Incident 2026-07-23: an uncapped nuxt generate (3.5G RSS) on pi1 starved the k3s control-plane and traefik (load >150, no swap, no OOM-kill) — every *.arcodange.lab endpoint went dark, Gitea included, while Gitea itself was healthy on pi2. Job containers are spawned via the host docker socket, so cgroup caps on the job container are the only guardrail. Applied live on pi1+pi3 via 03_cicd.yml on 2026-07-24 (both runners re-registered; pi3's runner was down and is back in service). Co-Authored-By: Claude Fable 5 <[email protected]>
163 lines
9.0 KiB
YAML
163 lines
9.0 KiB
YAML
---
|
|
|
|
- name: Deploy Gitea Action
|
|
hosts: raspberries:&local:!gitea # do not deploy on machine with gitea instance
|
|
|
|
roles:
|
|
- arcodange.factory.gitea_token # generate gitea_api_token used to replace generated token with set name if required
|
|
|
|
tasks:
|
|
|
|
- name: Fetch Gitea Token for Action Runner registration
|
|
delegate_to: "{{ groups.gitea[0] }}"
|
|
delegate_facts: false
|
|
ansible.builtin.command:
|
|
docker exec gitea su git -c "gitea actions generate-runner-token"
|
|
register: gitea_runner_token_cmd
|
|
|
|
- name: Deploy Gitea Action Docker Compose configuration
|
|
include_role:
|
|
name: arcodange.factory.deploy_docker_compose
|
|
vars:
|
|
dockercompose_content:
|
|
name: arcodange_factory_gitea_action
|
|
services:
|
|
gitea_action:
|
|
image: gitea/act_runner:latest
|
|
container_name: gitea_action
|
|
restart: always
|
|
environment:
|
|
CONFIG_FILE: /config.yaml
|
|
GITEA_INSTANCE_URL: >-
|
|
http://{{ hostvars[groups.gitea[0]].ansible_host }}:3000
|
|
GITEA_RUNNER_REGISTRATION_TOKEN: "{{ gitea_runner_token_cmd.stdout }}"
|
|
GITEA_RUNNER_NAME: arcodange_global_runner_{{ inventory_hostname }}
|
|
GITEA_RUNNER_LABELS: ubuntu-latest:docker://gitea.arcodange.lab/arcodange-org/runner-images:ubuntu-latest-ca,ubuntu-latest-ca:docker://gitea.arcodange.lab/arcodange-org/runner-images:ubuntu-latest-ca
|
|
ports:
|
|
- "43707:43707"
|
|
networks:
|
|
- gitea_action_network
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
- /etc/timezone:/etc/timezone:ro
|
|
- /etc/localtime:/etc/localtime:ro
|
|
- /etc/ssl/certs:/etc/ssl/certs:ro
|
|
- /usr/local/share/ca-certificates/:/usr/local/share/ca-certificates/:ro
|
|
- /mnt/arcodange/gitea-runner-cache:/home/git/.cache/actcache
|
|
- /mnt/arcodange/gitea-runner-act:/root/.cache/act
|
|
configs:
|
|
- config.yaml
|
|
networks:
|
|
gitea_action_network:
|
|
name: gitea_action_network
|
|
configs:
|
|
config.yaml:
|
|
content: |
|
|
# You don't have to copy this file to your instance,
|
|
# just run `./act_runner generate-config > config.yaml` to generate a config file.
|
|
|
|
#log:
|
|
# # The level of logging, can be trace, debug, info, warn, error, fatal
|
|
# level: info
|
|
|
|
runner:
|
|
# Where to store the registration result.
|
|
file: .runner
|
|
# Execute how many tasks concurrently at the same time.
|
|
# 1 seul job à la fois : les hôtes (8 Go, control-plane k3s sur pi1) ne survivent pas à 2 builds lourds simultanés.
|
|
capacity: 1
|
|
# Extra environment variables to run jobs.
|
|
envs:
