No description
  • Shell 68.6%
  • Dockerfile 31.4%
Find a file
nisu de05a5ca43
All checks were successful
Build runner images / Build runner:ubuntu-26.04 (push) Successful in 23m52s
feat: runner:ubuntu-26.04, act-24.04's tooling on Ubuntu 26.04 from the archive only
decsys needs podman 5 for its layer cache: 4.9.3, which Ubuntu 24.04 and
catthehacker's act-24.04 ship, never reuses a BlueBuild module step.
Installing podman and the job tools at the start of every job took ~10
minutes on the runner, so they are baked into a job image here instead.

Everything comes from the Ubuntu archive on Canonical's ubuntu:26.04: no
PPAs, vendor repositories, curl-to-bash installers or release tarballs,
because jobs on this image hold signing keys. The README lists where it
differs from act-24.04 (node 22, no npm or mikefarah yq).

The workflow builds it on ubuntu-latest through the runner's own docker
daemon, so the ubuntu-26.04 label picks it up without a pull. It runs a
privileged smoke test (including a nested podman build) and pushes a
moving tag plus a dated tag for rollback. Rebuilt weekly for security
updates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RC7Dz4RcTZyrr4AQdHSTKD
2026-09-11 01:40:43 -04:00
.forgejo/workflows feat: runner:ubuntu-26.04, act-24.04's tooling on Ubuntu 26.04 from the archive only 2026-09-11 01:40:43 -04:00
ubuntu-26.04 feat: runner:ubuntu-26.04, act-24.04's tooling on Ubuntu 26.04 from the archive only 2026-09-11 01:40:43 -04:00
.gitignore feat: runner:ubuntu-26.04, act-24.04's tooling on Ubuntu 26.04 from the archive only 2026-09-11 01:40:43 -04:00
README.md feat: runner:ubuntu-26.04, act-24.04's tooling on Ubuntu 26.04 from the archive only 2026-09-11 01:40:43 -04:00

runner-images

Job container images for this Forgejo instance's Actions runners.

image runner label built from
git.itsnisu.xyz/nisu/runner:ubuntu-26.04 ubuntu-26.04 ubuntu-26.04/

Dated tags (ubuntu-26.04-YYYYMMDD) stay in the registry for rollback. Point the label at one to pin it.

ubuntu-26.04

Ubuntu 26.04 LTS with the tooling workflows expect from catthehacker/ubuntu:act-24.04: git, git-lfs, node, the docker CLI with buildx and compose, python3 with pip/venv/pipx, jq, curl, wget, zstd, zip, sudo, openssh-client. It adds podman 5.7.0.

Every package comes from the Ubuntu archive, on Canonical's official ubuntu:26.04 image. act-24.04 installs git from a PPA, git-lfs from packagecloud, node from nodejs.org tarballs, docker from Microsoft's repository and jq from a GitHub release. Jobs on this image hold signing keys, so none of that is used here.

Why it exists: decsys builds its OS images with podman so the layer cache survives between runs. podman 4.9.3, which is Ubuntu 24.04's and so act-24.04's, never reuses a build step that bind-mounts another stage, and BlueBuild puts that mount on every module. 26.04 is the first LTS with podman 5. Installing the tools at the start of each job instead took about 10 minutes on the runner.

Differences from act-24.04

act-24.04 this image
node 20 and 24, nodejs.org tarballs under /opt/acttoolcache 22 (nodejs, universe). Actions declaring node24 run on it; actions/setup-node still works for other versions
npm bundled with node not installed: Ubuntu's npm pulls in ~340 more packages. apt-get install npm, or use actions/setup-node
yq mikefarah/yq not installed: Ubuntu's yq package is a different tool (kislyuk/yq, a jq wrapper)
ssh ssh (client and server) openssh-client only
known_hosts github.com and dev.azure.com keyscanned at build time none
podman none 5.7.0

podman, nodejs, docker.io, docker-buildx, docker-compose-v2, git-lfs and pipx are in universe: built and signed by Ubuntu, but with best-effort rather than guaranteed security maintenance. docker.io also installs dockerd and containerd; the base image's policy-rc.d stops package scripts from starting them (the smoke test checks it).

Build and update

.forgejo/workflows/build.yml rebuilds on a push to ubuntu-26.04/, weekly (Monday 03:00 UTC) for security updates, and on demand. It runs on ubuntu-latest, not on the label it produces, so a broken image cannot block its own fix.

The build goes through the runner's own docker daemon via the job's mounted socket. That daemon also starts job containers, and with the runner's default force_pull: false it uses the image it already has. The build gets a dated tag first, and the moving ubuntu-26.04 tag is applied only after the smoke test passes. From that point the next ubuntu-26.04 job runs the new build without pulling. A build that fails the test is removed and never touches the label. The push to the registry is what lets a pruned or different runner fetch it; anonymous pulls work, so runners need no registry credentials.

Needs one secret: REGISTRY_TOKEN, a personal access token with write:package. Forgejo's automatic Actions token cannot push packages.

Locally:

docker build --pull -t git.itsnisu.xyz/nisu/runner:ubuntu-26.04 ubuntu-26.04
docker run --rm --privileged git.itsnisu.xyz/nisu/runner:ubuntu-26.04 \
  bash -c "$(cat ubuntu-26.04/test.sh)"

Runner configuration

Add the label to the connection's labels in the runner config. A connection's labels replace runner.labels entirely, so this is the list that counts. Then restart the runner:

server:
  connections:
    forgejo:
      labels:
        - ubuntu-latest:docker://ghcr.io/catthehacker/ubuntu:act-24.04
        - ubuntu-26.04:docker://git.itsnisu.xyz/nisu/runner:ubuntu-26.04

Workflows opt in with runs-on: ubuntu-26.04. Everything under container: in the runner config (privileged, mounts, valid_volumes) applies to every label alike.

After the restart, the runner log's declared successfully line should list both labels.