CI / validate (pull_request) Successful in 1m37s
CI / molecule-tests (2) (pull_request) Successful in 5m49s
CI / molecule-tests (4) (pull_request) Failing after 6m16s
CI / molecule-tests (3) (pull_request) Failing after 6m18s
CI / molecule-tests (1) (pull_request) Failing after 7m6s
CI / auto-merge (pull_request) Skipped
The healthcheck previously used a single 75% threshold with an
until=1h filter. On busy runners with constant CI jobs, nothing
is older than 1h, so the prune barely frees anything — disk stays
at ~76% and the CI disk gate (80%) skips all molecule tests.
Two-tier approach:
- 75-79%: gentle prune (until=1h) — same as before
- 80%+: full prune (no until filter) — removes ALL stopped
containers and unused images regardless of age, plus
builder cache and networks
This ensures that when disk pressure is critical, the healthcheck
actually reclaims space instead of skipping everything that's
recently created.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
136 lines
7.0 KiB
YAML
136 lines
7.0 KiB
YAML
---
|
|
gitea_runner_version: "2.0.1"
|
|
gitea_runner_labels: "docker,ubuntu-latest:docker://runner-images:ubuntu-26.04"
|
|
gitea_runner_skip_registration: false
|
|
|
|
# Force re-registration even if .runner file exists.
|
|
# Use this when Gitea no longer recognizes the runner (e.g., after a Gitea
|
|
# server restore/reinstall or when the runner record was deleted from the
|
|
# admin UI). The existing .runner file is removed and a new registration is
|
|
# performed. Requires registration_token.
|
|
gitea_runner_force_reregister: false
|
|
|
|
# Per-runner user (rootless isolation)
|
|
gitea_runner_user_prefix: "grm-"
|
|
gitea_runner_base_home: "/home"
|
|
gitea_runner_service_user: "{{ gitea_runner_user_prefix }}{{ gitea_runner_name }}"
|
|
gitea_runner_home: "{{ gitea_runner_base_home }}/{{ gitea_runner_service_user }}"
|
|
|
|
# Base paths (instance-scoped via gitea_runner_name)
|
|
gitea_runner_base_data_dir: "/var/lib/gitea-runner"
|
|
gitea_runner_base_config_dir: "/etc/gitea-runner"
|
|
gitea_runner_data_dir: "{{ gitea_runner_base_data_dir }}/{{ gitea_runner_name }}"
|
|
gitea_runner_config_dir: "{{ gitea_runner_base_config_dir }}/{{ gitea_runner_name }}"
|
|
gitea_runner_binary_path: "/usr/local/bin/gitea_runner"
|
|
|
|
# Prune configuration
|
|
gitea_runner_prune_until: "24h"
|
|
# Every 6 hours — daily is insufficient for CI runners that build dozens
|
|
# of images per day. Accumulation between daily runs can trigger Docker
|
|
# daemon instability (containerd snapshotter GC holds locks, blocking
|
|
# container operations).
|
|
gitea_runner_prune_schedule: "*-*-* 00/6:00:00"
|
|
gitea_runner_prune_label: "gitea-runner=true"
|
|
|
|
# Service configuration
|
|
gitea_runner_service_restart_sec: "5"
|
|
|
|
# Health check configuration
|
|
# 2min interval — catches hung daemons before multiple CI jobs fail between checks.
|
|
# The previous 5min interval was too coarse: a stuck daemon could fail 3+ molecule
|
|
# jobs in the window between healthcheck runs.
|
|
gitea_runner_healthcheck_interval: "2min"
|
|
gitea_runner_healthcheck_boot_delay: "2min"
|
|
gitea_runner_healthcheck_disk_threshold: 75
|
|
# When disk reaches this level, prune EVERYTHING (no until-filter) — the
|
|
# runner is dangerously full and the gentle until=1h prune isn't enough.
|
|
# This removes all stopped containers and unused images regardless of age.
|
|
gitea_runner_healthcheck_disk_critical: 80
|
|
gitea_runner_healthcheck_script_path: "{{ gitea_runner_config_dir }}/healthcheck.sh"
|
|
|
|
# Auto-recovery: when the healthcheck detects an unregistered runner, it
|
|
# can automatically re-register if a Gitea API token is provided.
|
|
# The token needs admin or org-level access to fetch registration tokens.
|
|
# Stored in a file readable by the runner user (mode 0400).
|
|
# Set to empty string to disable auto-recovery (manual re-registration required).
|
|
gitea_runner_auto_recover_api_token: ""
