The runner's image is g1t.sh/flagon-io/g1t-runner, on g1t's own registry, public
g1t-runner 0.1.0 is pushed there for linux/amd64 and linux/arm64 (one index, tags 0.1.0 and latest) and pulls without signing in. The release workflow's image job logs in with G1T_TOKEN and pushes there; the Docker Hub variables and secret are gone. The self-hosted runners guide, the runners page's docker run line and DEPLOYING.md name it.
5 files+12−180/5 viewed
| 85 | 85 | name: linux-binaries | |
| 86 | 86 | path: release | |
| 87 | 87 | - name: Build and push for amd64 and arm64 | |
| 88 | + | # To g1t's own registry, where flagon-io keeps it public. | |
| 88 | 89 | env: | |
| 89 | − | REGISTRY_USER: ${{ vars.RUNNER_IMAGE_REGISTRY_USER }} | |
| 90 | − | REGISTRY_TOKEN: ${{ secrets.RUNNER_IMAGE_REGISTRY_TOKEN }} | |
| 91 | − | IMAGE: ${{ vars.RUNNER_IMAGE }} | |
| 90 | + | IMAGE: g1t.sh/flagon-io/g1t-runner | |
| 92 | 91 | run: | | |
| 93 | 92 | version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)" | |
| 94 | − | echo "$REGISTRY_TOKEN" | docker login --username "$REGISTRY_USER" --password-stdin | |
| 93 | + | echo "${{ secrets.G1T_TOKEN }}" | docker login g1t.sh -u g1t --password-stdin | |
| 95 | 94 | for arch in amd64 arm64; do | |
| 96 | 95 | mkdir -p "context-$arch" | |
| 97 | 96 | cp deploy/runner/Dockerfile "context-$arch/" |
| 226 | 226 | ||
| 227 | 227 | ## Docker and Kubernetes | |
| 228 | 228 | ||
| 229 | − | **The `flagonio/g1t-runner` image is not published yet.** Until it is, run | |
| 230 | − | the binary on the machine, or build the image from | |
| 231 | − | [`deploy/runner/Dockerfile`](https://g1t.sh/flagon-io/g1t/blob/main/deploy/runner/Dockerfile) | |
| 232 | − | with the Linux binary beside it. | |
| 233 | − | ||
| 234 | 229 | The runner's image runs `register-and-run`, which registers once and then | |
| 235 | 230 | runs. Each option can also come from `G1T_RUNNER_<OPTION>` in the | |
| 236 | 231 | environment, such as `G1T_RUNNER_TOKEN` and `G1T_RUNNER_LABELS`, so a | |
| 240 | 235 | docker run -d --name g1t-runner --restart unless-stopped \ | |
| 241 | 236 | -v /var/run/docker.sock:/var/run/docker.sock \ | |
| 242 | 237 | -v g1t-runner:/data -e G1T_RUNNER_DIR=/data \ | |
| 243 | − | flagonio/g1t-runner register-and-run --url https://g1t.sh --token g1trt_… | |
| 238 | + | g1t.sh/flagon-io/g1t-runner register-and-run --url https://g1t.sh --token g1trt_… | |
| 244 | 239 | ``` | |
| 245 | 240 | ||
| 246 | 241 | With the host's Docker socket, each job runs in a sibling container. | |
| 266 | 261 | spec: | |
| 267 | 262 | containers: | |
| 268 | 263 | - name: runner | |
| 269 | − | image: flagonio/g1t-runner | |
| 264 | + | image: g1t.sh/flagon-io/g1t-runner | |
| 270 | 265 | command: ["sh", "-c"] | |
| 271 | 266 | args: | |
| 272 | 267 | - | |
| 8 | 8 | # docker run -d --restart unless-stopped \ | |
| 9 | 9 | # -v /var/run/docker.sock:/var/run/docker.sock -v g1t-runner:/data \ | |
| 10 | 10 | # -e G1T_RUNNER_URL=https://g1t.sh -e G1T_RUNNER_TOKEN=g1trt_… \ | |
| 11 | − | # flagonio/g1t-runner | |
| 11 | + | # g1t.sh/flagon-io/g1t-runner | |
| 12 | 12 | # | |
| 13 | 13 | # Build context: a folder holding `g1t-runner` for the image's platform, | |
| 14 | 14 | # the static Linux build that scripts/runner-release.mjs makes (or |
| 550 | 550 | | The tool | `scripts/runner-release.mjs` (`keygen`, `build`, `sign`, `verify`, `publish`) | | |
| 551 | 551 | | The workflow | `.g1t/workflows/runner-release.yml`, on a tag `runner-v<version>` or by hand | | |
| 552 | 552 | | Where it is published | The R2 bucket `g1t-downloads`, served by the site at `g1t.sh/downloads/runner/<version>/<file>` and `/latest/<file>` (`apps/web/app/routes/downloads-runner.ts`) | | |
| 553 | − | | Its image | `deploy/runner/Dockerfile`, pushed as `RUNNER_IMAGE` (`flagonio/g1t-runner`) for amd64 and arm64 | | |
| 553 | + | | Its image | `deploy/runner/Dockerfile`, pushed to `g1t.sh/flagon-io/g1t-runner` (public) for amd64 and arm64 | | |
| 554 | 554 | ||
| 555 | 555 | A release is five binaries (Linux x64 and arm64, both static musl; macOS | |
| 556 | 556 | x64 and arm64; Windows x64), `SHA256SUMS`, and `manifest.json`; | |
| 568 | 568 | updates itself. | |
| 569 | 569 | 2. `npx wrangler r2 bucket create g1t-downloads`, and deploy the site so it | |
| 570 | 570 | has the `DOWNLOADS` binding. | |
| 571 | − | 3. Set the variables `RUNNER_IMAGE` (the image's name in a public registry), | |
| 572 | − | `RUNNER_IMAGE_REGISTRY_USER` and the secret `RUNNER_IMAGE_REGISTRY_TOKEN`, | |
| 573 | − | and `RUNNER_AGENT_IMAGE` (a public copy of `g1t-runner-base`, the image | |
| 574 | − | agent work runs in on customers' runners). | |
| 571 | + | 3. The image job pushes to g1t's own registry with the run's `G1T_TOKEN`; | |
| 572 | + | the `g1t-runner` package in flagon-io is public. Set the variable | |
| 573 | + | `RUNNER_AGENT_IMAGE` (a public copy of `g1t-runner-base`, the image agent | |
| 574 | + | work runs in on customers' runners) once there is one. | |
| 575 | 575 | 4. Register a self-hosted runner with the `docker` label for the image job. | |
| 576 | 576 | ||
| 577 | 577 | Each release: |
| 97 | 97 | * The runner's container image: `g1t-runner` and the Docker CLI, for | |
| 98 | 98 | * running it in Docker or Kubernetes. Published with each release. | |
| 99 | 99 | */ | |
| 100 | − | export const RUNNER_IMAGE = "flagonio/g1t-runner"; | |
| 100 | + | export const RUNNER_IMAGE = "g1t.sh/flagon-io/g1t-runner"; | |
| 101 | 101 | ||
| 102 | 102 | /** Where the runner binary is published: `g1t.sh/downloads/runner/<version>/<file>`. */ | |
| 103 | 103 | export const RUNNER_DOWNLOADS = "https://g1t.sh/downloads/runner"; |