Compare commits

..
Author SHA1 Message Date
grm-ci-bot d102453960 release: v0.18.8 [skip ci] 2026-08-06 19:16:18 +00:00
kireto 42409d9e47 GRM-160: fix: pin containerd.io to compatible version for Docker 28.x
Post-merge / detect-and-configure (push) Successful in 3m19s
Post-merge / release-and-maintain (push) Successful in 1m19s
Co-authored-by: kireto <kireto@oblachno.com>
2026-08-06 19:12:07 +00:00
gitea-actions-bot 91e880f05c chore: update badge URLs to commit 7b6c9f92 [skip ci] 2026-08-06 09:31:04 +00:00
grm-ci-bot 2d2eaa3291 release: v0.18.7 [skip ci] 2026-08-06 09:30:18 +00:00
kireto 8176a62885 GRM-159: fix: move StartLimit to [Unit] and make prune timer reload conditional
Post-merge / detect-and-configure (push) Successful in 3m49s
Post-merge / release-and-maintain (push) Successful in 3m43s
Co-authored-by: kireto <kireto@oblachno.com>
2026-08-06 09:23:29 +00:00
gitea-actions-bot 443756a508 chore: update badge URLs to commit 36201d0d [skip ci] 2026-08-06 00:00:05 +00:00
grm-ci-bot 340222e041 release: v0.18.6 [skip ci] 2026-08-05 23:59:22 +00:00
kireto 179e47bbb2 GRM-158: fix: pre-configure daemon.json before rootless setuptool + add DBUS_SESSION_BUS_ADDRESS
Post-merge / detect-and-configure (push) Successful in 1m2s
Post-merge / release-and-maintain (push) Successful in 1m38s
Co-authored-by: kireto <kireto@oblachno.com>
2026-08-05 23:57:25 +00:00
gitea-actions-bot 68d16577b3 chore: update badge URLs to commit 169df915 [skip ci] 2026-08-05 20:21:20 +00:00
grm-ci-bot 38607d9f29 release: v0.18.5 [skip ci] 2026-08-05 20:20:43 +00:00
kireto 90139b306b GRM-157: fix: pin Docker 28.x + disable containerd snapshotter + tune prune/disk
Post-merge / detect-and-configure (push) Successful in 1m8s
Post-merge / release-and-maintain (push) Successful in 1m31s
Co-authored-by: kireto <kireto@oblachno.com>
2026-08-05 20:18:38 +00:00
gitea-actions-bot dd475bec0d chore: update badge URLs to commit 83a5b577 [skip ci] 2026-08-05 13:53:01 +00:00
grm-ci-bot 0f0ada3576 release: v0.18.4 [skip ci] 2026-08-05 13:52:28 +00:00
emo 185e41c49e GRM-156: fix: harden rootless Docker daemon resilience on CI runners
Post-merge / detect-and-configure (push) Successful in 1m9s
Post-merge / release-and-maintain (push) Successful in 1m15s
2026-08-05 13:50:34 +00:00
gitea-actions-bot 103741b3ab chore: update badge URLs to commit 7136903b [skip ci] 2026-08-04 14:04:34 +00:00
grm-ci-bot b770d1debf release: v0.18.3 [skip ci] 2026-08-04 14:03:59 +00:00
gitea-admin 2f11489be0 GRM-2: fix: switch default network driver to slirp4netns (pasta TCP RST bug)
Post-merge / detect-and-configure (push) Successful in 1m8s
Post-merge / release-and-maintain (push) Successful in 1m22s
Co-authored-by: oblachno Admin <admin@oblachno.oblachno.fyi>
2026-08-04 14:01:56 +00:00
36 changed files with 311 additions and 1311 deletions
-47
View File
@@ -1,47 +0,0 @@
name: 'Notify on failure'
description: 'Create a Gitea issue when a CI workflow fails (calls devx.ci.notify_failure)'
# Composite action for the common "Notify on failure" step pattern.
# Replaces the repeated inline:
# - name: Notify on failure
# if: failure()
# env:
# CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
# run: |
# . .venv/bin/activate 2>/dev/null || true
# export PATH="$HOME/.local/bin:$PATH"
# python3 -m devx.ci.notify_failure \
# --repo "${{ github.repository }}" \
# --run-id "${{ github.run_id }}" \
# --workflow "ci/validate" \
# --commit "${{ github.sha }}" \
# --auto-login
#
# Gitea 1.27 notes:
# - `if: failure()` is evaluated in the calling workflow's context and
# propagates correctly to composite action steps.
# - `secrets` are not accessible here; the calling workflow's top-level
# `env:` CI_GITEA_API_TOKEN is used via `${{ env.* }}`.
inputs:
workflow:
description: 'Workflow/job name used in the Gitea issue title (e.g., ci/validate)'
required: true
runs:
using: 'composite'
steps:
- name: Notify on failure
if: failure()
shell: bash
env:
CI_GITEA_API_TOKEN: ${{ env.CI_GITEA_API_TOKEN }}
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
python3 -m devx.ci.notify_failure \
--repo "${{ github.repository }}" \
--run-id "${{ github.run_id }}" \
--workflow "${{ inputs.workflow }}" \
--commit "${{ github.sha }}" \
--auto-login
-89
View File
@@ -1,89 +0,0 @@
name: 'Quality checks'
description: 'Run lint, unit tests with coverage, test speed, docs, translations, and security scan'
# Composite action for the 6-step quality check sequence used by the
# devx validate job. Replaces the inline block:
# - Lint all
# - Unit tests with 100% coverage
# - Check unit test speed
# - Documentation gate (coverage + stale refs + lint + version refs + prose)
# - Translation completeness check
# - Dependency security scan
#
# Each step activates the venv defensively (`. .venv/bin/activate 2>/dev/null
# || true`) so the action works whether or not the setup step created a
# venv at the repo root (pre-built CI images symlink /opt/venv to .venv).
#
# Gitea 1.27 notes:
# - Every `run` step needs explicit `shell:`.
# - Inputs are string-typed; numeric thresholds are passed through as
# strings to `devx.tools.check_test_speed`.
inputs:
package:
description: 'Package name for doc version checks (e.g., devx, grm). Empty = no DEVX_DOC_VERSIONS_PKG override.'
required: false
default: ''
test-speed-max:
description: 'Max total test seconds (passed to check_test_speed --max-seconds)'
required: false
default: '15'
test-speed-max-single:
description: 'Max single test seconds (passed to check_test_speed --max-single-seconds)'
required: false
default: '0.5'
translations-file:
description: 'Path to translations.json (empty = default location src/devx/translations.json)'
required: false
default: ''
runs:
using: 'composite'
steps:
- name: Lint all
shell: bash
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
make lint-all
- name: Unit tests with 100% coverage
shell: bash
run: |
. .venv/bin/activate 2>/dev/null || true
make pytest-cov
- name: Check unit test speed
shell: bash
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.tools.check_test_speed \
--max-seconds "${{ inputs.test-speed-max }}" \
--max-single-seconds "${{ inputs.test-speed-max-single }}"
- name: Documentation gate (coverage + stale refs + lint + version refs + prose)
shell: bash
env:
DEVX_DOC_COVERAGE_STRICT: "1"
DEVX_VALE_LEVEL: warning
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
if [ -n "${{ inputs.package }}" ]; then
export DEVX_DOC_VERSIONS_PKG="${{ inputs.package }}"
fi
make devx-docs-check
- name: Translation completeness check
shell: bash
run: |
. .venv/bin/activate 2>/dev/null || true
if [ -n "${{ inputs.translations-file }}" ]; then
python3 -m devx.ci.check_translations --translations "${{ inputs.translations-file }}"
else
python3 -m devx.ci.check_translations
fi
- name: Dependency security scan
shell: bash
run: |
. .venv/bin/activate 2>/dev/null || true
# Install pip in venv if missing (needed by pip-audit)
.venv/bin/python -m ensurepip 2>/dev/null || true
PIPAPI_PYTHON_LOCATION=$PWD/.venv/bin/python \
pip-audit --desc --skip-editable 2>&1 || true
-37
View File
@@ -1,37 +0,0 @@
name: 'Set up environment'
description: 'Set up CI environment with venv and PATH (calls make setup-image)'
# Composite action for the common "Set up environment" step pattern.
# Replaces the repeated inline:
# - name: Set up environment
# env:
# CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
# run: make setup-image
#
# Gitea 1.27 notes:
# - Every `run` step needs explicit `shell:`.
# - Composite actions cannot access `secrets` directly; they read from
# the `env:` context which the calling workflow must populate.
# - The calling workflow's top-level `env:` block (CI_GITEA_API_TOKEN,
# CI_GITEA_USERNAME) is visible here via `${{ env.* }}`.
inputs:
extras:
description: 'Extra pip install groups passed to make setup-image (e.g., ci,lint,release)'
required: false
default: ''
runs:
using: 'composite'
steps:
- name: Set up environment
shell: bash
env:
CI_GITEA_API_TOKEN: ${{ env.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ env.CI_GITEA_USERNAME }}
run: |
if [ -n "${{ inputs.extras }}" ]; then
make setup-image EXTRAS="${{ inputs.extras }}"
else
make setup-image
fi
+78 -93
View File
@@ -18,11 +18,7 @@ jobs:
