From 22a185a6ed437ea4adb7bf273834a86763ea4eca Mon Sep 17 00:00:00 2001 From: eternal-flame-AD Date: Fri, 8 Nov 2024 07:47:15 -0600 Subject: [PATCH] init docker in docker Signed-off-by: eternal-flame-AD --- .gitignore | 1 + config.yml | 91 +++++++++++++++++++++++++++ docker-compose.yml | 27 ++++++++ images/scrachpad/archlinux/Dockerfile | 6 ++ images/scrachpad/node-20/Dockerfile | 2 + images/scrachpad/ubuntu/Dockerfile | 6 ++ 6 files changed, 133 insertions(+) create mode 100644 .gitignore create mode 100644 config.yml create mode 100644 docker-compose.yml create mode 100644 images/scrachpad/archlinux/Dockerfile create mode 100644 images/scrachpad/node-20/Dockerfile create mode 100644 images/scrachpad/ubuntu/Dockerfile diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..a7ca880 --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +/workspace diff --git a/config.yml b/config.yml new file mode 100644 index 0000000..0ec8472 --- /dev/null +++ b/config.yml @@ -0,0 +1,91 @@ +# Example configuration file, it's safe to copy this as the default config file without any modification. + +# You don't have to copy this file to your instance, +# just run `./act_runner generate-config > config.yaml` to generate a config file. + +log: + # The level of logging, can be trace, debug, info, warn, error, fatal + level: info + +runner: + # Where to store the registration result. + file: .runner + # Execute how many tasks concurrently at the same time. + capacity: 1 + # Extra environment variables to run jobs. + envs: DOCKER_HOST=tcp://dind:2376 + # Extra environment variables to run jobs from a file. + # It will be ignored if it's empty or the file doesn't exist. + env_file: .env + # The timeout for a job to be finished. + # Please note that the Forgejo instance also has a timeout (3h by default) for the job. + # So the job could be stopped by the Forgejo instance if it's timeout is shorter than this. + timeout: 3h + # Whether skip verifying the TLS certificate of the Forgejo instance. + insecure: false + # The timeout for fetching the job from the Forgejo instance. + fetch_timeout: 5s + # The interval for fetching the job from the Forgejo instance. + fetch_interval: 2s + # The labels of a runner are used to determine which jobs the runner can run, and how to run them. + # Like: ["macos-arm64:host", "ubuntu-latest:docker://node:16-bullseye", "ubuntu-22.04:docker://node:16-bullseye"] + # If it's empty when registering, it will ask for inputting labels. + # If it's empty when execute `deamon`, will use labels in `.runner` file. + labels: + - "archlinux:docker://archlinux:base-devel" + +cache: + # Enable cache server to use actions/cache. + enabled: true + # The directory to store the cache data. + # If it's empty, the cache data will be stored in $HOME/.cache/actcache. + dir: "" + # The host of the cache server. + # It's not for the address to listen, but the address to connect from job containers. + # So 0.0.0.0 is a bad choice, leave it empty to detect automatically. + host: "" + # The port of the cache server. + # 0 means to use a random available port. + port: 0 + # The external cache server URL. Valid only when enable is true. + # If it's specified, act_runner will use this URL as the ACTIONS_CACHE_URL rather than start a server by itself. + # The URL should generally end with "/". + external_server: "" + +container: + # Specifies the network to which the container will connect. + # Could be host, bridge or the name of a custom network. + # If it's empty, create a network automatically. + network: "" + # Whether to create networks with IPv6 enabled. Requires the Docker daemon to be set up accordingly. + # Only takes effect if "network" is set to "". + enable_ipv6: true + # Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker). + privileged: false + # And other options to be used when the container is started (eg, --add-host=my.forgejo.url:host-gateway). + options: -u forgejo-job:forgejo-job --security-opt=no-new-privileges -m 8g + # The parent directory of a job's working directory. + # If it's empty, /workspace will be used. + workdir_parent: + # Volumes (including bind mounts) can be mounted to containers. Glob syntax is supported, see https://github.com/gobwas/glob + # You can specify multiple volumes. If the sequence is empty, no volumes can be mounted. + # For example, if you only allow containers to mount the `data` volume and all the json files in `/src`, you should change the config to: + # valid_volumes: + # - data + # - /src/*.json + # If you want to allow any volume, please use the following configuration: + # valid_volumes: + # - '**' + valid_volumes: [] + # overrides the docker client host with the specified one. + # If it's empty, act_runner will find an available docker host automatically. + # If it's "-", act_runner will find an available docker host automatically, but the docker host won't be mounted to the job containers and service containers. + # If it's not empty or "-", the specified docker host will be used. An error will be returned if it doesn't work. + docker_host: "" + # Pull docker image(s) even if already present + force_pull: false + +host: + # The parent directory of a job's working directory. + # If it's empty, $HOME/.cache/act/ will be used. + workdir_parent: /dev/null diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..7d9df9a --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,27 @@ +name: yume-forgejo-runner + +services: + dind: + image: docker:27.3-dind-rootless + environment: + - DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS="-p 0.0.0.0:2376:2376/tcp" + privileged: true + networks: + - dind-network + + runner: + image: code.forgejo.org/forgejo/runner:4.0.1 + links: + - dind + networks: + - dind-network + - external-network + volumes: + - ./config.yaml:/config.yaml + - ./workspace:/workspace + - /var/run/docker.sock:/var/run/docker.sock + +networks: + dind-network: + internal: true + external-network: \ No newline at end of file diff --git a/images/scrachpad/archlinux/Dockerfile b/images/scrachpad/archlinux/Dockerfile new file mode 100644 index 0000000..ba5452d --- /dev/null +++ b/images/scrachpad/archlinux/Dockerfile @@ -0,0 +1,6 @@ +FROM archlinux:base-devel + +RUN pacman -Syu --noconfirm fish git curl wget unzip tar gzip bzip2 xz && \ + pacman -Scc --noconfirm && \ + rm -rf /var/cache/pacman/pkg/* + diff --git a/images/scrachpad/node-20/Dockerfile b/images/scrachpad/node-20/Dockerfile new file mode 100644 index 0000000..da8c086 --- /dev/null +++ b/images/scrachpad/node-20/Dockerfile @@ -0,0 +1,2 @@ +FROM node:20-bookworm + diff --git a/images/scrachpad/ubuntu/Dockerfile b/images/scrachpad/ubuntu/Dockerfile new file mode 100644 index 0000000..503e92b --- /dev/null +++ b/images/scrachpad/ubuntu/Dockerfile @@ -0,0 +1,6 @@ +FROM debian:bookworm + +RUN apt-get update && apt-get install -y fish build-essential git curl wget unzip tar gzip bzip2 xz-utils && \ + apt-get clean && \ + rm -rf /var/lib/apt/lists/* +