Skip to content
94 linesCodeBlameRaw
1# Rebuilds the base image of g1t's sandboxes (services/runner/base/Dockerfile:
2# the OS, toolchains and the Claude Code CLI), pushes it to Cloudflare's
3# registry, and opens a pull request that records it in
4# services/runner/base.json. Merging that pull request is what rolls it out:
5# the next deploy builds the runner's image on it, in seconds.
6#
7# Weekly, for security updates and new stable toolchains; when the base's
8# folder changes on main (a change that forgot to rebuild it); and by hand.
9#
10# It needs Docker, which g1t's own sandboxes do not have, so it runs on a
11# self-hosted runner with the `docker` label. Until one is registered, run
12# the same thing by hand on a machine with Docker:
13#
14# node scripts/deploy.mjs build-base
15#
16# and commit services/runner/base.json. docs/DEPLOYING.md explains both.
17name: Runner base image
18
19on:
20 schedule:
21 - cron: "17 6 * * 1"
22 push:
23 branches: [main]
24 paths:
25 - services/runner/base/**
26 workflow_dispatch:
27 inputs:
28 no_cache:
29 description: "Build every layer again, ignoring the previous base"
30 type: boolean
31 default: false
32
33# Its token pushes the branch with base.json and opens the pull request.
34# What a job's token does starts no workflows, so that pull request's
35# checks start when someone pushes to it or runs CI by hand.
36permissions:
37 contents: write
38 pull-requests: write
39
40concurrency:
41 group: runner-base
42 cancel-in-progress: false
43
44env:
45 CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
46 WRANGLER_SEND_METRICS: "false"
47
48jobs:
49 build:
50 name: Build and push the base
51 runs-on: [self-hosted, docker]
52 environment: production
53 timeout-minutes: 60
54 steps:
55 - uses: actions/checkout@v5
56 - name: Install Wrangler
57 run: npm ci --workspaces=false --no-audit --no-fund
58 - name: Build and push
59 env:
60 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
61 CI: "true"
62 NO_CACHE: ${{ inputs.no_cache }}
63 run: |
64 args=()
65 if [ "$NO_CACHE" = "true" ]; then args+=(--no-cache); fi
66 node scripts/deploy.mjs build-base "${args[@]}"
67 # The runner's own image on the new base, so the deploy after the
68 # merge finds it in the registry instead of building it.
69 - name: Build and push the runner's image on it
70 env:
71 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
72 CI: "true"
73 run: node scripts/deploy.mjs image
74 - name: Open a pull request with base.json
75 env:
76 G1T_TOKEN: ${{ github.token }}
77 REPO: ${{ github.repository }}
78 run: |
79 if git diff --quiet -- services/runner/base.json; then
80 echo "The base is unchanged."
81 exit 0
82 fi
83 branch="runner-base/$(date -u +%Y%m%d-%H%M)"
84 git config user.name "g1t"
85 git config user.email "g1t@users.noreply.g1t.sh"
86 git checkout -b "$branch"
87 git add services/runner/base.json
88 git commit -m "A new base image for g1t's sandboxes"
89 git push origin "$branch"
90 tag=$(node -e 'console.log(require("./services/runner/base.json").image.split(":").pop())')
91 body=$(node -e 'const b=require("./services/runner/base.json"); console.log("Built and pushed by the Runner base image workflow.\n\n| | |\n| --- | --- |\n" + Object.entries(b.versions).map(([k,v]) => `| ${k} | ${v} |`).join("\n") + `\n| size | ${(b.size_bytes/1e9).toFixed(2)} GB unpacked |`)')
92 curl -fsS -X POST "https://api.g1t.sh/repos/$REPO/pulls" \
93 -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \
94 -d "$(node -e 'console.log(JSON.stringify({ title: `Runner base image ${process.argv[1]}`, branch: process.argv[2], body: process.argv[3] }))' "$tag" "$branch" "$body")"