# Saves ~5x checkout+setup overhead vs 6 separate jobs.
validate:
runs-on: docker
container:
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
credentials:
username: ${{ vars.CI_GITEA_USERNAME }}
password: ${{ secrets.CI_GITEA_API_TOKEN }}
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
timeout-minutes: 15
defaults:
run:
@@ -36,14 +32,45 @@ jobs:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: ./.gitea/actions/setup-env
with:
extras: "ci,lint"
- uses: ./.gitea/actions/quality-checks
with:
package: grm
test-speed-max: "4"
translations-file: src/grm/translations.json
- name: Set up environment
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
run: make setup-image EXTRAS=ci,lint
# --- quality steps ---
- name: Lint all
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
make lint-all
- name: Unit tests with 100% coverage
run: |
. .venv/bin/activate 2>/dev/null || true
make pytest-cov
- name: Documentation gate (coverage + stale refs + lint + version refs + prose)
env:
DEVX_DOC_COVERAGE_STRICT: "1"
DEVX_DOC_VERSIONS_PKG: grm
DEVX_VALE_LEVEL: warning
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
make devx-docs-check
- name: Translation completeness check
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.ci.check_translations --translations src/grm/translations.json
- name: Check unit test speed
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.tools.check_test_speed --max-seconds 4 --max-single-seconds 0.5
- name: Dependency security scan
run: |
. .venv/bin/activate 2>/dev/null || true
# Install pip in venv if missing (needed by pip-audit)
.venv/bin/python -m ensurepip 2>/dev/null || true
PIPAPI_PYTHON_LOCATION=$PWD/.venv/bin/python \
pip-audit --desc --skip-editable 2>&1 || true
- name: Workflow dry-run validation
run: |
. .venv/bin/activate 2>/dev/null || true
@@ -113,25 +140,30 @@ jobs:
--owner "${{ github.repository_owner }}" \
--repo "${{ github.event.repository.name }}" \
--github-output
- uses: ./.gitea/actions/notify-failure
with:
workflow: "ci/validate"
- name: Notify on failure
if: failure()
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
python3 -m devx.ci.notify_failure --auto-login \
--repo "${{ github.repository }}" \
--run-id "${{ github.run_id }}" \
--workflow "ci/validate" \
--commit "${{ github.sha }}"
molecule-tests:
needs: [validate]
if: needs.validate.outputs.ansible-changed == 'true'
runs-on: docker
container:
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
credentials:
username: ${{ vars.CI_GITEA_USERNAME }}
password: ${{ secrets.CI_GITEA_API_TOKEN }}
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
timeout-minutes: 15
strategy:
fail-fast: false
max-parallel: 4
fail-fast: true
max-parallel: 6
matrix:
runner-index: [1, 2, 3, 4]
runner-index: [1, 2, 3, 4, 5, 6]
steps:
- uses: actions/checkout@v4
- name: Set up environment
@@ -146,34 +178,25 @@ jobs:
- name: Discover assigned test pairs
env:
RUNNER_INDEX: ${{ matrix.runner-index }}
MAX_RUNNERS: 4
MAX_RUNNERS: 6
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.molecule.distribute_molecule \
--runner-index "$RUNNER_INDEX" \
--max-runners "$MAX_RUNNERS" \
--github-env
- name: Prune stale Docker data
id: prune
if: env.SKIP != 'true'
run: |
docker system prune -af --volumes 2>/dev/null || true
disk_pct=$(df -P / | awk 'NR==2 {gsub(/%/, "", $5); print $5}')
echo "Disk usage after prune: ${disk_pct}%"
if [ "$disk_pct" -ge 85 ]; then
echo "should-run=false" >> "$GITHUB_OUTPUT"
echo "::warning::Disk usage at ${disk_pct}% after prune — skipping molecule tests to avoid ENOSPC failures"
else
echo "should-run=true" >> "$GITHUB_OUTPUT"
fi
- name: Run molecule tests
if: env.SKIP != 'true' && steps.prune.outputs.should-run != 'false'
shell: bash
if: env.SKIP != 'true'
env:
GITEA_URL: ${{ github.server_url }}
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
DOCKER_HOST: unix:///var/run/docker.sock
RUN_ID: ${{ github.run_id }}
ANSIBLE_INJECT_INVOCATION: "1"
JOB_NAME: ${{ github.job }}
MATRIX_INDEX: ${{ matrix.runner-index }}
GITEA_REPOSITORY: ${{ github.repository }}
DOCKER_HOST: unix:///var/run/docker.sock
run: |
. .venv/bin/activate 2>/dev/null || true
if [ -z "$TEST_PAIRS" ]; then exit 0; fi
@@ -184,61 +207,21 @@ jobs:
_TOKEN="$CI_GITEA_API_TOKEN"; [ -z "$_TOKEN" ] && _TOKEN="$CI_GITEA_TOKEN"
[ -z "$_TOKEN" ] && { echo "Gitea API token not set — skipping Docker login"; exit 0; }
echo "$_TOKEN" | docker login git.oblachno.oblachno.fyi -u "$CI_GITEA_USERNAME" --password-stdin
# Run each molecule test pair sequentially.
# Pairs are 4-part: scenario|platform_name|platform_image|platform_command
# Spaces in platform_command are encoded as __SPACE__.
role_dir="ansible/roles/gitea_runner"
# shellcheck disable=SC2086 # intentional word splitting for pair list
for pair in $TEST_PAIRS; do
IFS='|' read -r scenario platform_name platform_image platform_command <<< "$pair"
platform_command="${platform_command//__SPACE__/ }"
export MOLECULE_PLATFORM_NAME="$platform_name"
export MOLECULE_PLATFORM_IMAGE="$platform_image"
if [ -n "$platform_command" ]; then
export MOLECULE_PLATFORM_COMMAND="$platform_command"
else
unset MOLECULE_PLATFORM_COMMAND
fi
export ANSIBLE_ALLOW_BROKEN_CONDITIONALS=true
echo "--- Running: $scenario on $platform_name ---"
pushd "$role_dir" >/dev/null
if [ "$scenario" = "default" ]; then
molecule test || {
echo "FAILED: $pair — running molecule destroy"
molecule destroy 2>/dev/null || true
popd >/dev/null
exit 1
}
else
molecule test -s "$scenario" || {
echo "FAILED: $pair — running molecule destroy"
molecule destroy -s "$scenario" 2>/dev/null || true
popd >/dev/null
exit 1
}
fi
popd >/dev/null
echo "PASSED: $pair"
docker system prune -af --volumes 2>/dev/null || true
done
echo "All molecule tests passed."
# shellcheck disable=SC2086 # intentional word splitting for argument expansion
python3 -m devx.molecule.molecule_ci_guard $TEST_PAIRS
auto-merge:
# Auto-merge runs after validate passes. molecule-tests is NOT in needs
# because Gitea Actions skips dependent jobs of skipped jobs without
# evaluating if: conditions — having molecule-tests in needs would
# cascade the skip to auto-merge when ansible-changed=false.
needs: [validate]
# Auto-merge runs after validate + molecule-tests pass (or molecule is skipped).
# Uses always() so it evaluates even when molecule-tests is skipped
# (Gitea Actions skips dependent jobs of skipped jobs by default).
needs: [validate, molecule-tests]
if: >-
always() &&
github.event_name == 'pull_request' &&
needs.validate.result == 'success'
needs.validate.result == 'success' &&
(needs.molecule-tests.result == 'success' || needs.molecule-tests.result == 'skipped')
runs-on: docker
container:
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
credentials:
username: ${{ vars.CI_GITEA_USERNAME }}
password: ${{ secrets.CI_GITEA_API_TOKEN }}
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
timeout-minutes: 10
defaults:
run:
@@ -248,9 +231,11 @@ jobs:
with:
fetch-depth: 0
token: ${{ secrets.CI_GITEA_API_TOKEN }}
- uses: ./.gitea/actions/setup-env
with:
extras: "ci"
- name: Set up environment
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
run: make setup-image EXTRAS=ci
- name: Post approval review
env:
REVIEWER_GITEA_API_TOKEN: ${{ secrets.REVIEWER_GITEA_API_TOKEN }}
+35 -25
View File
@@ -36,11 +36,7 @@ env:
jobs:
detect-and-configure:
runs-on: docker
container:
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
credentials:
username: ${{ vars.CI_GITEA_USERNAME }}
password: ${{ secrets.CI_GITEA_API_TOKEN }}
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
timeout-minutes: 10
defaults:
run:
@@ -53,9 +49,11 @@ jobs:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: ./.gitea/actions/setup-env
with:
extras: "ci"
- name: Set up environment
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
run: make setup-image EXTRAS=ci
- name: Ensure branch protection and labels
env:
DEVX_REPO_NAME: grm
@@ -89,19 +87,24 @@ jobs:
--base "HEAD~1" \
--head "HEAD" \
--github-output
- uses: ./.gitea/actions/notify-failure
with:
workflow: "post-merge/detect-and-configure"
- name: Notify on failure
if: failure()
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
python3 -m devx.ci.notify_failure --auto-login \
--repo "${{ github.repository }}" \
--run-id "${{ github.run_id }}" \
--workflow "post-merge/detect-and-configure" \
--commit "${{ github.sha }}"
release-and-maintain:
needs: [detect-and-configure]
if: always() && needs.detect-and-configure.result == 'success'
runs-on: docker
container:
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
credentials:
username: ${{ vars.CI_GITEA_USERNAME }}
password: ${{ secrets.CI_GITEA_API_TOKEN }}
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
timeout-minutes: 15
outputs:
tag: ${{ steps.release-tag.outputs.tag }}
@@ -114,22 +117,20 @@ jobs:
fetch-depth: 0
ref: master
token: ${{ secrets.CI_GITEA_API_TOKEN }}
- uses: ./.gitea/actions/setup-env
with:
extras: "ci,lint"
- name: Configure git
- name: Set up environment
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
run: make setup-image EXTRAS=ci,lint
- name: Configure git
run: |
git config user.name "grm-ci-bot"
git config user.email "grm-ci-bot@oblachno.fyi"
git remote set-url origin "https://grm-ci-bot:${CI_GITEA_API_TOKEN}@git.oblachno.oblachno.fyi/oblachno-oss/grm.git"
# --- release + publish (only if not a release commit) ---
- name: Run release
id: release-tag
if: needs.detect-and-configure.outputs.is-release == 'false' && needs.detect-and-configure.outputs.user-facing-changed == 'true'
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
DEVX_VERSION_FILE: src/grm/__init__.py
DEVX_TASK_PREFIX: GRM
DEVX_VIKUNJA_PROJECT_ID: 6
@@ -176,6 +177,15 @@ jobs:
git fetch origin master
git reset --hard origin/master
python3 -m devx.ci.push_badges
- uses: ./.gitea/actions/notify-failure
with:
workflow: "post-merge/release-and-maintain"
- name: Notify on failure
if: failure()
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
python3 -m devx.ci.notify_failure --auto-login \
--repo "${{ github.repository }}" \
--run-id "${{ github.run_id }}" \
--workflow "post-merge/release-and-maintain" \
--commit "${{ github.sha }}"
-40
View File
@@ -96,43 +96,3 @@ repos:
types: [python]
pass_filenames: false
stages: [pre-push]
- id: check-ansible-no-log
name: ansible no_log on secret tasks
entry: make check-ansible-no-log
language: system
files: ^ansible/.*\.(yml|yaml)$
pass_filenames: false
stages: [pre-commit]
- id: check-ansible-no-state-absent-on-db
name: no state absent on DB paths
entry: make check-ansible-no-state-absent-on-db
language: system
files: ^ansible/.*\.(yml|yaml)$
pass_filenames: false
stages: [pre-commit]
- id: check-ansible-patterns
name: ansible failure-masking patterns
entry: make check-ansible-patterns
language: system
files: ^ansible/.*\.(yml|yaml)$
pass_filenames: false
stages: [pre-commit]
- id: check-jinja-expr
name: jinja2 expression validation
entry: make check-jinja-expr
language: system
files: ^ansible/.*\.(yml|yaml|j2)$
pass_filenames: false
stages: [pre-commit]
- id: check-ansible-set-fact-to-json
name: set_fact to_json misuse check
entry: make check-ansible-set-fact-to-json
language: system
files: ^ansible/.*\.(yml|yaml)$
pass_filenames: false
stages: [pre-commit]
+3 -3
View File
@@ -278,9 +278,9 @@ via `[tool.devx.classify]` in `pyproject.toml`.
