feat(06-03): add act_runner compose definition and CI/CD setup runbook
- docker-compose.ci.yml with act_runner service (ephemeral mode, Docker socket mount) - docs/ci-cd-setup.md runbook covering Gitea remote, runner setup, secrets, security - Registration token referenced from environment, never hardcoded (T-06-08)
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# CI/CD Infrastructure - act_runner for Gitea Actions
|
||||
#
|
||||
# This compose file documents the act_runner setup pattern for Tessera CI/CD.
|
||||
# The runner executes Gitea Actions workflow jobs inside Docker containers.
|
||||
#
|
||||
# Usage:
|
||||
# docker compose -f docker-compose.ci.yml up -d
|
||||
#
|
||||
# Prerequisites:
|
||||
# - Gitea instance running with Actions enabled
|
||||
# - Runner registration token from Gitea (Admin/Repo -> Actions -> Runners)
|
||||
# - Set GITEA_INSTANCE_URL and GITEA_RUNNER_REGISTRATION_TOKEN in .env or environment
|
||||
|
||||
services:
|
||||
act_runner:
|
||||
image: gitea/act_runner:latest
|
||||
container_name: tessera-runner
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
GITEA_INSTANCE_URL: ${GITEA_INSTANCE_URL:?GITEA_INSTANCE_URL must be set}
|
||||
GITEA_RUNNER_REGISTRATION_TOKEN: ${GITEA_RUNNER_REGISTRATION_TOKEN:?Token must be set}
|
||||
GITEA_RUNNER_NAME: tessera-runner
|
||||
GITEA_RUNNER_LABELS: "ubuntu-latest:docker://node:24,ubuntu-22.04:docker://node:24,ubuntu-20.04:docker://node:24"
|
||||
GITEA_RUNNER_EPHEMERAL: "1"
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- runner_data:/data
|
||||
# Security note: Docker socket mount grants the runner control over host
|
||||
# containers. This is acceptable for internal-only CI where only Claude
|
||||
# pushes (D-11). Ephemeral mode (GITEA_RUNNER_EPHEMERAL=1) revokes
|
||||
# runner credentials after each job for additional security.
|
||||
|
||||
volumes:
|
||||
runner_data:
|
||||
Reference in New Issue
Block a user