apps/forgejo/resources/runners/act-runner-arm64.yaml
Peter Kurfer 25b8a13e14
Some checks are pending
Renovate / renovate (push) Waiting to run
feat(dind): configure Docker daemon
2024-05-12 12:25:19 +02:00

139 lines
No EOL
4.3 KiB
YAML

---
apiVersion: apps/v1
kind: Deployment
metadata:
name: act-runner-arm64
spec:
selector:
matchLabels:
app.kubernetes.io/name: act-runner
app.kubernetes.io/instance: arm64
replicas: 2
strategy:
type: Recreate
template:
metadata:
labels:
app.kubernetes.io/name: act-runner
app.kubernetes.io/instance: arm64
spec:
restartPolicy: Always
# Initialise our configuration file using offline registration
# https://forgejo.org/docs/v1.21/admin/actions/#offline-registration
initContainers:
- name: runner-register
image: act_runner
command: ["forgejo-runner"]
args:
- "register"
- "--no-interactive"
- "--token"
- $(RUNNER_SECRET)
- "--name"
- $(RUNNER_NAME)
- "--instance"
- $(FORGEJO_INSTANCE_URL)
- "--labels"
- "docker:docker://code.icb4dc0.de/infrastructure/images/act_runtime:arm64,ubuntu-latest:docker://code.icb4dc0.de/infrastructure/images/act_runtime:arm64,ubuntu-22.04:docker://code.icb4dc0.de/infrastructure/images/act_runtime:arm64,ubuntu-20.04:docker://code.icb4dc0.de/infrastructure/images/act_runtime:20.04-arm64"
env:
- name: RUNNER_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: RUNNER_SECRET
valueFrom:
secretKeyRef:
name: forgejo-runner-secret
key: token
- name: FORGEJO_INSTANCE_URL
value: http://forgejo-http.forgejo.svc.cluster.local:3000
resources:
limits:
cpu: "0.50"
memory: "64Mi"
volumeMounts:
- name: runner-data
mountPath: /data
containers:
- name: runner
image: act_runner
imagePullPolicy: Always
command: ["sh", "-c", "while ! nc -z localhost 2376 </dev/null; do echo 'waiting for docker daemon...'; sleep 5; done; forgejo-runner daemon --config /etc/act/config.yaml"]
env:
- name: DOCKER_HOST
value: tcp://localhost:2376
- name: DOCKER_CERT_PATH
value: /certs/client
- name: DOCKER_TLS_VERIFY
value: "1"
volumeMounts:
- name: runner-data
mountPath: /data
- name: docker-certs
mountPath: /certs
- name: runner-config
mountPath: /etc/act
securityContext:
privileged: true
resources:
requests:
memory: "384Mi"
cpu: "500m"
limits:
memory: "768Mi"
cpu: "1500m"
- name: daemon
image: dind
env:
- name: DOCKER_TLS_CERTDIR
value: /certs
securityContext:
privileged: true
volumeMounts:
- name: docker-certs
mountPath: /certs
- name: runner-data
mountPath: /data
- name: docker-config
mountPath: /etc/docker
resources:
requests:
memory: "256Mi"
cpu: "200m"
limits:
memory: "768Mi"
cpu: "500m"
securityContext:
fsGroup: 1000
nodeSelector:
kubernetes.io/arch: arm64
affinity:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- topologyKey: kubernetes.io/hostname
labelSelector:
matchExpressions:
- key: app.kubernetes.io/name
operator: In
values:
- act-runner
volumes:
- name: runner-data
emptyDir:
sizeLimit: 500Mi
- name: docker-certs
emptyDir:
sizeLimit: 5Mi
- name: runner-config
configMap:
name: act-runner-config-arm64
items:
- key: config.yaml
path: config.yaml
- name: docker-config
configMap:
name: act-runner-config-arm64
items:
- key: daemon.json
path: daemon.json