- Any new file type not in the allowlist
**devx module structure** (installed from git, not in this repo):
- `devx.ci.*` — CI/CD automation (run by workflows): release, publish, auto_merge, classify_changes, detect_release_commit, push_badges, doc_coverage, sync_wiki, distribute_molecule, discover_runners, notify_failure, post_merge, pr_review, validate_commit_msg
- `devx.ci.*` — CI/CD automation (run by workflows): release, publish, auto_merge, classify_changes, detect_release_commit, push_badges, doc_coverage, sync_wiki, distribute_molecule, molecule_ci_guard, discover_runners, notify_failure, post_merge, pr_review, validate_commit_msg
- `devx.tools.*` — Dev tools (run locally): check_test_speed, configure_repo, install_checkmake, install_tools, setup, generate_badges, create_task, create_pr, pr_status, pr_logs, pr_label, rebase, pr_rebase
- `devx.molecule.*` — Molecule helpers: molecule_all, platforms, discover_runners, distribute_molecule
- `devx.molecule.*` — Molecule helpers: molecule_all, platforms, discover_runners, distribute_molecule, molecule_ci_guard
- `devx.gitea_cli` — Tea CLI wrapper
- `devx.i18n` — i18n translation system
- `devx.config` — Shared configuration (DEVX_* env vars)
@@ -348,7 +348,7 @@ Since devx is installed as a package (via `pip install` from git), it is importa
| PYTHONPATH | When to use | Example modules |
|------------|-------------|-----------------|
| `src` | Module imports from `grm` | `devx.ci.auto_merge`, `devx.ci.pr_review`, `devx.ci.pr_review`, `devx.ci.sync_wiki`, `devx.ci.post_merge`, `devx.ci.classify_changes`, `devx.molecule.discover_runners`, `devx.ci.doc_coverage` |
| (none) | Module has no GRM imports | `devx.ci.detect_release_commit`, `devx.molecule.distribute_molecule`, `devx.ci.push_badges`, `devx.ci.validate_commit_msg` |
| (none) | Module has no GRM imports | `devx.ci.detect_release_commit`, `devx.molecule.distribute_molecule`, `devx.molecule.molecule_ci_guard`, `devx.ci.push_badges`, `devx.ci.validate_commit_msg` |
**In workflows**, always use `env:` blocks (not inline `PYTHONPATH=value`):
```yaml
-37
View File
@@ -2,49 +2,12 @@
All notable changes to this project will be documented in this file.
## [Unreleased]
### CI
- Convert `ci.yml` and `post-merge.yml` to use composite actions
(`setup-env`, `quality-checks`, `notify-failure`) copied from devx,
reducing workflow duplication
### Bug Fixes
- Fix `register.yml` premature service start: removed step that ran
`systemctl --user start gitea-runner` before the systemd unit file was
created by `service.yml` (included after `register.yml`). First-time
installs were failing with "Unit gitea-runner.service not found".
- Fix `ci.yml` auto-merge IndentationError: replaced broken inline Python
polling script with `devx.ci.wait_for_checks` (the inline Python had
YAML run-block indentation leaking into `python3 -c` string).
### Dependencies
- Bump devx from v0.50.0 to v0.50.5 (adds `wait_for_checks` tool,
consolidated Ansible checks, tenacity retry in `install_tools`,
increased download retry attempts/backoff)
## [0.20.0] - 2026-08-09
### Features
- *(healthcheck)* Add two-tier disk prune with critical threshold
## [0.19.0] - 2026-08-08
### Features
- Use Gitea mirror for Ansible collection installs
## [0.18.8] - 2026-08-06
### Bug Fixes
- Pin containerd.io to compatible version for Docker 28.x
## [0.18.7] - 2026-08-06
### Bug Fixes
+1 -26
View File
@@ -175,36 +175,11 @@ makefile-lint:
echo "checkmake not found, skipping Makefile lint"; \
fi
lint-all: lint ansible-lint makefile-lint workflow-lint check-api-identity-checks check-ansible-no-log check-ansible-no-state-absent-on-db check-ansible-patterns check-jinja-expr check-ansible-set-fact-to-json
lint-all: lint ansible-lint makefile-lint workflow-lint check-api-identity-checks
check-api-identity-checks:
@$(BIN)/python -m devx.tools.check_api_identity_checks
check-ansible-no-log:
@echo "[check-ansible-no-log] Checking Ansible tasks for missing no_log on secret-handling tasks..."
@$(BIN)/python -m devx.tools.check_ansible_no_log
@echo "[check-ansible-no-log] Passed."
check-ansible-no-state-absent-on-db:
@echo "[check-ansible-no-state-absent-on-db] Checking for state: absent on DB data directories..."
@$(BIN)/python -m devx.tools.check_ansible_no_state_absent_on_db
@echo "[check-ansible-no-state-absent-on-db] Passed."
check-ansible-patterns:
@echo "[check-ansible-patterns] Checking for dangerous failure-masking patterns..."
@$(BIN)/python -m devx.tools.check_ansible_patterns
@echo "[check-ansible-patterns] Passed."
check-jinja-expr:
@echo "[check-jinja-expr] Validating Jinja2 expressions in Ansible files..."
@$(BIN)/python -m devx.tools.check_jinja_expr
@echo "[check-jinja-expr] Passed."
check-ansible-set-fact-to-json:
@echo "[check-ansible-set-fact-to-json] Checking set_fact tasks for to_json misuse..."
@$(BIN)/python -m devx.tools.check_ansible_set_fact_to_json
@echo "[check-ansible-set-fact-to-json] Passed."
test-integration:
$(BIN)/pytest tests/integration/ -v --no-cov
+6 -6
View File
@@ -8,12 +8,12 @@ Each runner runs in an isolated **rootless Docker** environment under a dedicate
[![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/src/branch/master/LICENSE)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/python.svg)](https://www.python.org/downloads/)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/python.svg)](https://www.python.org/downloads/)
## Why GRM?
+3 -7
View File
@@ -1,11 +1,7 @@
---
collections:
- name: community.general
type: url
source: https://git.oblachno.oblachno.fyi/api/packages/emil/generic/ansible-collections/13.1.0/community-general-13.1.0.tar.gz
version: "==13.1.0"
- name: ansible.posix
type: url
source: https://git.oblachno.oblachno.fyi/api/packages/emil/generic/ansible-collections/2.2.1/ansible-posix-2.2.1.tar.gz
version: "==2.2.1"
- name: community.docker
type: url
source: https://git.oblachno.oblachno.fyi/api/packages/emil/generic/ansible-collections/5.2.1/community-docker-5.2.1.tar.gz
version: "==5.2.1"
+4 -38
View File
@@ -3,13 +3,6 @@ gitea_runner_version: "2.0.1"
gitea_runner_labels: "docker,ubuntu-latest:docker://runner-images:ubuntu-26.04"
gitea_runner_skip_registration: false
# Force re-registration even if .runner file exists.
# Use this when Gitea no longer recognizes the runner (e.g., after a Gitea
# server restore/reinstall or when the runner record was deleted from the
# admin UI). The existing .runner file is removed and a new registration is
# performed. Requires registration_token.
gitea_runner_force_reregister: false
# Per-runner user (rootless isolation)
gitea_runner_user_prefix: "grm-"
gitea_runner_base_home: "/home"
@@ -36,37 +29,14 @@ gitea_runner_prune_label: "gitea-runner=true"
gitea_runner_service_restart_sec: "5"
# Health check configuration
# 2min interval — catches hung daemons before multiple CI jobs fail between
# checks. The 1min interval caused excessive pruning which removed cached
# images, forcing all 6 parallel slots to re-pull simultaneously and
# actually increasing disk pressure.
# 2min interval — catches hung daemons before multiple CI jobs fail between checks.
# The previous 5min interval was too coarse: a stuck daemon could fail 3+ molecule
# jobs in the window between healthcheck runs.
gitea_runner_healthcheck_interval: "2min"
gitea_runner_healthcheck_boot_delay: "2min"
gitea_runner_healthcheck_disk_threshold: 70
# When disk reaches this level, prune EVERYTHING (no until-filter) — the
# runner is dangerously full and the gentle until=1h prune isn't enough.
# This removes all stopped containers and unused images regardless of age.
# At 75%+, molecule containers fail with "container is not running" because
# overlay2 runs out of space under parallel DinD load.
# IMPORTANT: keep at 75 (not lower) — the host disk normally sits at ~74%.
# Lowering to 70 triggers full prune every cycle, wiping cached images and
# forcing all parallel slots to re-pull simultaneously, which increases
# disk pressure rather than reducing it.
gitea_runner_healthcheck_disk_critical: 75
gitea_runner_healthcheck_disk_threshold: 75
gitea_runner_healthcheck_script_path: "{{ gitea_runner_config_dir }}/healthcheck.sh"
