## Problem
Init container skips registration if `.runner` file exists on PVC:
```
test -f /data/.runner || forgejo-runner register ...
```
This means changing runner labels in `values.yaml` (e.g. the label image fix from PR #1) has **no effect** until PVCs are manually deleted — not GitOps-friendly.
## Fix
Always delete `.runner` and re-register on every pod start:
```
rm -f /data/.runner
forgejo-runner register --no-interactive ...
```
Labels now stay in sync with `values.yaml` automatically. ArgoCD syncs → pods restart → init re-registers with current labels.
## Files Changed
- `k8s/infra/forgejo-runner/templates/deployment.yaml` (init container logic)
## After Merge
ArgoCD syncs → deployment spec changes → pods restart → init re-registers with new labels from PR #1 → CI works across all repos.Reviewed-on: #2
Co-authored-by: rock <[email protected]>
1. Forgejo CI is broken across all repos
Every workflow fails because runner labels point to a bare Alpine image with nothing in it.
┌────────────────────────────────────────┬──────────────────────────────────────┐
│ Before │ After │
├────────────────────────────────────────┼──────────────────────────────────────┤
│ golang:docker://forgejo/runner:6 │ golang:docker://golang:1.26-bookworm │
├────────────────────────────────────────┼──────────────────────────────────────┤
│ No Go, no Node.js, no apt-get, no root │ Go, git, apt-get, root │
└────────────────────────────────────────┴──────────────────────────────────────┘
Plus the docker socket isn't shared between dind sidecar and runner, so even if docker CLI existed, it can't reach the daemon.
┌───────────────────────────────────────────┬─────────────────────────────────────────────────────────────┐
│ Before │ After │
├───────────────────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ dind creates socket in its own filesystem │ Shared /run emptyDir volume │
├───────────────────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ Runner can't see it │ Both containers see /run/docker.sock │
├───────────────────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ No docker_host config │ docker_host: automount passes socket to workflow containers │
Co-authored-by: rock <[email protected]>
- Runner egress: allow 192.168.1.160/32:443. forgejo.riotpiao.com resolves to
the ingress LB, inside the 192.168.1.0/24 block the NetworkPolicy denies, so
docker push hung until timeout.
- dind CA: also mount homelab-ca at /etc/docker/certs.d/forgejo.riotpiao.com/,
the path dockerd actually reads for per-registry trust.
- Pull secret: dockerconfigjson for the api namespace; /v2/ answers 401.
- AppProject: allow the Forgejo repo as a source for api-gw.