The builder image is now multi-arch (linux/amd64 + linux/arm64, pushed as srfplay-builder:latest after building all three plugin zips in each variant), so jobs no longer need an amd64 host. runs-on moves from linux/amd64 to ubuntu-latest, which draco-x86, freebox and oracle-a1 all carry, so a job no longer waits behind long jobs on draco while the ARM runners sit idle. .gitea/runner/cloud-init.yaml sets up such a runner on an Oracle Cloud Always Free Ampere VM (Ubuntu 24.04): Docker, act_runner registered instance-wide with the instance's label set, and a weekly image prune. The registration token and the optional console password hash are placeholders here and must be filled in locally before use. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
59 lines
2.6 KiB
YAML
59 lines
2.6 KiB
YAML
#cloud-config
|
|
# Gitea Actions runner on an Oracle Cloud Always Free Ampere (ARM) VM, shared by
|
|
# every repo on the instance.
|
|
#
|
|
# Paste this into "Advanced options -> Management -> Initialization script" when
|
|
# creating the instance (image: Canonical Ubuntu 24.04, shape: VM.Standard.A1.Flex).
|
|
# Before pasting, replace REGISTRATION_TOKEN below with an instance-wide token:
|
|
# Site Administration -> Actions -> Runners -> Create new runner
|
|
# (a token from repo Settings would limit the runner to that one repo).
|
|
#
|
|
# The runner only makes outbound connections (to Gitea and container registries),
|
|
# so the VM needs no inbound ports beyond SSH.
|
|
#
|
|
# Labels follow the instance convention (same set as the freebox ARM runner).
|
|
# ubuntu-latest / ubuntu-22.04 are shared with the amd64 runner, so a job asking
|
|
# for them may land on either architecture; ask for linux/arm64 or linux/amd64
|
|
# when a job needs a specific one. SRF Play jobs run in the multi-arch
|
|
# srfplay-builder image, so they work on both.
|
|
|
|
# Optional: a password for the "ubuntu" user, so you can log in through the Oracle
|
|
# serial console ("Launch Cloud Shell connection") without an SSH key. Generate the
|
|
# hash locally with: openssl passwd -6
|
|
# then uncomment and paste it in. SSH still only accepts keys.
|
|
#chpasswd:
|
|
# expire: false
|
|
# users:
|
|
# - name: ubuntu
|
|
# password: "$6$...paste the hash here..."
|
|
|
|
package_update: true
|
|
packages:
|
|
- docker.io
|
|
- docker-compose-v2
|
|
|
|
write_files:
|
|
- path: /opt/act_runner/docker-compose.yml
|
|
permissions: "0600"
|
|
content: |
|
|
services:
|
|
runner:
|
|
image: gitea/act_runner:latest
|
|
restart: unless-stopped
|
|
environment:
|
|
GITEA_INSTANCE_URL: https://gitea.tourolle.paris
|
|
GITEA_RUNNER_REGISTRATION_TOKEN: REGISTRATION_TOKEN
|
|
GITEA_RUNNER_NAME: oracle-a1
|
|
# Comma-separated with no spaces: label:docker://<default job image>
|
|
GITEA_RUNNER_LABELS: "ubuntu-latest:docker://gitea/runner-images:ubuntu-latest,ubuntu-22.04:docker://gitea/runner-images:ubuntu-22.04,linux-arm64:docker://gitea/runner-images:ubuntu-latest,self-hosted:docker://gitea/runner-images:ubuntu-latest,linux/arm64:docker://gitea/runner-images:ubuntu-latest"
|
|
volumes:
|
|
# Registration is stored here, so the token is only used once.
|
|
- ./data:/data
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
|
|
runcmd:
|
|
- systemctl enable --now docker
|
|
- cd /opt/act_runner && docker compose up -d
|
|
# Weekly clean-up so pulled images and build caches do not fill the boot volume.
|
|
- echo '0 4 * * 0 root docker system prune -af --filter "until=168h" >/dev/null 2>&1' > /etc/cron.d/docker-prune
|