# Auto-recovery: when the healthcheck detects an unregistered runner, it
# can automatically re-register if a Gitea API token is provided.
# The token needs admin or org-level access to fetch registration tokens.
# Stored in a file readable by the runner user (mode 0400).
# Set to empty string to disable auto-recovery (manual re-registration required).
gitea_runner_auto_recover_api_token: ""
# Cooldown file to prevent auto-recovery loops (e.g., if Gitea is down).
# The healthcheck writes a timestamp to this file after a re-registration
# attempt and skips further attempts for the cooldown period.
gitea_runner_auto_recover_cooldown_sec: 300
# Docker daemon resilience settings (applied to daemon.json).
# live-restore: containers survive daemon restarts — prevents stuck container
# states when the healthcheck restarts a hung daemon.
@@ -81,10 +51,6 @@ gitea_runner_docker_shutdown_timeout: 30
gitea_runner_docker_max_concurrent_downloads: 3
gitea_runner_docker_max_concurrent_uploads: 3
gitea_runner_docker_default_nofile: 65536
# Log file size limits — under parallel DinD load, container logs can fill
# disk and cause the daemon to become unresponsive. Limit log size per container.
gitea_runner_docker_max_log_size: "10m"
gitea_runner_docker_max_log_files: 3
# Admin token for runner deregistration via Gitea API.
# If not set, falls back to registration_token (which likely lacks admin scope).
@@ -10,7 +10,3 @@
- ansible_facts is defined
- ansible_facts['service_mgr'] | default('') == 'systemd'
- gitea_runner_docker_rootless_setup
- name: Reload systemd user daemon
ansible.builtin.systemd:
daemon_reload: true
@@ -47,9 +47,9 @@
ansible.builtin.assert:
that:
- "'Type=oneshot' in prune_service.content | b64decode"
- "'docker rm -f' in prune_service.content | b64decode"
- "'GITEA-ACTIONS-TASK' in prune_service.content | b64decode"
- "'docker system prune -af' in prune_service.content | b64decode"
- "'docker system prune' in prune_service.content | b64decode"
- "'docker volume prune' in prune_service.content | b64decode"
- "'docker container prune' in prune_service.content | b64decode"
- "'docker network prune' in prune_service.content | b64decode"
- "'docker builder prune' in prune_service.content | b64decode"
fail_msg: "Prune service template is missing expected directives"
@@ -105,11 +105,23 @@
- "'timeout 10 docker info' in healthcheck_script.content | b64decode"
- "'systemctl --user restart docker.service' in healthcheck_script.content | b64decode"
- "'systemctl --user restart gitea-runner.service' in healthcheck_script.content | b64decode"
- "'docker rm -f' in healthcheck_script.content | b64decode"
- "'GITEA-ACTIONS-TASK' in healthcheck_script.content | b64decode"
- "'docker system prune -af' in healthcheck_script.content | b64decode"
- "'docker system prune' in healthcheck_script.content | b64decode"
- "'docker container prune' in healthcheck_script.content | b64decode"
- "'docker network prune' in healthcheck_script.content | b64decode"
- "'status=removing' in healthcheck_script.content | b64decode"
- "'status=stopping' in healthcheck_script.content | b64decode"
- "'docker rm -f' in healthcheck_script.content | b64decode"
- "gitea_runner_healthcheck_disk_threshold | string in healthcheck_script.content | b64decode"
fail_msg: "Healthcheck script template is missing expected content"
- name: Assert healthcheck script does NOT use aggressive prune (-af)
ansible.builtin.assert:
that:
- "'prune -af' not in healthcheck_script.content | b64decode"
- "'image prune -af' not in healthcheck_script.content | b64decode"
- "'system prune -af' not in healthcheck_script.content | b64decode"
- "'volume prune -af' not in healthcheck_script.content | b64decode"
fail_msg: >-
Healthcheck script uses 'prune -af' which removes ALL images
(including tagged runner images like ci-full). Use 'prune -f'
(dangling only) to preserve tagged images.
@@ -7,22 +7,6 @@
group: "{{ gitea_runner_service_user }}"
mode: "0755"
- name: Write auto-recovery API token file
ansible.builtin.copy:
content: "{{ gitea_runner_auto_recover_api_token }}"
dest: "{{ gitea_runner_config_dir }}/auto-recover.token"
owner: "{{ gitea_runner_service_user }}"
group: "{{ gitea_runner_service_user }}"
mode: "0400"
no_log: true
when: gitea_runner_auto_recover_api_token | length > 0
- name: Remove stale auto-recovery token file (if auto-recovery disabled)
ansible.builtin.file:
path: "{{ gitea_runner_config_dir }}/auto-recover.token"
state: absent
when: gitea_runner_auto_recover_api_token | length == 0
- name: Create healthcheck user service file
ansible.builtin.template:
src: runner-healthcheck.service.j2
@@ -40,22 +24,24 @@
mode: "0644"
- name: Reload systemd user daemon for healthcheck timer
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user daemon-reload
ansible.builtin.command: systemctl --user daemon-reload
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
- gitea_runner_docker_rootless_setup
- name: Enable and start healthcheck user timer
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user enable --now runner-healthcheck.timer
ansible.builtin.command: systemctl --user enable --now runner-healthcheck.timer
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
@@ -13,9 +13,9 @@
- name: Include validation
ansible.builtin.include_tasks: validate.yml
- name: Include service setup
ansible.builtin.include_tasks: service.yml
- name: Include registration
ansible.builtin.include_tasks: register.yml
when: not gitea_runner_skip_registration
- name: Include service setup
ansible.builtin.include_tasks: service.yml
+12 -10
View File
@@ -18,11 +18,12 @@
register: gitea_runner_prune_timer
- name: Reload systemd user daemon for prune timer
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user daemon-reload
ansible.builtin.command: systemctl --user daemon-reload
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
@@ -30,11 +31,12 @@
- gitea_runner_prune_service is changed or gitea_runner_prune_timer is changed
- name: Enable and start docker-prune user timer
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user enable --now docker-prune.timer
ansible.builtin.command: systemctl --user enable --now docker-prune.timer
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
+3 -27
View File
@@ -7,20 +7,11 @@
group: "{{ gitea_runner_service_user }}"
mode: "0755"
- name: Check if runner registration file exists
- name: Check if runner is already registered
ansible.builtin.stat:
path: "{{ gitea_runner_data_dir }}/.runner"
register: gitea_runner_registered
- name: Remove stale runner registration file
ansible.builtin.file:
path: "{{ gitea_runner_data_dir }}/.runner"
state: absent
when:
- gitea_runner_registered.stat.exists
- gitea_runner_force_reregister | bool
register: gitea_runner_registration_removed
- name: Register runner with Gitea
ansible.builtin.command: >
{{ gitea_runner_binary_path }} register
@@ -37,22 +28,7 @@
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid | default(0) }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
DOCKER_HOST: "unix:///run/user/{{ gitea_runner_uid | default(0) }}/docker.sock"
when: not gitea_runner_registered.stat.exists or gitea_runner_force_reregister | bool
when: not gitea_runner_registered.stat.exists
register: gitea_runner_register_output
changed_when: >-
gitea_runner_register_output.rc == 0 and
('already exists' not in gitea_runner_register_output.stdout | default(''))
changed_when: "'already exists' not in gitea_runner_register_output.stdout | default('')"
timeout: 60
- name: Restart runner service after (re-)registration
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user restart gitea-runner
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
- gitea_runner_docker_rootless_setup
- gitea_runner_register_output is defined
- gitea_runner_register_output.rc | default(1) == 0
@@ -53,6 +53,72 @@
register: gitea_runner_docker_install
when: ansible_facts['os_family'] == 'Debian'
