From dbc4a55b025371b965a4463cd4f8334ff774edc5 Mon Sep 17 00:00:00 2001 From: Story Crater Bot <19826264+Riotpiaole@users.noreply.github.com> Date: Fri, 21 Aug 2026 16:49:26 -0700 Subject: [PATCH] feat(forgejo-runner): split into golang/node/rust runners, retire generic docker runner --- k8s/argocd/apps/30-security.yaml | 72 ++++++++++++++++++++--- k8s/infra/forgejo-runner/values-node.yaml | 9 +++ k8s/infra/forgejo-runner/values-rust.yaml | 10 ++++ k8s/infra/forgejo-runner/values.yaml | 10 +++- 4 files changed, 90 insertions(+), 11 deletions(-) create mode 100644 k8s/infra/forgejo-runner/values-node.yaml create mode 100644 k8s/infra/forgejo-runner/values-rust.yaml diff --git a/k8s/argocd/apps/30-security.yaml b/k8s/argocd/apps/30-security.yaml index 85436f0..8a79c3f 100644 --- a/k8s/argocd/apps/30-security.yaml +++ b/k8s/argocd/apps/30-security.yaml @@ -131,21 +131,27 @@ spec: # than failing on "already exists". - ServerSideApply=true --- -# Forgejo runner (local chart), single generic "docker"-labeled instance. -# Being retired in favor of three language-specific instances of the same -# chart (forgejo-runner-golang/-node/-rust). Added here ahead of that removal, -# in its own commit, so it syncs BEFORE the Application is deleted -- a -# non-cascading delete would otherwise orphan this Deployment, its dind -# sidecar and both PVCs (same lesson as the Kong retirement). +# Forgejo runners (local chart, one instance per language), replacing the +# single generic "docker"-labeled runner. Each instance is a full standalone +# Deployment with its own dind sidecar, own PVCs (registration + layer +# cache) and own registered label -- there is no shared generic runner +# anymore, so each instance also builds and pushes images for the repos it +# serves (the chart's ConfigMap/NetworkPolicy fixes for that -- valid_volumes, +# network: host, egress to ingress-nginx -- apply identically to all three). +# +# `values.yaml` is the chart's default and doubles as the golang instance's +# config; node and rust layer a small values-.yaml override on top for +# just runner.name/runner.labels. All three share one runner-token Secret +# (Forgejo registration tokens are reusable across multiple runners, unlike +# GitHub's one-time tokens) -- if that assumption is ever wrong, registration +# will fail loudly in the register initContainer's logs, not silently. apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: forgejo-runner + name: forgejo-runner-golang namespace: argocd annotations: argocd.argoproj.io/sync-wave: "3" - finalizers: - - resources-finalizer.argocd.argoproj.io spec: project: homelab source: @@ -159,3 +165,51 @@ spec: automated: prune: true selfHeal: true +--- +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: forgejo-runner-node + namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "3" +spec: + project: homelab + source: + repoURL: https://github.com/Riotpiaole/riotpiao.homelab.com.git + targetRevision: main + path: k8s/infra/forgejo-runner + helm: + valueFiles: + - values-node.yaml + destination: + server: https://kubernetes.default.svc + namespace: cicd + syncPolicy: + automated: + prune: true + selfHeal: true +--- +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: forgejo-runner-rust + namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "3" +spec: + project: homelab + source: + repoURL: https://github.com/Riotpiaole/riotpiao.homelab.com.git + targetRevision: main + path: k8s/infra/forgejo-runner + helm: + valueFiles: + - values-rust.yaml + destination: + server: https://kubernetes.default.svc + namespace: cicd + syncPolicy: + automated: + prune: true + selfHeal: true diff --git a/k8s/infra/forgejo-runner/values-node.yaml b/k8s/infra/forgejo-runner/values-node.yaml new file mode 100644 index 0000000..0a64186 --- /dev/null +++ b/k8s/infra/forgejo-runner/values-node.yaml @@ -0,0 +1,9 @@ +# Override on top of values.yaml (the chart's defaults) for the node-labeled +# runner instance. Only runner.name and runner.labels differ -- everything +# else (image, dind, persistence, tolerations, nodeSelector) is shared. +# +# node:22-bookworm ships Node natively, so unlike the golang/rust instances, +# jobs on this runner need no "install node" step before actions/checkout. +runner: + name: node-runner + labels: "node:docker://node:22-bookworm" diff --git a/k8s/infra/forgejo-runner/values-rust.yaml b/k8s/infra/forgejo-runner/values-rust.yaml new file mode 100644 index 0000000..acc5804 --- /dev/null +++ b/k8s/infra/forgejo-runner/values-rust.yaml @@ -0,0 +1,10 @@ +# Override on top of values.yaml (the chart's defaults) for the rust-labeled +# runner instance. Only runner.name and runner.labels differ -- everything +# else (image, dind, persistence, tolerations, nodeSelector) is shared. +# +# rust:1.83-bookworm -- verified this tag exists (docker manifest inspect) +# before pinning it, per this repo's convention of not trusting a tag exists +# without checking. +runner: + name: rust-runner + labels: "rust:docker://rust:1.83-bookworm" diff --git a/k8s/infra/forgejo-runner/values.yaml b/k8s/infra/forgejo-runner/values.yaml index 4e4df63..38dda1e 100644 --- a/k8s/infra/forgejo-runner/values.yaml +++ b/k8s/infra/forgejo-runner/values.yaml @@ -2,8 +2,14 @@ runner: image: repository: code.forgejo.org/forgejo/runner tag: "6" # pin exact release before apply - name: talos-runner - labels: "docker:docker://node:22-bookworm" + name: golang-runner + # Default image is only used when a job's `container:` doesn't override it + # (both ci.yaml and build.yaml in homelab-frontend do). Retired the old + # "docker" label entirely; every repo this runner serves is Go, so this + # instance carries the golang toolchain and its own dind sidecar builds and + # pushes that repo's images too -- there is no separate generic runner + # anymore. + labels: "golang:docker://golang:1.25-bookworm" # In-cluster Service (:3000) — direct, avoids the ingress/public-hostname hop # (the public URL is :443 which forgejo doesn't serve; runner got i/o timeout). forgejoUrl: http://forgejo-gitea-http.cicd.svc.cluster.local:3000