ci(deploy): switch to libretech/runner-image:v1, consolidate workflow #43

Merged
libretech merged 1 commits from feat/runner-image-cleanup into main 2026-04-29 14:27:06 +02:00
Owner

Cleanup follow-up to #42.

Summary

  • Replaces the third-party catthehacker/ubuntu:runner-latest image with our own git.librete.ch/libretech/runner-image:v1 (Ubuntu 24.04 + docker CLI + node + git + perl, runner uid 1001 in docker gid 998 — no --user root needed).
  • deploy.yml collapses build + deploy into a single job. Tag computation moved to docker/metadata-action@v5.
  • Removes the per-deploy perl -i rewrite of LIBRENOTES_IMAGE on the host. The host pins it once in /srv/librenotes/.env and main pushes update the rolling :main tag; rollback / release pinning is a manual .env edit + compose pull && up -d (documented in docs/operations.md).
  • Drops the unused generic compose.prod.yaml overlay.
  • ci.yml moves to the same image so make, git, node, go-via-setup-go all work without per-step apt installs.

Why

Two regressions on the previous workflow caught only at runtime:

  1. Workflow-level volumes: /var/run/docker.sock:/var/run/docker.sock collided with act_runner's own auto-mount → Duplicate mount point failure.
  2. The third-party image's runner user (uid 1001) wasn't in the host's docker group, so even after fixing #1 the build failed with permission denied while trying to connect to the docker API.

The bespoke image bakes the group membership in (build-arg DOCKER_GID=998, matches netcup), and the workflow no longer adds a duplicate mount, so both invariants are codified rather than retried.

Verification

  • yq -e . parses both workflow YAMLs.
  • docker compose -f compose.yaml -f compose.netcup.yaml config resolves with the new image ref.
  • Local docker run --rm -v /var/run/docker.sock:/var/run/docker.sock --group-add 131 git.librete.ch/libretech/runner-image:v1 bash -c 'id; docker version; node -v; git --version; make -v | head -1' returns uid=1001 (not root) and lists all required tools.

Out of scope (already in flight elsewhere)

  • Self-hosting CI for the runner-image repo: shipped as git.librete.ch/libretech/runner-image:.gitea/workflows/build.yml.
  • Server update / security audit on netcup itself.
Cleanup follow-up to #42. ## Summary - Replaces the third-party `catthehacker/ubuntu:runner-latest` image with our own `git.librete.ch/libretech/runner-image:v1` (Ubuntu 24.04 + docker CLI + node + git + perl, runner uid 1001 in docker gid 998 — no `--user root` needed). - `deploy.yml` collapses `build` + `deploy` into a single job. Tag computation moved to `docker/metadata-action@v5`. - Removes the per-deploy `perl -i` rewrite of `LIBRENOTES_IMAGE` on the host. The host pins it once in `/srv/librenotes/.env` and main pushes update the rolling `:main` tag; rollback / release pinning is a manual `.env` edit + `compose pull && up -d` (documented in `docs/operations.md`). - Drops the unused generic `compose.prod.yaml` overlay. - `ci.yml` moves to the same image so `make`, `git`, `node`, `go-via-setup-go` all work without per-step apt installs. ## Why Two regressions on the previous workflow caught only at runtime: 1. Workflow-level `volumes: /var/run/docker.sock:/var/run/docker.sock` collided with act_runner's own auto-mount → `Duplicate mount point` failure. 2. The third-party image's `runner` user (uid 1001) wasn't in the host's docker group, so even after fixing #1 the build failed with `permission denied while trying to connect to the docker API`. The bespoke image bakes the group membership in (build-arg `DOCKER_GID=998`, matches netcup), and the workflow no longer adds a duplicate mount, so both invariants are codified rather than retried. ## Verification - `yq -e .` parses both workflow YAMLs. - `docker compose -f compose.yaml -f compose.netcup.yaml config` resolves with the new image ref. - Local `docker run --rm -v /var/run/docker.sock:/var/run/docker.sock --group-add 131 git.librete.ch/libretech/runner-image:v1 bash -c 'id; docker version; node -v; git --version; make -v | head -1'` returns uid=1001 (not root) and lists all required tools. ## Out of scope (already in flight elsewhere) - Self-hosting CI for the runner-image repo: shipped as `git.librete.ch/libretech/runner-image:.gitea/workflows/build.yml`. - Server update / security audit on netcup itself.
libretech added 1 commit 2026-04-29 14:18:36 +02:00
The deploy workflow is now a single job that builds, pushes, and
deploys in one runner. Tag computation moved to docker/metadata-action,
the per-deploy .env perl rewrite is gone (host pins LIBRENOTES_IMAGE
once; main pushes update :main rolling, releases pin to :vX.Y.Z by
manual edit), and both jobs run in our bespoke runner image whose
runner user already has socket access via group membership.

ci.yml moves to the same image so go/make/node are all available
without per-step apt installs.

Drops compose.prod.yaml (unused, redundant with compose.netcup.yaml).
libretech merged commit bb730c2e67 into main 2026-04-29 14:27:06 +02:00
Sign in to join this conversation.