# Docker 28.x vendors containerd v2.1.x. containerd.io >= 2.3 ships a shim that
# returns a protobuf BootstrapResult the vendored 2.1.x code cannot parse, causing
# "failed to create TTRPC connection: unsupported protocol" on every container start.
# Detect the mismatch and downgrade containerd.io to the latest compatible 2.2.x.
- name: Check installed Docker CE version (Debian/Ubuntu)
ansible.builtin.command: dpkg-query -W -f='${Version}' docker-ce
register: gitea_runner_docker_version_check
changed_when: false
when: ansible_facts['os_family'] == 'Debian'
- name: Check installed containerd.io version (Debian/Ubuntu)
ansible.builtin.shell: "set -o pipefail; dpkg-query -W -f='${Version}' containerd.io 2>/dev/null | cut -d: -f2 | cut -d- -f1"
args:
executable: /bin/bash
register: gitea_runner_containerd_version_check
changed_when: false
when: ansible_facts['os_family'] == 'Debian'
- name: Determine if containerd.io is incompatible with installed Docker
ansible.builtin.set_fact:
gitea_runner_containerd_needs_downgrade: >-
{{
gitea_runner_containerd_version_check.stdout.split('.')[0] | int > gitea_runner_containerd_max_compatible_major
or (
gitea_runner_containerd_version_check.stdout.split('.')[0] | int == gitea_runner_containerd_max_compatible_major
and gitea_runner_containerd_version_check.stdout.split('.')[1] | int > gitea_runner_containerd_max_compatible_minor
)
}}
gitea_runner_docker_major: "{{ gitea_runner_docker_version_check.stdout.split('.')[0] | default('0') | int }}"
when: ansible_facts['os_family'] == 'Debian'
- name: Find latest compatible containerd.io version (Debian/Ubuntu)
ansible.builtin.shell: |
set -o pipefail
apt-cache madison containerd.io \
| awk -F'|' '{print $2}' \
| tr -d ' ' \
| grep -E '^{{ gitea_runner_containerd_max_compatible_major }}\.{{ gitea_runner_containerd_max_compatible_minor }}\.' \
| head -1
args:
executable: /bin/bash
register: gitea_runner_containerd_compatible_version
changed_when: false
when:
- ansible_facts['os_family'] == 'Debian'
- gitea_runner_containerd_needs_downgrade | default(false)
- gitea_runner_docker_major | int < 29
- name: Downgrade containerd.io to compatible version (Debian/Ubuntu)
ansible.builtin.apt:
name: "containerd.io={{ gitea_runner_containerd_compatible_version.stdout }}"
state: present
allow_downgrades: true
register: gitea_runner_containerd_downgrade
when:
- ansible_facts['os_family'] == 'Debian'
- gitea_runner_containerd_needs_downgrade | default(false)
- gitea_runner_docker_major | int < 29
- gitea_runner_containerd_compatible_version.stdout | length > 0
- name: Hold containerd.io package to prevent auto-upgrade (Debian/Ubuntu)
ansible.builtin.dpkg_selections:
name: containerd.io
selection: hold
when: ansible_facts['os_family'] == 'Debian'
- name: Update pacman cache (Arch Linux)
community.general.pacman:
update_cache: true
@@ -143,10 +209,6 @@
{% if gitea_runner_docker_rootless_net_driver == 'pasta' %}
Environment="DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS=--ipv6"
{% endif %}
Restart=always
RestartSec=5
StartLimitIntervalSec=300
StartLimitBurst=10
mode: "0644"
owner: "{{ gitea_runner_service_user }}"
group: "{{ gitea_runner_service_user }}"
@@ -184,10 +246,6 @@
"features": {
"containerd-snapshotter": false
},
"log-opts": {
"max-size": "{{ gitea_runner_docker_max_log_size }}",
"max-file": "{{ gitea_runner_docker_max_log_files }}"
},
{% if gitea_runner_docker_rootless_net_driver == 'pasta' %}
"ipv6": true,
"ip6tables": true,
@@ -220,20 +278,22 @@
- not gitea_runner_rootless_docker_check.stat.exists
- name: Start rootless Docker daemon (systemd user service)
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user start docker
ansible.builtin.command: systemctl --user start docker
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid }}/bus"
changed_when: true
when: gitea_runner_docker_rootless_setup
- name: Enable rootless Docker daemon (systemd user service)
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user enable docker
ansible.builtin.command: systemctl --user enable docker
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid }}/bus"
changed_when: true
when: gitea_runner_docker_rootless_setup
@@ -256,10 +316,6 @@
{% if gitea_runner_docker_rootless_net_driver == 'pasta' %}
Environment="DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS=--ipv6"
{% endif %}
Restart=always
RestartSec=5
StartLimitIntervalSec=300
StartLimitBurst=10
mode: "0644"
owner: "{{ gitea_runner_service_user }}"
group: "{{ gitea_runner_service_user }}"
@@ -267,11 +323,12 @@
when: gitea_runner_docker_rootless_setup
- name: Reload systemd user daemon if network config changed
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user daemon-reload
ansible.builtin.command: systemctl --user daemon-reload
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid }}/bus"
changed_when: true
when:
- gitea_runner_docker_rootless_setup
@@ -292,10 +349,6 @@
"features": {
"containerd-snapshotter": false
},
"log-opts": {
"max-size": "{{ gitea_runner_docker_max_log_size }}",
"max-file": "{{ gitea_runner_docker_max_log_files }}"
},
{% if gitea_runner_docker_rootless_net_driver == 'pasta' %}
"ipv6": true,
"ip6tables": true,
@@ -313,11 +366,12 @@
when: gitea_runner_docker_rootless_setup
- name: Restart rootless Docker if config changed
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user restart docker
ansible.builtin.command: systemctl --user restart docker
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid }}/bus"
changed_when: true
when:
- gitea_runner_docker_rootless_setup
+18 -15
View File
@@ -9,11 +9,12 @@
register: gitea_runner_service_file
- name: Reload systemd user daemon
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user daemon-reload
ansible.builtin.command: systemctl --user daemon-reload
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
@@ -21,11 +22,12 @@
- gitea_runner_service_file is changed
- name: Restart gitea-runner if service file changed
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user restart gitea-runner
ansible.builtin.command: systemctl --user restart gitea-runner
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
@@ -33,11 +35,12 @@
- gitea_runner_service_file is changed
- name: Enable and start gitea-runner user service
ansible.builtin.command: >
runuser -u {{ gitea_runner_service_user }} --
env XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus
systemctl --user enable --now gitea-runner
ansible.builtin.command: systemctl --user enable --now gitea-runner
become: true
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ gitea_runner_uid | default(0) }}/bus"
changed_when: true
when:
- gitea_runner_systemd_available.stat.exists
@@ -69,31 +69,3 @@
owner: "{{ gitea_runner_service_user }}"
group: "{{ gitea_runner_service_user }}"
mode: "0755"
- name: Disable systemd-oomd memory pressure kill for runner user
when: gitea_runner_systemd_available.stat.exists
block:
- name: Ensure user service override directory exists
ansible.builtin.file:
path: "/etc/systemd/system/user@{{ gitea_runner_uid }}.service.d"
state: directory
owner: root
group: root
mode: "0755"
- name: Disable ManagedOOMMemoryPressure for runner user
ansible.builtin.copy:
content: |
[Service]
ManagedOOMMemoryPressure=auto
ManagedOOMMemoryPressureLimit=100%
OOMScoreAdjust=-500
dest: "/etc/systemd/system/user@{{ gitea_runner_uid }}.service.d/oomd-override.conf"
owner: root
group: root
mode: "0644"
notify: Reload systemd user daemon
- name: Reload systemd daemon for oomd override
ansible.builtin.systemd:
daemon_reload: true
@@ -5,13 +5,8 @@ Description=Docker prune for Gitea runner resources
Type=oneshot
Environment=DOCKER_HOST=unix:///run/user/{{ gitea_runner_uid }}/docker.sock
Environment=XDG_RUNTIME_DIR=/run/user/{{ gitea_runner_uid }}
# Force-remove stale containers (including running ones) left behind by failed
# molecule tests. "docker container prune -f" only removes stopped containers,
# so running containers from crashed/interrupted CI jobs accumulate indefinitely,
# consuming disk and memory. We stop+rm everything first, then prune the rest.
# Exclude CI job containers (name starts with GITEA-ACTIONS-TASK) — removing
# them kills the active CI job and causes "RWLayer is unexpectedly nil" errors.
ExecStart=/bin/sh -c 'docker ps -a --format "{% raw %}{{.ID}} {{.Names}}{% endraw %}" 2>/dev/null | grep -v "GITEA-ACTIONS-TASK" | awk "{print $1}" | xargs -r docker rm -f 2>/dev/null || true'
ExecStart=/usr/bin/docker system prune -af --filter "until={{ gitea_runner_prune_until }}" --volumes
ExecStart=/usr/bin/docker system prune -f --filter "label={{ gitea_runner_prune_label }}" --filter "until={{ gitea_runner_prune_until }}"
ExecStart=/usr/bin/docker volume prune -f --filter "label={{ gitea_runner_prune_label }}"
ExecStart=/usr/bin/docker container prune -f
ExecStart=/usr/bin/docker network prune -f
ExecStart=/usr/bin/docker builder prune -f
@@ -44,130 +44,16 @@ if [[ "$runner_state" != "active" ]]; then
echo "RECOVERED: gitea-runner service restarted successfully"
fi
# 2b. Detect unregistered runner state. When Gitea no longer recognizes the
# runner (e.g., server restore, runner record deleted, Gitea restart with
# token salt change), the runner logs "unregistered runner" every few seconds.
# A service restart will not fix this; re-registration is required.
{% if gitea_runner_auto_recover_api_token %}
# Auto-recovery is enabled: fetch a new registration token from the Gitea API
# and re-register the runner automatically. A cooldown prevents infinite loops.
GITEA_API_TOKEN_FILE="{{ gitea_runner_config_dir }}/auto-recover.token"
COOLDOWN_FILE="{{ gitea_runner_data_dir }}/auto-recover.cooldown"
COOLDOWN_SEC={{ gitea_runner_auto_recover_cooldown_sec }}
GITEA_URL="{{ gitea_url }}"
RUNNER_NAME="{{ gitea_runner_name }}"
RUNNER_LABELS="{{ gitea_runner_labels }}"
BINARY="{{ gitea_runner_binary_path }}"
{% endif %}
recent_errors=$(journalctl --user -u gitea-runner.service --since "5 minutes ago" --no-pager -q 2>/dev/null | grep -c "unregistered runner" || true)
if [[ "$recent_errors" -ge 3 ]]; then
echo "CRITICAL: runner is unregistered in Gitea (re-login failed $recent_errors times in 5 minutes)."
{% if gitea_runner_auto_recover_api_token %}
# Check cooldown — skip if we recently attempted recovery
if [[ -f "$COOLDOWN_FILE" ]]; then
last_attempt=$(cat "$COOLDOWN_FILE" 2>/dev/null || echo 0)
now=$(date +%s)
elapsed=$((now - last_attempt))
if [[ "$elapsed" -lt "$COOLDOWN_SEC" ]]; then
echo "SKIP: auto-recovery cooldown active (${elapsed}s < ${COOLDOWN_SEC}s). Will retry later."
exit 3
fi
fi
# Mark attempt time BEFORE trying (so failures also get cooldown)
date +%s > "$COOLDOWN_FILE" 2>/dev/null || true
# Read the API token
if [[ ! -f "$GITEA_API_TOKEN_FILE" ]]; then
echo "ERROR: auto-recover token file not found at $GITEA_API_TOKEN_FILE. Manual re-registration required."
exit 3
fi
API_TOKEN=$(cat "$GITEA_API_TOKEN_FILE" 2>/dev/null || true)
if [[ -z "$API_TOKEN" ]]; then
echo "ERROR: auto-recover token file is empty. Manual re-registration required."
exit 3
fi
echo "ATTEMPT: auto-recovering by fetching new registration token and re-registering..."
