--- apiVersion: v1 kind: ConfigMap metadata: name: gitea-act-runner-config namespace: gitea data: config.yaml: | log: level: debug cache: enabled: false container: valid_volumes: - /certs options: | --add-host=docker:host-gateway -v /certs:/certs -e "DOCKER_HOST=tcp://docker:2376/" -e "DOCKER_TLS_VERIFY=1" -e "DOCKER_CERT_PATH=/certs/client" --- apiVersion: v1 kind: ConfigMap metadata: name: gitea-docker-daemon-config namespace: gitea data: daemon.json: | { "insecure-registries": ["git.italiadatacenter.com"] } --- apiVersion: apps/v1 kind: StatefulSet metadata: name: gitea-act-runner-dind namespace: gitea spec: replicas: 1 selector: matchLabels: app: gitea-act-runner-dind serviceName: gitea-act-runner-dind template: metadata: labels: app: gitea-act-runner-dind spec: initContainers: - name: gitea-act-runner-init image: gitea/gitea:1.22.1-rootless # Creates temporary gitea instance, generates token and saves it to act-runner command: - bash - -exc - | sed '/[server]/a LOCAL_ROOT_URL = https://git.italiadatacenter.com/' /data/gitea/conf/app.ini > /tmp/app.ini; test -e /act-runner-data/.runner || gitea actions generate-runner-token > /act-runner-data/token env: - name: GITEA_APP_INI value: /tmp/app.ini - name: GITEA_CUSTOM value: /data/gitea - name: GITEA_WORK_DIR value: /data volumeMounts: - name: gitea-shared-storage mountPath: /data readOnly: true - name: gitea-act-runner-data mountPath: /act-runner-data containers: - name: runner image: gitea/act_runner:nightly # Container only for gitea, so we can choose the dind variant (rootless or not) image: gitea/act_runner:0.2.10 env: - name: DOCKER_HOST value: tcp://127.0.0.1:2376 - name: DOCKER_CERT_PATH value: /certs/client - name: DOCKER_TLS_VERIFY value: "1" - name: GITEA_RUNNER_REGISTRATION_TOKEN_FILE value: /data/token - name: CONFIG_FILE value: /config.yaml - name: GITEA_INSTANCE_URL value: https://git.italiadatacenter.com - name: CONFIG_FILE value: /actrunner/config.yaml volumeMounts: - name: gitea-act-runner-data mountPath: /data - name: docker-certs mountPath: /certs/client - name: runner-config mountPath: /actrunner ## Avoid subPath because it cannot be updated ## https://github.com/kubernetes/kubernetes/issues/50345 #mountPath: /actrunner/config.yaml #subPath: config.yaml - name: daemon ## Rootless works for simple cases, but not for docker buildx #image = "docker:27.1.2-dind-rootless" image = "docker:27.1.2-dind" env: - name: DOCKER_TLS_CERTDIR value: /certs - name: DOCKER_HOST value: tcp://127.0.0.1:2376 - name: DOCKER_TLS_VERIFY value: 1 securityContext: privileged: true volumeMounts: - name: docker-certs mountPath: /certs/client - name: gitea-docker-daemon-config ## This one for rootless variant #mountPath: /home/rootless/.config/docker ## This other for regular variant mountPath: /etc/docker ## Avoid subPath because it cannot be updated ## https://github.com/kubernetes/kubernetes/issues/50345 #mountPath: /home/rootless/.config/docker/daemon.json #mountPath: /etc/docker/daemon.json #subPath: daemon.json volumes: - name: docker-certs emptyDir: {} - name: gitea-act-runner-config configMap: name: gitea-act-runner-config - name: gitea-act-runner-data persistentVolumeClaim: claimName: gitea-act-runner - name: gitea-shared-storage persistentVolumeClaim: claimName: gitea-shared-storage readOnly: true - name: gitea-docker-daemon-config configMap: name: gitea-docker-daemon-config volumeClaimTemplates: - metadata: name: gitea-act-runner-data namespace: gitea spec: accessModes: - ReadWriteOnce storageClassName: standard resources: requests: storage: 1Gi