|
|
|
|
# Cooldown file to prevent auto-recovery loops (e.g., if Gitea is down).
|
|
# The healthcheck writes a timestamp to this file after a re-registration
|
|
# attempt and skips further attempts for the cooldown period.
|
|
gitea_runner_auto_recover_cooldown_sec: 300
|
|
|
|
# Docker daemon resilience settings (applied to daemon.json).
|
|
# live-restore: containers survive daemon restarts — prevents stuck container
|
|
# states when the healthcheck restarts a hung daemon.
|
|
# shutdown-timeout: grace period (seconds) for containers to stop on daemon
|
|
# shutdown/restart. Default 15s is too short for DinD containers with nested
|
|
# processes (molecule tests). 30s gives SIGTERM time to propagate.
|
|
# max-concurrent-downloads/uploads: limits parallel transfers to reduce daemon
|
|
# memory pressure when multiple CI jobs pull images simultaneously.
|
|
# default-ulimits: prevents FD exhaustion in container processes.
|
|
gitea_runner_docker_live_restore: true
|
|
gitea_runner_docker_shutdown_timeout: 30
|
|
gitea_runner_docker_max_concurrent_downloads: 3
|
|
gitea_runner_docker_max_concurrent_uploads: 3
|
|
gitea_runner_docker_default_nofile: 65536
|
|
|
|
# Admin token for runner deregistration via Gitea API.
|
|
# If not set, falls back to registration_token (which likely lacks admin scope).
|
|
# Set this to a token with admin scope to enable automatic runner cleanup on removal.
|
|
gitea_runner_admin_token: ""
|
|
|
|
# Removal defaults
|
|
gitea_runner_remove_systemd_template: true
|
|
gitea_runner_remove_user: true
|
|
|
|
# Runner configuration
|
|
gitea_runner_log_level: "info"
|
|
gitea_runner_container_label: "gitea-runner=true"
|
|
gitea_runner_file: ".runner"
|
|
|
|
# Containerd version pinning — Docker 28.x vendors containerd v2.1.x internally.
|
|
# containerd.io >= 2.3 ships a shim that returns a protobuf BootstrapResult which
|
|
# Docker 28.x's vendored containerd code cannot parse, causing:
|
|
# "failed to create TTRPC connection: unsupported protocol: \b\x03\x12Yunix"
|
|
# When Docker 29+ is installed (it vendors containerd 2.3+), this pin is not needed.
|
|
# Set to "" to skip the compatibility check and allow any containerd.io version.
|
|
gitea_runner_containerd_max_compatible_major: 2
|
|
gitea_runner_containerd_max_compatible_minor: 2
|
|
|
|
# Docker installation (for rootless dependencies)
|
|
gitea_runner_docker_gpg_key_path: "/etc/apt/keyrings/docker.gpg"
|
|
gitea_runner_docker_apt_arch: "{{ 'amd64' if ansible_facts['architecture'] == 'x86_64' else ansible_facts['architecture'] }}"
|
|
gitea_runner_docker_apt_source_line: >-
|
|
deb [arch={{ gitea_runner_docker_apt_arch }} signed-by={{ gitea_runner_docker_gpg_key_path }}]
|
|
https://download.docker.com/linux/{{ ansible_facts['distribution'] | lower }}
|
|
{{ ansible_facts['distribution_release'] }} stable
|
|
# Set to false in CI/molecule to skip rootless daemon startup (needs kernel userns)
|
|
gitea_runner_docker_rootless_setup: true
|
|
|
|
# Rootless Docker helper scripts (dockerd-rootless-setuptool.sh / dockerd-rootless.sh).
|
|
# Arch Linux's "docker" package does not ship these (unlike Debian's docker-ce-rootless-extras),
|
|
# and no official Arch package provides them. They are fetched from the upstream moby/moby
|
|
# "contrib/" directory at the git ref below. The scripts are stable bash wrappers that are
|
|
# version-agnostic with respect to the dockerd binary, so a pinned ref is safe.
|
|
gitea_runner_rootless_scripts_ref: "v28.5.1"
|
|
# Install dir MUST match the location of the "docker" / "dockerd" / "rootlesskit" binaries so
|
|
# that dockerd-rootless-setuptool.sh (which derives BIN from its own dirname) finds them co-located.
|
|
gitea_runner_rootless_scripts_install_dir: "/usr/bin"
|
|
|
|
# Rootless Docker network driver: "slirp4netns" (default) or "pasta" (IPv6 support)
|
|
# slirp4netns is the default because pasta has a TCP proxy bug that sends RST
|
|
# packets with wrong sequence numbers, breaking TCP connections from Docker
|
|
# containers to external hosts. slirp4netns doesn't have IPv6 support.
|
|
# See: https://bugs.passt.top/show_bug.cgi?id=52
|
|
gitea_runner_docker_rootless_net_driver: "slirp4netns"
|
|
|
|
# IPv6 subnet for rootless Docker containers (ULA range, not routable on internet)
|
|
gitea_runner_docker_ipv6_cidr: "fd00:dead:beef::/48"
|
|
|
|
# Pre-pull Docker images that CI runners need (avoids pulling on every CI run).
|
|
# The runner container image (ci-full) is large (~3.3GB) and the healthcheck's
|
|
# disk-space prune only removes dangling images, so pre-pulled tagged images persist.
|
|
# Set to [] to skip pre-pulling. Images are pulled as the runner user via rootless Docker.
|
|
gitea_runner_pre_pull_images: []
|