# Fetch a new registration token from the Gitea API
# Try org-level first (for org-scoped runners), then instance-level
REG_TOKEN=""
for endpoint in \
"api/v1/orgs/{{ gitea_runner_org | default('oblachno') }}/actions/runners/registration-token" \
"api/v1/admin/actions/runners/registration-token"; do
REG_TOKEN=$(curl -sf --connect-timeout 5 --max-time 10 -X POST \
-H "Authorization: token $API_TOKEN" \
"${GITEA_URL}/${endpoint}" 2>/dev/null | python3 -c "import sys,json; print(json.load(sys.stdin).get('token',''))" 2>/dev/null || true)
if [[ -n "$REG_TOKEN" ]]; then
echo "INFO: fetched registration token from ${endpoint}"
break
fi
done
if [[ -z "$REG_TOKEN" ]]; then
echo "ERROR: failed to fetch registration token from Gitea API. Is Gitea reachable?"
exit 3
fi
# Stop the runner service
systemctl --user stop gitea-runner.service 2>/dev/null || true
sleep 1
# Remove the stale .runner file
rm -f "{{ gitea_runner_data_dir }}/.runner" 2>/dev/null || true
# Re-register
cd "{{ gitea_runner_data_dir }}"
if "$BINARY" register \
--token "$REG_TOKEN" \
--name "$RUNNER_NAME" \
--instance "$GITEA_URL" \
--labels "$RUNNER_LABELS" \
--no-interactive 2>&1; then
echo "RECOVERED: runner re-registered successfully"
else
echo "ERROR: re-registration failed. Manual intervention required."
exit 3
fi
# Start the runner service
systemctl --user start gitea-runner.service
sleep 3
# Verify recovery — check if unregistered errors stopped
new_errors=$(journalctl --user -u gitea-runner.service --since "10 seconds ago" --no-pager -q 2>/dev/null | grep -c "unregistered runner" || true)
if [[ "$new_errors" -eq 0 ]]; then
echo "OK: runner recovered and no longer reporting unregistered errors"
# Clear cooldown on success
rm -f "$COOLDOWN_FILE" 2>/dev/null || true
else
echo "WARN: runner still showing unregistered errors after re-registration. Will retry after cooldown."
exit 3
fi
{% else %}
echo "Manual re-registration required: re-run gitea_runner role with gitea_runner_force_reregister=true."
# Restart the service once in case it is a transient token refresh issue,
# but this cannot recover an unregistered runner without re-registration.
systemctl --user restart gitea-runner.service
sleep 2
exit 3
{% endif %}
fi
# 3. Check disk space — prune aggressively if below threshold
disk_pct=$(df -P / | awk 'NR==2 {gsub(/%/, "", $5); print $5}')
if [[ "$disk_pct" -ge {{ gitea_runner_healthcheck_disk_threshold }} ]]; then
echo "WARN: Disk usage at ${disk_pct}%, pruning all runner resources"
# Force-remove stale containers (including running ones from failed molecule tests).
# "docker container prune -f" only removes stopped containers, so running
# containers from crashed CI jobs accumulate and consume disk/memory.
# Exclude CI job containers (name starts with GITEA-ACTIONS-TASK).
docker ps -a --format '{% raw %}{{.ID}} {{.Names}}{% endraw %}' 2>/dev/null \
| grep -v 'GITEA-ACTIONS-TASK' \
| awk '{print $1}' \
| xargs -r docker rm -f 2>/dev/null || true
docker system prune -af --filter "until=1h" --volumes || true
docker system prune -f --filter "label={{ gitea_runner_prune_label }}" --filter "until=1h" || true
docker volume prune -f --filter "label={{ gitea_runner_prune_label }}" || true
# Only prune dangling (untagged) images — keep tagged runner images (ci-full, ci-quality)
docker image prune -f || true
# Clean up stopped containers and dangling networks that accumulate from failed jobs
docker container prune -f || true
docker network prune -f || true
disk_pct=$(df -P / | awk 'NR==2 {gsub(/%/, "", $5); print $5}')
echo "INFO: Disk usage after prune: ${disk_pct}%"
+1 -1
View File
@@ -33,5 +33,5 @@
become_user: "{{ gitea_runner_service_user }}"
environment:
XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}"
when: gitea_runner_systemd_available.stat.exists
when: systemd_available.stat.exists
changed_when: true
+6 -6
View File
@@ -8,12 +8,12 @@ Each runner runs in an isolated **rootless Docker** environment under a dedicate
[![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/src/branch/master/LICENSE)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/e96a599d8e0a5186cd72bebaddbd24b2df2e2058/python.svg)](https://www.python.org/downloads/)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/grm/raw/commit/7b6c9f92334256c26b0b018e3a23968a30abdf64/python.svg)](https://www.python.org/downloads/)
## Overview
+3 -3
View File
@@ -259,9 +259,9 @@ OS platform matrix (defined in `devx.molecule.platforms`), then splits
the resulting test pairs evenly across the requested number of runners.
Each pair is encoded as `scenario|platform_name|platform_image|platform_command`.
The CI workflow runs each test pair sequentially via a shell loop that
sets the appropriate `MOLECULE_PLATFORM_*` environment variables and
invokes `molecule test` directly.
`devx.molecule.molecule_ci_guard` runs the actual molecule test for a
given test pair, with CI context (Gitea URL, token, run ID) for
reporting results back to the commit status API.
### Commit Message Validation
+1 -1
View File
@@ -91,7 +91,7 @@ The `molecule-tests` job uses `fromJSON()` to consume the dynamic matrix, and pa
`devx.molecule.distribute_molecule` discovers all molecule scenarios under `ansible/roles/*/molecule/` and crosses them with the supported OS platform matrix, then splits the resulting test pairs evenly across the requested number of runners. Each pair is encoded as `scenario|platform_name|platform_image|platform_command`.
The CI workflow runs each test pair sequentially via a shell loop that sets the appropriate `MOLECULE_PLATFORM_*` environment variables and invokes `molecule test` directly.
`devx.molecule.molecule_ci_guard` runs the actual molecule test for a given test pair, with CI context (Gitea URL, token, run ID) for reporting results back to the commit status API.
### Path-based CI filtering
+2 -2
View File
@@ -36,7 +36,7 @@ ci = [
"build==1.5.1",
"twine==6.2.0",
# Reusable CI/CD and dev tools (auto-merge, pr-review, pre-push checks, etc.)
"devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.50.1",
"devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.47.8",
]
# Lint and type-checking tools (validate job)
lint = [
@@ -56,7 +56,7 @@ molecule = [
dev = [
"grm[ci,lint,molecule]",
# Reusable CI/CD and dev tools (pre-push hooks, create-task, create-pr)
"devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.50.1",
"devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.47.8",
# Non-Python dev dependency: checkmake (Makefile linter)
# Install via: go install github.com/checkmake/checkmake/cmd/checkmake@latest
]
-136
View File
@@ -1,136 +0,0 @@
#!/usr/bin/env python3
"""Clean up stale runner registrations from Gitea.
A runner is considered stale if it hasn't been online for more than a
configurable threshold (default: 1 hour). Stale runners accumulate when:
- A runner host is rebuilt or re-provisioned (old registration remains)
- A runner is re-registered (old entry remains alongside the new one)
- A runner process dies and the healthcheck can't auto-recover
This script queries the Gitea API for all runners, identifies stale ones,
and deletes them via ``DELETE /api/v1/admin/actions/runners/{id}``.
Usage::
python3 scripts/cleanup_stale_runners.py --gitea-url https://git.example.com --token <admin-token>
python3 scripts/cleanup_stale_runners.py --gitea-url https://git.example.com --token <admin-token> --dry-run
python3 scripts/cleanup_stale_runners.py --gitea-url https://git.example.com --token <admin-token> \\
--stale-threshold 3600
"""
from __future__ import annotations
import argparse
import json
import sys
import time
import urllib.error
import urllib.request # noqa: PTH123 # nosec B404
from typing import Any
def _api_request(base_url: str, token: str, method: str, path: str) -> Any:
url = f"{base_url.rstrip('/')}/api/v1{path}"
req = urllib.request.Request(url, method=method) # nosec B310
req.add_header("Authorization", f"token {token}")
req.add_header("Accept", "application/json")
try:
with urllib.request.urlopen(req) as resp: # noqa: PTH123 # nosec B310
if resp.status == 204:
return None
raw = resp.read()
return json.loads(raw) if raw else None
except urllib.error.HTTPError as e:
detail = e.read().decode("utf-8", errors="replace")
raise RuntimeError(f"Gitea API error {e.code}: {detail}") from e
def list_runners(base_url: str, token: str) -> list[dict[str, Any]]:
data = _api_request(base_url, token, "GET", "/admin/actions/runners")
if data is None:
return []
if isinstance(data, list):
return data
if isinstance(data, dict):
return data.get("runners", [])
return []
def delete_runner(base_url: str, token: str, runner_id: int) -> bool:
try:
_api_request(base_url, token, "DELETE", f"/admin/actions/runners/{runner_id}")
return True
except RuntimeError as e:
print(f" ERROR deleting runner {runner_id}: {e}", file=sys.stderr)
return False
def main(argv: list[str] | None = None) -> int:
parser = argparse.ArgumentParser(description="Clean up stale Gitea runner registrations")
parser.add_argument("--gitea-url", required=True, help="Gitea base URL")
parser.add_argument("--token", required=True, help="Gitea admin API token")
parser.add_argument(
"--stale-threshold",
type=int,
default=3600,
help="Seconds since last_online before a runner is considered stale (default: 3600 = 1h)",
)
parser.add_argument("--dry-run", action="store_true", help="List stale runners without deleting")
args = parser.parse_args(argv)
runners = list_runners(args.gitea_url, args.token)
if not runners:
print("No runners found.")
return 0
now = int(time.time())
stale: list[dict[str, Any]] = []
online: list[dict[str, Any]] = []
for runner in runners:
last_online = runner.get("last_online", 0) or 0
seconds_since = now - last_online
runner["seconds_since_online"] = seconds_since
if seconds_since > args.stale_threshold:
stale.append(runner)
else:
online.append(runner)
print(f"Total runners: {len(runners)}")
print(f"Online (within {args.stale_threshold}s): {len(online)}")
print(f"Stale (>{args.stale_threshold}s): {len(stale)}")
print()
if not stale:
print("No stale runners to clean up.")
return 0
print("Stale runners:")
for r in stale:
rid = r.get("id", "?")
name = r.get("name", "?")
uuid = r.get("uuid", "?")[:8]
secs = r.get("seconds_since_online", 0)
hours = secs / 3600
print(f" id={rid} name={name} uuid={uuid}... offline={hours:.1f}h ago")
if args.dry_run:
print("\n--dry-run: not deleting. Remove --dry-run to clean up.")
return 0
print(f"\nDeleting {len(stale)} stale runners...")
deleted = 0
for r in stale:
rid = r.get("id")
if rid is None:
continue
if delete_runner(args.gitea_url, args.token, rid):
deleted += 1
print(f" Deleted runner id={rid} ({r.get('name', '?')})")
print(f"\nDone: {deleted}/{len(stale)} stale runners deleted.")
return 0 if deleted == len(stale) else 1
if __name__ == "__main__": # pragma: no cover
sys.exit(main())
-217
View File
@@ -1,217 +0,0 @@
"""Tests for cleanup_stale_runners.py."""
from __future__ import annotations
import time
from unittest.mock import MagicMock, patch
from scripts.cleanup_stale_runners import (
_api_request,
delete_runner,
list_runners,
main,
)
class TestListRunners:
"""Tests for list_runners()."""
