Adding gitea act_runner roles
This commit is contained in:
@@ -209,6 +209,55 @@ With the alias in place you can use the shorter SCP-like URL:
|
||||
git clone git@gitea.ladkau.de:<username>/myrepo.git
|
||||
```
|
||||
|
||||
### 3.4 Deploy Gitea Actions runners
|
||||
|
||||
Three `act_runner` containers (Docker executor) are provisioned by the
|
||||
`act_runner` Ansible role. Each runner handles one concurrent job; together
|
||||
they allow up to three parallel workflow jobs.
|
||||
|
||||
**This step requires Gitea to be running and the admin account to exist
|
||||
(step 3.1). Runners cannot register until a token is obtained from Gitea.**
|
||||
|
||||
**Step 1 — Get a runner registration token**
|
||||
|
||||
1. Go to `https://gitea.ladkau.de` → sign in as admin.
|
||||
2. Navigate to **Site Administration** (top-right menu) →
|
||||
**Actions** → **Runners**.
|
||||
3. Click **Create runner token** and copy the token.
|
||||
|
||||
**Step 2 — Add the token to the vault**
|
||||
|
||||
```bash
|
||||
ansible-vault edit ansible/group_vars/all/vault.yml
|
||||
```
|
||||
|
||||
Add the key:
|
||||
|
||||
```yaml
|
||||
gitea_runner_registration_token: "<token-from-step-1>"
|
||||
```
|
||||
|
||||
**Step 3 — Deploy the runners**
|
||||
|
||||
```bash
|
||||
ansible-playbook -i ansible/inventory.ini ansible/site.yml \
|
||||
--tags act_runner --ask-vault-pass
|
||||
```
|
||||
|
||||
Ansible creates `/opt/act_runner/` with a shared `config.yml` and three
|
||||
per-runner data directories (`runner-1/`, `runner-2/`, `runner-3/`). On first
|
||||
start each container auto-registers with Gitea and writes a `.runner` file to
|
||||
its data directory. Subsequent restarts reuse the saved registration.
|
||||
|
||||
**Verify**
|
||||
|
||||
Back in Gitea **Site Administration → Actions → Runners**, all three runners
|
||||
should appear as **Online** within a few seconds.
|
||||
|
||||
> **Security note:** Each runner container mounts `/var/run/docker.sock`.
|
||||
> This gives workflow jobs root-equivalent access to the host Docker daemon.
|
||||
> Only run workflows from trusted repositories.
|
||||
|
||||
## 4. Nextcloud
|
||||
|
||||
The admin credentials are set via `nextcloud_admin_user` and
|
||||
|
||||
@@ -121,6 +121,10 @@ registry_users:
|
||||
- username: alice
|
||||
password: "your-password"
|
||||
|
||||
# Gitea Actions runners — token obtained after Gitea is running
|
||||
# See step 3.4 of runbook-configuration.md; replace after Gitea admin account is created
|
||||
gitea_runner_registration_token: "placeholder"
|
||||
|
||||
# Vaultwarden password vault
|
||||
vaultwarden_admin_token: "" # generate: openssl rand -hex 32
|
||||
# vaultwarden_sso_client_secret is added after Keycloak is configured — see
|
||||
@@ -203,20 +207,28 @@ ansible-playbook -i ansible/inventory.ini ansible/site.yml --ask-vault-pass
|
||||
|
||||
This runs all roles in order:
|
||||
|
||||
| # | Role | What it does |
|
||||
|---|------------|--------------|
|
||||
| 1 | `base` | OS hardening, deploy user, SSH config, ufw firewall, fail2ban |
|
||||
| 2 | `docker` | Docker Engine + Compose plugin, shared Traefik network |
|
||||
| 3 | `traefik` | Reverse proxy, automatic TLS via Let's Encrypt |
|
||||
| 4 | `gitea` | Self-hosted Git with PostgreSQL |
|
||||
| 5 | `nextcloud`| File storage with PostgreSQL, Redis, cron sidecar |
|
||||
| 6 | `sso` | Keycloak single sign-on with PostgreSQL |
|
||||
| 7 | `mail` | Roundcube webmail client with PostgreSQL |
|
||||
| 8 | `registry` | Docker Registry v2 with htpasswd auth |
|
||||
| 9 | `k8s` | Placeholder page at k8s.ladkau.de |
|
||||
| 10 | `vaultwarden` | Vaultwarden password vault at vault.ladkau.de |
|
||||
| 11 | `dl` | Public download server at dl.ladkau.de — nginx HTTPS + SFTP upload |
|
||||
| 12 | `dashboard` | Public status dashboard at cloud.ladkau.de — service health and server stats |
|
||||
| # | Role | What it does |
|
||||
|----|---------------|--------------|
|
||||
| 1 | `base` | OS hardening, deploy user, SSH config, ufw firewall, fail2ban |
|
||||
| 2 | `docker` | Docker Engine + Compose plugin, shared Traefik network |
|
||||
| 3 | `traefik` | Reverse proxy, automatic TLS via Let's Encrypt |
|
||||
| 4 | `gitea` | Self-hosted Git with PostgreSQL |
|
||||
| 5 | `act_runner` | Three Gitea Actions runners with Docker executor |
|
||||
| 6 | `nextcloud` | File storage with PostgreSQL, Redis, cron sidecar |
|
||||
| 7 | `sso` | Keycloak single sign-on with PostgreSQL |
|
||||
| 8 | `mail` | Roundcube webmail client with PostgreSQL |
|
||||
| 9 | `registry` | Docker Registry v2 with htpasswd auth |
|
||||
| 10 | `k8s` | Placeholder page at k8s.ladkau.de |
|
||||
| 11 | `vaultwarden` | Vaultwarden password vault at vault.ladkau.de |
|
||||
| 12 | `dl` | Public download server at dl.ladkau.de — nginx HTTPS + SFTP upload |
|
||||
| 13 | `dashboard` | Public status dashboard at cloud.ladkau.de — service health and server stats |
|
||||
|
||||
> **Note:** The `act_runner` role requires `gitea_runner_registration_token` in the
|
||||
> vault, which can only be obtained after Gitea is running and an admin account has
|
||||
> been created. On a fresh provisioning run the role will fail if the token is
|
||||
> absent. Either add a placeholder and redeploy with `--tags act_runner` after
|
||||
> Gitea is configured (see step 3.4 of `runbook-configuration.md`), or skip the
|
||||
> role on first run: `--skip-tags act_runner`.
|
||||
|
||||
To apply a single role:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user