsnisu.xyz/nisu/runner:ubuntu-26.04 ubuntu-26.04
docker run --rm --privileged git.itsnisu.xyz/nisu/runner:ubuntu-26.04 \
bash -c "$(cat ubuntu-26.04/test.sh)"
Runner configuration
Add the label to the connection's labels in the runner config. A connection's
labels replace runner.labels entirely, so this is the list that counts.
Then restart the runner:
server:
connections:
forgejo:
labels:
- ubuntu-latest:docker://ghcr.io/catthehacker/ubuntu:act-24.04
- ubuntu-26.04:docker://git.itsnisu.xyz/nisu/runner:ubuntu-26.04
Workflows opt in with runs-on: ubuntu-26.04. Everything under container:
in the runner config (privileged, mounts, valid_volumes) applies to every
label alike.
After the restart, the runner log's declared successfully line should list
both labels.