@patch("scripts.cleanup_stale_runners._api_request")
def test_returns_list_of_runners(self, mock_req: MagicMock) -> None:
mock_req.return_value = [{"id": 1, "name": "runner-1"}, {"id": 2, "name": "runner-2"}]
result = list_runners("https://git.example.com", "token")
assert len(result) == 2
assert result[0]["id"] == 1
@patch("scripts.cleanup_stale_runners._api_request")
def test_returns_empty_on_none(self, mock_req: MagicMock) -> None:
mock_req.return_value = None
result = list_runners("https://git.example.com", "token")
assert result == []
@patch("scripts.cleanup_stale_runners._api_request")
def test_extracts_runners_from_dict(self, mock_req: MagicMock) -> None:
mock_req.return_value = {"runners": [{"id": 1}]}
result = list_runners("https://git.example.com", "token")
assert len(result) == 1
assert result[0]["id"] == 1
@patch("scripts.cleanup_stale_runners._api_request")
def test_returns_empty_on_non_list_non_dict(self, mock_req: MagicMock) -> None:
mock_req.return_value = "not a list"
result = list_runners("https://git.example.com", "token")
assert result == []
class TestDeleteRunner:
"""Tests for delete_runner()."""
@patch("scripts.cleanup_stale_runners._api_request")
def test_returns_true_on_success(self, mock_req: MagicMock) -> None:
mock_req.return_value = None
assert delete_runner("https://git.example.com", "token", 42) is True
@patch("scripts.cleanup_stale_runners._api_request")
def test_returns_false_on_error(self, mock_req: MagicMock) -> None:
mock_req.side_effect = RuntimeError("API error 404: not found")
assert delete_runner("https://git.example.com", "token", 42) is False
class TestApiRequest:
"""Tests for _api_request()."""
@patch("scripts.cleanup_stale_runners.urllib.request.urlopen")
def test_returns_json_on_success(self, mock_urlopen: MagicMock) -> None:
mock_resp = MagicMock()
mock_resp.status = 200
mock_resp.read.return_value = b'{"key": "value"}'
mock_urlopen.return_value.__enter__.return_value = mock_resp
result = _api_request("https://git.example.com", "token", "GET", "/test")
assert result == {"key": "value"}
@patch("scripts.cleanup_stale_runners.urllib.request.urlopen")
def test_returns_none_on_204(self, mock_urlopen: MagicMock) -> None:
mock_resp = MagicMock()
mock_resp.status = 204
mock_urlopen.return_value.__enter__.return_value = mock_resp
result = _api_request("https://git.example.com", "token", "DELETE", "/test/1")
assert result is None
@patch("scripts.cleanup_stale_runners.urllib.request.urlopen")
def test_returns_none_on_empty_body(self, mock_urlopen: MagicMock) -> None:
mock_resp = MagicMock()
mock_resp.status = 200
mock_resp.read.return_value = b""
mock_urlopen.return_value.__enter__.return_value = mock_resp
result = _api_request("https://git.example.com", "token", "GET", "/test")
assert result is None
@patch("scripts.cleanup_stale_runners.urllib.request.urlopen")
def test_raises_on_http_error(self, mock_urlopen: MagicMock) -> None:
import urllib.error
mock_error = urllib.error.HTTPError(
"url",
404,
"Not Found",
{},
None,
)
mock_error.read = MagicMock(return_value=b'{"message": "not found"}')
mock_urlopen.side_effect = mock_error
import pytest
with pytest.raises(RuntimeError, match="404"):
_api_request("https://git.example.com", "token", "GET", "/test")
class TestMain:
"""Tests for main()."""
@patch("scripts.cleanup_stale_runners.list_runners")
def test_no_runners(self, mock_list: MagicMock) -> None:
mock_list.return_value = []
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
assert rc == 0
@patch("scripts.cleanup_stale_runners.list_runners")
def test_no_stale_runners(self, mock_list: MagicMock) -> None:
now = int(time.time())
mock_list.return_value = [
{"id": 1, "name": "runner-1", "last_online": now - 60},
]
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
assert rc == 0
@patch("scripts.cleanup_stale_runners.list_runners")
def test_dry_run_does_not_delete(self, mock_list: MagicMock) -> None:
now = int(time.time())
mock_list.return_value = [
{"id": 1, "name": "runner-1", "last_online": now - 7200},
]
with patch("scripts.cleanup_stale_runners.delete_runner") as mock_del:
rc = main(
[
"--gitea-url",
"https://git.example.com",
"--token",
"t",
"--dry-run",
]
)
assert rc == 0
mock_del.assert_not_called()
@patch("scripts.cleanup_stale_runners.list_runners")
@patch("scripts.cleanup_stale_runners.delete_runner")
def test_deletes_stale_runners(self, mock_del: MagicMock, mock_list: MagicMock) -> None:
now = int(time.time())
mock_list.return_value = [
{"id": 1, "name": "runner-1", "last_online": now - 60},
{"id": 2, "name": "runner-2", "last_online": now - 7200},
{"id": 3, "name": "runner-3", "last_online": now - 9999},
]
mock_del.return_value = True
rc = main(
[
"--gitea-url",
"https://git.example.com",
"--token",
"t",
"--stale-threshold",
"3600",
]
)
assert rc == 0
assert mock_del.call_count == 2
@patch("scripts.cleanup_stale_runners.list_runners")
@patch("scripts.cleanup_stale_runners.delete_runner")
def test_returns_1_on_partial_failure(self, mock_del: MagicMock, mock_list: MagicMock) -> None:
now = int(time.time())
mock_list.return_value = [
{"id": 1, "name": "runner-1", "last_online": now - 7200},
{"id": 2, "name": "runner-2", "last_online": now - 7200},
]
mock_del.side_effect = [True, False]
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
assert rc == 1
@patch("scripts.cleanup_stale_runners.list_runners")
def test_runner_with_zero_last_online(self, mock_list: MagicMock) -> None:
"""Runners with last_online=0 should be considered stale."""
mock_list.return_value = [
{"id": 1, "name": "runner-1", "last_online": 0},
]
with patch("scripts.cleanup_stale_runners.delete_runner") as mock_del:
mock_del.return_value = True
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
assert rc == 0
mock_del.assert_called_once()
@patch("scripts.cleanup_stale_runners.list_runners")
def test_runner_with_missing_last_online(self, mock_list: MagicMock) -> None:
"""Runners with missing last_online should be considered stale."""
mock_list.return_value = [
{"id": 1, "name": "runner-1"},
]
with patch("scripts.cleanup_stale_runners.delete_runner") as mock_del:
mock_del.return_value = True
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
assert rc == 0
mock_del.assert_called_once()
@patch("scripts.cleanup_stale_runners.list_runners")
@patch("scripts.cleanup_stale_runners.delete_runner")
def test_skips_runner_with_none_id(self, mock_del: MagicMock, mock_list: MagicMock) -> None:
"""Runners with id=None should be skipped during deletion."""
now = int(time.time())
mock_list.return_value = [
{"id": None, "name": "bad-runner", "last_online": now - 7200},
{"id": 2, "name": "runner-2", "last_online": now - 7200},
]
mock_del.return_value = True
rc = main(["--gitea-url", "https://git.example.com", "--token", "t"])
# 1/2 deleted (None id skipped), so rc=1 (partial)
assert rc == 1
mock_del.assert_called_once_with("https://git.example.com", "t", 2)
+1 -1
View File
@@ -1,3 +1,3 @@
"""Gitea Runner Manager — lean CLI for managing Gitea Actions runners."""
__version__ = "0.20.0"
__version__ = "0.18.8"
+1 -21
View File
@@ -145,25 +145,11 @@ def cli(ctx: click.Context, become_password_file: str | None, verbose: bool) ->
"Example: docker:docker://alpine:latest"
),
)
@click.option(
"--force-reregister/--no-force-reregister",
default=False,
help=_("Force re-registration even if .runner file exists (env: GITEA_FORCE_REREGISTER)"),
)
@click.option(
"--ask-become-pass/--no-ask-become-pass",
default=True,
help=_("Prompt for sudo password (default)"),
)
@click.option(
"--auto-recover-token",
default=None,
help=_(
"Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). "
"When set, the healthcheck can automatically re-register the runner "
"if it becomes unregistered. Requires admin or org-level access."
),
)
@_handle_errors("Installation failed: {error}")
def install(
host: str,
@@ -175,14 +161,10 @@ def install(
admin_token: str | None,
integration_retries: int,
labels: str | None,
force_reregister: bool,
ask_become_pass: bool,
auto_recover_token: str | None,
) -> None:
if labels is None:
labels = os.getenv("GITEA_RUNNER_LABELS")
if auto_recover_token is None:
auto_recover_token = os.getenv("GITEA_AUTO_RECOVER_TOKEN")
manager = RunnerManager()
manager.install(
host=host,
@@ -194,11 +176,9 @@ def install(
admin_token=admin_token,
integration_retries=integration_retries,
labels=labels,
force_reregister=force_reregister,
ask_become_pass=ask_become_pass,
become_password_file=_get_become_password_file(),
verbose=_get_verbose(),
auto_recover_token=auto_recover_token,
)
@@ -526,7 +506,7 @@ def list_runners(ask_become_pass: bool, no_status: bool) -> None:
click.echo(f"{_('NAME'):<18} {_('HOST'):<16} {_('USER'):<10} {_('LABELS'):<30} {_('STATUS')}")
click.echo("-" * 90)
for r in runners:
click.echo(f"{r['name']:<18} {r['host']:<16} {r['user']:<10} {(r['labels'] or ''):<30} {r['status']}")
click.echo(f"{r['name']:<18} {r['host']:<16} {r['user']:<10} {r['labels']:<30} {r['status']}")
@cli.command(name="trigger-workflow", help=_("Trigger a Gitea Actions workflow via the API."))
