thermograph/infra/deploy/forgejo/ci-runner/Dockerfile
Emi Griffith 3678f643ef
All checks were successful
PR build (required check) / changes (pull_request) Successful in 6s
secrets-guard / encrypted (pull_request) Successful in 7s
shell-lint / shellcheck (pull_request) Successful in 7s
PR build (required check) / build-backend (pull_request) Has been skipped
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Has been skipped
PR build (required check) / gate (pull_request) Successful in 2s
infra/forgejo: fix ci-runner — node is required by actions/checkout
v1 dropped node:20-bookworm for a Node-free Debian base, on the wrong
assumption that nothing in CI needs Node since the frontend is Go now.
Forgejo's runner executes actions/checkout@v4 as `node dist/index.js`
inside the job container regardless of what the workflow itself runs,
so every job's checkout step failed. Caught from the live run within
a minute; runner was reverted to node:20-bookworm immediately.

v2 keeps the node:20-bookworm base and only adds docker-ce-cli +
docker-buildx-plugin on top, preserving the actual fix (BuildKit
instead of the classic builder, no per-job docker.io install) without
removing a hard dependency.
2026-07-24 11:47:49 -07:00

46 lines
2.6 KiB
Docker

# Job-container image for the LAN Forgejo Actions runner's `docker`-labeled
# jobs (see ../register-lan-runner.sh) — used by every backend/frontend
# build-push, deploy, and validation workflow that needs `docker build`.
#
# Base stays node:20-bookworm, NOT a Node-free slim image (v1 of this file
# tried that and broke every job: `actions/checkout@v4` is a JS action that
# Forgejo's runner execs as `node dist/index.js` *inside the job container*,
# so a Node runtime is a hard requirement regardless of whether the workflow
# itself uses npm/node — this repo's own workflows don't, but the checkout
# step every one of them starts with does).
#
# What this image actually fixes: every workflow using the `docker` label
# currently re-provisions the Docker CLI on each run via `apt-get install
# docker.io` — that step costs ~15-20s per job and, more importantly,
# installs the CLASSIC Docker builder rather than BuildKit, which mishandles
# `COPY --chown=<name>` group resolution on images without a matching system
# group (a real bug hit during the frontend Go rewrite). Installing
# docker-buildx-plugin here makes BuildKit the default, closing that bug
# class, and skips the per-job install entirely.
#
# Build/push (manual — see ../README.md for when to rebuild):
# docker build -t git.thermograph.org/emi/thermograph/ci-runner:vN \
# infra/deploy/forgejo/ci-runner
# docker push git.thermograph.org/emi/thermograph/ci-runner:vN
#
# Cutting over the live runner to a new tag means editing the `labels` array
# in ~/forgejo-runner/.runner on the runner host directly (same runner
# id/token, no re-registration needed) and updating register-lan-runner.sh's
# LABELS default so future re-provisioning picks it up too.
FROM node:20-bookworm
RUN apt-get update -qq \
&& apt-get install -y -qq --no-install-recommends \
ca-certificates curl gnupg git python3 python3-yaml \
&& install -m 0755 -d /etc/apt/keyrings \
&& curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc \
&& chmod a+r /etc/apt/keyrings/docker.asc \
&& echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian bookworm stable" \
> /etc/apt/sources.list.d/docker.list \
&& apt-get update -qq \
&& apt-get install -y -qq --no-install-recommends docker-ce-cli docker-buildx-plugin \
&& rm -rf /var/lib/apt/lists/* /etc/apt/sources.list.d/docker.list
RUN docker --version && docker buildx version && git --version \
&& node --version \
&& python3 -c "import yaml; print('PyYAML', yaml.__version__)"