From ecd0ae69dace4cccc68c5f12ba6adb458304a964 Mon Sep 17 00:00:00 2001 From: Michael Czechowski Date: Thu, 30 Apr 2026 00:17:05 +0200 Subject: [PATCH 1/5] ci: pin runner-image v2 (adds gcc for cgo, fixes go test -race) v1 lacked gcc, so 'go test -race' (in Makefile) failed in CI with 'go: -race requires cgo'. v2 of the runner image installs gcc, libc6-dev, and pkg-config. --- .gitea/workflows/ci.yml | 2 +- .gitea/workflows/deploy.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 46c4703..75e3fff 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -12,7 +12,7 @@ jobs: # Bespoke runner image (Ubuntu 24.04 + make + git + node + go via # actions/setup-go). See git.librete.ch/libretech/runner-image. container: - image: git.librete.ch/libretech/runner-image:v1 + image: git.librete.ch/libretech/runner-image:v2 timeout-minutes: 5 steps: - name: Checkout diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index ca7346c..1592cd2 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -34,7 +34,7 @@ jobs: # + perl + ssh, runner user pre-joined to docker gid 998 so the # auto-mounted /var/run/docker.sock is writable without --user root. container: - image: git.librete.ch/libretech/runner-image:v1 + image: git.librete.ch/libretech/runner-image:v2 timeout-minutes: 20 if: ${{ vars.DEPLOY_ENABLED == 'true' }} steps: -- 2.36.6 From 6dd20cc9bd668d2bb0b382218f0010519c374a99 Mon Sep 17 00:00:00 2001 From: Michael Czechowski Date: Thu, 30 Apr 2026 11:53:41 +0200 Subject: [PATCH 2/5] ci: update runner-image path to public/ namespace The runner-image repo moved from libretech/ to public/ on Gitea; ci.yml and deploy.yml + docs reference public/runner-image. --- .gitea/workflows/ci.yml | 4 ++-- .gitea/workflows/deploy.yml | 2 +- docs/operations.md | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 75e3fff..c98eec1 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -10,9 +10,9 @@ jobs: ci: runs-on: ubuntu-latest # Bespoke runner image (Ubuntu 24.04 + make + git + node + go via - # actions/setup-go). See git.librete.ch/libretech/runner-image. + # actions/setup-go). See git.librete.ch/public/runner-image. container: - image: git.librete.ch/libretech/runner-image:v2 + image: git.librete.ch/public/runner-image:v2 timeout-minutes: 5 steps: - name: Checkout diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 1592cd2..934124f 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -34,7 +34,7 @@ jobs: # + perl + ssh, runner user pre-joined to docker gid 998 so the # auto-mounted /var/run/docker.sock is writable without --user root. container: - image: git.librete.ch/libretech/runner-image:v2 + image: git.librete.ch/public/runner-image:v2 timeout-minutes: 20 if: ${{ vars.DEPLOY_ENABLED == 'true' }} steps: diff --git a/docs/operations.md b/docs/operations.md index 4071c1e..75ccfff 100644 --- a/docs/operations.md +++ b/docs/operations.md @@ -70,7 +70,7 @@ docker compose -f compose.yaml -f compose.netcup.yaml up -d Workflows run on the netcup `act_runner` (see `runner/` stack in the netcup umbrella). Both `ci.yml` and `deploy.yml` declare -`container: image: git.librete.ch/libretech/runner-image:v1` — +`container: image: git.librete.ch/public/runner-image:v1` — a bespoke Ubuntu 24.04 image (built and signed by us, hosted on the same Gitea instance) that bundles `git`, `make`, `node`, `perl`, `ssh`, and a docker CLI. The image's `runner` user is -- 2.36.6 From c9470d199f9f07bccaa5499b403e678b492abd2e Mon Sep 17 00:00:00 2001 From: Michael Czechowski Date: Thu, 30 Apr 2026 12:17:34 +0200 Subject: [PATCH 3/5] ci: digest-pin runner-image v0.1.0 (was :v2) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Drops the ad-hoc :vN tag scheme — see runner-image#semver. Consumers now reference tag + digest so the resolved image is byte-identical across runs. --- .gitea/workflows/ci.yml | 2 +- .gitea/workflows/deploy.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index c98eec1..25024c2 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -12,7 +12,7 @@ jobs: # Bespoke runner image (Ubuntu 24.04 + make + git + node + go via # actions/setup-go). See git.librete.ch/public/runner-image. container: - image: git.librete.ch/public/runner-image:v2 + image: git.librete.ch/public/runner-image:v0.1.0:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 timeout-minutes: 5 steps: - name: Checkout diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 934124f..f1e7db9 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -34,7 +34,7 @@ jobs: # + perl + ssh, runner user pre-joined to docker gid 998 so the # auto-mounted /var/run/docker.sock is writable without --user root. container: - image: git.librete.ch/public/runner-image:v2 + image: git.librete.ch/public/runner-image:v0.1.0:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 timeout-minutes: 20 if: ${{ vars.DEPLOY_ENABLED == 'true' }} steps: -- 2.36.6 From d34df180fd31e9a939d1cb9a8145c20de8000473 Mon Sep 17 00:00:00 2001 From: Michael Czechowski Date: Thu, 30 Apr 2026 12:20:19 +0200 Subject: [PATCH 4/5] fix(ci): correct image digest separator (@ not :) --- .gitea/workflows/ci.yml | 2 +- .gitea/workflows/deploy.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 25024c2..70b0068 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -12,7 +12,7 @@ jobs: # Bespoke runner image (Ubuntu 24.04 + make + git + node + go via # actions/setup-go). See git.librete.ch/public/runner-image. container: - image: git.librete.ch/public/runner-image:v0.1.0:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 + image: git.librete.ch/public/runner-image:v0.1.0@sha256:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 timeout-minutes: 5 steps: - name: Checkout diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index f1e7db9..c3a0bc4 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -34,7 +34,7 @@ jobs: # + perl + ssh, runner user pre-joined to docker gid 998 so the # auto-mounted /var/run/docker.sock is writable without --user root. container: - image: git.librete.ch/public/runner-image:v0.1.0:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 + image: git.librete.ch/public/runner-image:v0.1.0@sha256:9d1e204fe8e06b7d16cdc8da0c7077fa4171daef62099cc8c09993834e576ca5 timeout-minutes: 20 if: ${{ vars.DEPLOY_ENABLED == 'true' }} steps: -- 2.36.6