+1 -6
View File
@@ -87,10 +87,8 @@ class RunnerManager:
integration_retries: int = 3,
ask_become_pass: bool = False,
labels: str | None = None,
force_reregister: bool = False,
become_password_file: str | None = None,
verbose: bool = False,
auto_recover_token: str | None = None,
) -> None:
"""Install a runner on a remote host using Ansible."""
if not name:
@@ -100,19 +98,16 @@ class RunnerManager:
if not token:
raise AnsibleError(_("GITEA_REGISTRATION_TOKEN must be set (or pass --token)"))
extra_vars: dict[str, str | int | bool] = {
extra_vars: dict[str, str | int] = {
"registration_token": token,
"gitea_runner_name": name,
"gitea_url": gitea_url,
"gitea_runner_integration_retries": integration_retries,
"gitea_runner_force_reregister": force_reregister,
}
if admin_token:
extra_vars["gitea_admin_token"] = admin_token
if labels is not None:
extra_vars["gitea_runner_labels"] = labels
if auto_recover_token:
extra_vars["gitea_runner_auto_recover_api_token"] = auto_recover_token
with track_steps() as tracker:
tracker.begin(_("Installing Gitea Runner on {host}", host=host))
-16
View File
@@ -367,14 +367,6 @@
"ru": "Токен регистрации (env: GITEA_REGISTRATION_TOKEN)",
"zh": "注册令牌(环境变量: GITEA_REGISTRATION_TOKEN"
},
"Force re-registration even if .runner file exists (env: GITEA_FORCE_REREGISTER)": {
"bg": "Принудителна повторна регистрация, дори ако .runner файлът съществува (env: GITEA_FORCE_REREGISTER)",
"de": "Erneute Registrierung erzwingen, auch wenn .runner-Datei existiert (env: GITEA_FORCE_REREGISTER)",
"en": "Force re-registration even if .runner file exists (env: GITEA_FORCE_REREGISTER)",
"pl": "Wymuś ponowną rejestrację, nawet jeśli plik .runner istnieje (env: GITEA_FORCE_REREGISTER)",
"ru": "Принудительно повторно зарегистрировать, даже если файл .runner существует (env: GITEA_FORCE_REREGISTER)",
"zh": "即使存在 .runner 文件也强制重新注册(环境变量: GITEA_FORCE_REREGISTER"
},
"Remove a registered Gitea Runner completely.": {
"bg": "Пълно премахване на регистриран Gitea Runner.",
"de": "Einen registrierten Gitea Runner vollständig entfernen.",
@@ -782,13 +774,5 @@
"pl": "Workflow uruchomiony pomyślnie. ID uruchomienia: {run_id}",
"ru": "Workflow успешно запущен. ID запуска: {run_id}",
"zh": "工作流触发成功。运行 ID{run_id}"
},
"Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.": {
"bg": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.",
"de": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.",
"en": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.",
"pl": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.",
"ru": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access.",
"zh": "Gitea API token for healthcheck auto-recovery (env: GITEA_AUTO_RECOVER_TOKEN). When set, the healthcheck can automatically re-register the runner if it becomes unregistered. Requires admin or org-level access."
}
}
-122
View File
@@ -50,11 +50,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -75,11 +73,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=False,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -118,11 +114,9 @@ class TestCLI:
admin_token=None,
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -171,11 +165,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -196,11 +188,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -236,92 +226,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels="docker:docker://alpine:latest",
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
def test_install_force_reregister(self, mock_manager_class: MagicMock) -> None:
mock_manager = MagicMock()
mock_manager_class.return_value = mock_manager
runner = CliRunner(env=_TEST_ENV)
result = runner.invoke(cli, ["install", "host1", "--user", "ubuntu", "--token", "tok", "--force-reregister"])
assert result.exit_code == 0
mock_manager.install.assert_called_once_with(
host="host1",
user="ubuntu",
key=None,
name=None,
token="tok",
gitea_url="https://git.example.com",
admin_token="",
integration_retries=3,
labels=None,
force_reregister=True,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
def test_install_with_auto_recover_token(self, mock_manager_class: MagicMock) -> None:
"""--auto-recover-token passes the token to the manager for healthcheck auto-recovery."""
mock_manager = MagicMock()
mock_manager_class.return_value = mock_manager
runner = CliRunner(env=_TEST_ENV)
result = runner.invoke(
cli,
["install", "host1", "--user", "ubuntu", "--token", "tok", "--auto-recover-token", "api-tok"],
)
assert result.exit_code == 0
mock_manager.install.assert_called_once_with(
host="host1",
user="ubuntu",
key=None,
name=None,
token="tok",
gitea_url="https://git.example.com",
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token="api-tok",
)
@patch("grm.cli.RunnerManager")
def test_install_auto_recover_token_from_env(self, mock_manager_class: MagicMock) -> None:
"""GITEA_AUTO_RECOVER_TOKEN env var is used when --auto-recover-token is not passed."""
mock_manager = MagicMock()
mock_manager_class.return_value = mock_manager
env = {**_TEST_ENV, "GITEA_AUTO_RECOVER_TOKEN": "env-tok"}
runner = CliRunner(env=env)
result = runner.invoke(cli, ["install", "host1", "--user", "ubuntu", "--token", "tok"])
assert result.exit_code == 0
mock_manager.install.assert_called_once_with(
host="host1",
user="ubuntu",
key=None,
name=None,
token="tok",
gitea_url="https://git.example.com",
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token="env-tok",
)
@patch("grm.cli.RunnerManager")
@@ -343,11 +250,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels="",
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -369,11 +274,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels="docker:docker://alpine:latest",
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=False,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -404,11 +307,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=pw_file,
verbose=False,
auto_recover_token=None,
)
finally:
import os
@@ -433,11 +334,9 @@ class TestCLI:
admin_token="",
integration_retries=3,
labels=None,
force_reregister=False,
ask_become_pass=True,
become_password_file=None,
verbose=True,
auto_recover_token=None,
)
@patch("grm.cli.RunnerManager")
@@ -842,27 +741,6 @@ class TestCLI:
assert "active" in result.output
mock_manager.list_runners.assert_called_once_with(become_pass=None, no_status=False)
@patch("grm.cli.RunnerManager")
def test_list_with_none_labels(self, mock_manager_class: MagicMock) -> None:
"""Runners with labels=None should not crash the list command."""
mock_manager = MagicMock()
mock_manager.list_runners.return_value = [
{
"name": "r1",
"host": "10.0.0.1",
"user": "ubuntu",
"labels": None,
"status": "active",
},
]
mock_manager_class.return_value = mock_manager
runner = CliRunner()
result = runner.invoke(cli, ["list"])
assert result.exit_code == 0
assert "r1" in result.output
assert "active" in result.output
@patch("grm.cli.RunnerManager")
def test_list_no_status(self, mock_manager_class: MagicMock) -> None:
"""--no-status skips SSH checks and shows registry only."""
-48
View File
@@ -51,7 +51,6 @@ class TestRunnerManager:
assert manager._captured_extra_vars["registration_token"] == "tok"
assert manager._captured_extra_vars["gitea_runner_name"] == "192.168.1.10"
assert manager._captured_extra_vars["gitea_url"] == "https://git.example.com"
assert manager._captured_extra_vars["gitea_runner_force_reregister"] is False
assert "Installing Gitea Runner on 192.168.1.10" in mock_executor.run.call_args.kwargs["description"]
mock_registry.add.assert_called_once_with(
name="192.168.1.10",
@@ -77,7 +76,6 @@ class TestRunnerManager:
assert "/key" in cmd_str
assert manager._captured_extra_vars["registration_token"] == "preset"
assert manager._captured_extra_vars["gitea_runner_name"] == "my-runner"
assert manager._captured_extra_vars["gitea_runner_force_reregister"] is False
assert "--ask-become-pass" not in cmd_str
mock_registry.add.assert_called_once_with(
name="my-runner",
@@ -99,52 +97,6 @@ class TestRunnerManager:
cmd_str = " ".join(cmd)
assert "--ask-become-pass" in cmd_str
def test_install_force_reregister(self) -> None:
mock_registry = MagicMock()
manager = RunnerManager(registry=mock_registry)
mock_executor = MagicMock()
manager._executor = mock_executor
manager.install(
"host1",
"root",
token="tok",
gitea_url="https://git.example.com",
force_reregister=True,
)
assert manager._captured_extra_vars["gitea_runner_force_reregister"] is True
def test_install_with_auto_recover_token(self) -> None:
"""auto_recover_token is passed as extra_var to Ansible."""
mock_registry = MagicMock()
manager = RunnerManager(registry=mock_registry)
mock_executor = MagicMock()
manager._executor = mock_executor
manager.install(
"host1",
"root",
token="tok",
gitea_url="https://git.example.com",
auto_recover_token="api-tok",
)
assert manager._captured_extra_vars["gitea_runner_auto_recover_api_token"] == "api-tok"
def test_install_without_auto_recover_token(self) -> None:
"""When auto_recover_token is None, the extra_var is not set."""
mock_registry = MagicMock()
manager = RunnerManager(registry=mock_registry)
mock_executor = MagicMock()
manager._executor = mock_executor
manager.install(
"host1",
"root",
token="tok",
gitea_url="https://git.example.com",
)
assert "gitea_runner_auto_recover_api_token" not in manager._captured_extra_vars
def test_install_missing_gitea_url(self) -> None:
manager = RunnerManager()
with pytest.raises(AnsibleError, match="GITEA_URL must be set"):