|
|
A_TEST_ENV_NAME_1: a_test_env_value_1
|
|
A_TEST_ENV_NAME_2: a_test_env_value_2
|
|
# Extra environment variables to run jobs from a file.
|
|
# It will be ignored if it's empty or the file doesn't exist.
|
|
env_file: .env
|
|
# The timeout for a job to be finished.
|
|
# Please note that the Gitea instance also has a timeout (3h by default) for the job.
|
|
# So the job could be stopped by the Gitea instance if it's timeout is shorter than this.
|
|
timeout: 3h
|
|
# Whether skip verifying the TLS certificate of the Gitea instance.
|
|
insecure: true
|
|
# The timeout for fetching the job from the Gitea instance.
|
|
fetch_timeout: 5s
|
|
# The interval for fetching the job from the Gitea instance.
|
|
fetch_interval: 2s
|
|
# The labels of a runner are used to determine which jobs the runner can run, and how to run them.
|
|
# Like: "macos-arm64:host" or "ubuntu-latest:docker://gitea/runner-images:ubuntu-latest"
|
|
# Find more images provided by Gitea at https://gitea.com/gitea/runner-images .
|
|
# If it's empty when registering, it will ask for inputting labels.
|
|
# If it's empty when execute `daemon`, will use labels in `.runner` file.
|
|
labels:
|
|
- "ubuntu-latest:docker://gitea.arcodange.lab/arcodange-org/runner-images:ubuntu-latest-ca"
|
|
- "ubuntu-latest-ca:docker://gitea.arcodange.lab/arcodange-org/runner-images:ubuntu-latest-ca"
|
|
|
|
cache:
|
|
# Enable cache server to use actions/cache.
|
|
enabled: true
|
|
# The directory to store the cache data.
|
|
# If it's empty, the cache data will be stored in $HOME/.cache/actcache.
|
|
dir: "/home/git/.cache/actcache"
|
|
# The host of the cache server.
|
|
# It's not for the address to listen, but the address to connect from job containers.
|
|
# So 0.0.0.0 is a bad choice, leave it empty to detect automatically.
|
|
host: "{{ ansible_default_ipv4.address }}"
|
|
# The port of the cache server.
|
|
# 0 means to use a random available port.
|
|
port: 43707
|
|
# The external cache server URL. Valid only when enable is true.
|
|
# If it's specified, act_runner will use this URL as the ACTIONS_CACHE_URL rather than start a server by itself.
|
|
# The URL should generally end with "/".
|
|
external_server: ""
|
|
|
|
container:
|
|
# Specifies the network to which the container will connect.
|
|
# Could be host, bridge or the name of a custom network.
|
|
# If it's empty, act_runner will create a network automatically.
|
|
network: ""
|
|
# Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker).
|
|
privileged: false
|
|
# And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway).
|
|
# Plafonds durs : un build ne doit jamais pouvoir affamer l'hôte (incident 2026-07-23 :
|
|
# nuxt generate à 3,5 Go RSS sur pi1 → load 150, ingress+API k3s morts → gitea.arcodange.lab injoignable).
|
|
options: "--memory=3g --memory-swap=3g --cpus=2 --pids-limit=512"
|
|
# The parent directory of a job's working directory.
|
|
# NOTE: There is no need to add the first '/' of the path as act_runner will add it automatically.
|
|
# If the path starts with '/', the '/' will be trimmed.
|
|
# For example, if the parent directory is /path/to/my/dir, workdir_parent should be path/to/my/dir
|
|
# If it's empty, /workspace will be used.
|
|
workdir_parent:
|
|
# Volumes (including bind mounts) can be mounted to containers. Glob syntax is supported, see https://github.com/gobwas/glob
|
|
# You can specify multiple volumes. If the sequence is empty, no volumes can be mounted.
|
|
# For example, if you only allow containers to mount the `data` volume and all the json files in `/src`, you should change the config to:
|
|
# valid_volumes:
|
|
# - data
|
|
# - /src/*.json
|
|
# If you want to allow any volume, please use the following configuration:
|
|
# valid_volumes:
|
|
# - '**'
|
|
valid_volumes: []
|
|
# overrides the docker client host with the specified one.
|
|
# If it's empty, act_runner will find an available docker host automatically.
|
|
# If it's "-", act_runner will find an available docker host automatically, but the docker host won't be mounted to the job containers and service containers.
|
|
# If it's not empty or "-", the specified docker host will be used. An error will be returned if it doesn't work.
|
|
docker_host: ""
|
|
# Pull docker image(s) even if already present
|
|
force_pull: false
|
|
# Rebuild docker image(s) even if already present
|
|
force_rebuild: false
|
|
|
|
host:
|
|
# The parent directory of a job's working directory.
|
|
# If it's empty, $HOME/.cache/act/ will be used.
|
|
workdir_parent:
|
|
- name: Deploy Gitea Action with Docker Compose
|
|
community.docker.docker_compose_v2:
|
|
project_src: "/home/pi/arcodange/docker_composes/arcodange_factory_gitea_action"
|
|
pull: missing
|
|
state: "{{ docker_compose_down_then_up }}"
|
|
register: deploy_result
|
|
loop: ["absent", "present"]
|
|
loop_control:
|
|
loop_var: docker_compose_down_then_up
|