Compare commits

...
61 Commits
Author SHA1 Message Date
Marcus Young 000e4c0e03 [Automated 🤖 ] Bump to version 2.299.1 2022-11-02 20:06:22 -04:00
Marcus Young ccad12634b [Automated 🤖 ] Bump to version 2.299.0 2022-11-02 15:10:20 -04:00
Marcus Young adff5c97f3 Sid is now bookworm in lsb_release -cs 2022-10-31 10:03:36 -05:00
Marcus Young e44424c8b9 [Automated 🤖 ] Bump to version 2.298.2 2022-10-04 11:52:15 -05:00
Marcus Young f60efe84a9 [Automated 🤖 ] Bump to version 2.298.1 2022-10-04 10:36:00 -05:00
Marcus Young e3f7748492 [Automated 🤖 ] Bump to version 2.298.0 2022-10-04 07:27:21 -05:00
myoung34andGitHub 0f2883e196 Merge pull request #250 from chantra/fix_ephemeral
Fix ephemeral support
2022-10-02 08:31:55 -05:00
chantra 2fc9c11800 Fix ephemeral support
The quotes added in 08608da938 cause
`ephemeral` to evaluate as false when `DISABLE_AUTO_UPDATE` was not set.

This is explained in details in #249. This diff changes the logic to use
an array where extra parameters are being added.
When calling config.sh, the array is expanded.

Testing:
../self_hosted_runner.env contains
```
EPHEMERAL=true
```

Before: https://gist.github.com/chantra/443dfaa60d964d938bcb1c020781ca00
we can see multiple jobs got scheduled on the runner

After: https://gist.github.com/chantra/061dc471c63964c01a2e3733a53bd3ec
we can see that when the job finished, the container shutdown.

After with DISABLE_AUTO_UPDATE set: https://gist.github.com/chantra/df0102c7340b8f6bfd458ec56d9fa29c

Also adding `set -x` before the call to `config.sh` revealed the
arguments were correctly added.

Fixes #249
2022-09-30 14:49:04 -07:00
Marcus Young dafb91bfa3 Hotfix: more lenient sid to bullseye sub 2022-09-28 01:48:12 -05:00
Marcus Young c3c6a4e493 Fix ghcli installer by using API and not html parsing 2022-09-26 12:08:03 -05:00
Marcus Young 087e754f56 Fix permissions for release creation 2022-09-26 11:27:59 -05:00
Marcus Young 5b19b8dafa [Automated 🤖 ] Bump to version 2.297.0 2022-09-26 10:54:33 -05:00
Marcus Young f4ac990ab1 Port ghcr to latest build 2022-09-16 11:21:21 -05:00
Marcus Young a3bcbecef1 Force a latest release build 2022-09-16 11:14:02 -05:00
myoung34andGitHub 26245f5fb3 Merge pull request #245 from jkroepke/patch-1
Add ghcr.io as image mirror
2022-09-16 11:07:26 -05:00
Jan-Otto KröpkeandGitHub 5a85c6bc92 Add ghcr.io as image mirror 2022-09-16 08:27:22 +02:00
myoung34andGitHub e77cb92da3 Merge pull request #242 from myoung34/test_on_pr
Test on pr
2022-09-12 10:56:05 -05:00
Marcus Young 4b56b45734 Test on pr 2022-09-12 10:55:17 -05:00
myoung34andGitHub 0a895b9bbe Merge pull request #241 from myoung34/contributing
add contributing.md
2022-09-12 10:51:40 -05:00
Marcus Young b8d4598b96 add contributing.md 2022-09-12 10:48:14 -05:00
myoung34andGitHub 1d440a09e9 Merge pull request #240 from myoung34/chown_optimization
Chown optimization
2022-09-12 09:10:45 -05:00
Marcus Young 91be52197d remove unnecessary echo from workflow 2022-09-10 19:49:06 -05:00
Marcus Young 650aeba07c Fix typos 2022-09-10 19:32:13 -05:00
Marcus Young 395d555a98 Fix workflow name 2022-09-10 19:24:14 -05:00
Marcus Young 08608da938 shellcheck entrypoint.sh 2022-09-10 19:23:25 -05:00
Marcus Young 6b686411c7 Set up pre-commit 2022-09-10 19:21:17 -05:00
Marcus Young 325fe76ae4 Add chown optimization, set up shellcheck 2022-09-10 19:08:40 -05:00
Marcus Young a6a57d36ab [Automated 🤖 ] Bump to version 2.296.2 2022-09-08 12:46:35 -05:00
myoung34andGitHub de41bc7f8b Merge pull request #234 from Rumbles/master
Check to see if not running as root
2022-09-06 19:41:53 -05:00
myoung34andGitHub c253d823a6 Merge pull request #238 from nmalaguti/feature/github-cli-gpg-key-problem
Change gh cli install method to github releases
2022-09-06 19:24:04 -05:00
Nick Malaguti 214b75489b Change gh cli install method to github releases
The apt repo for the gh cli is broken due to an expired GPG key:
https://github.com/cli/cli/issues/6175

They want to retire the debian packaging altogether
https://github.com/cli/cli/issues/5941 and this is the recommended "long
term" solution
https://github.com/cli/cli/issues/6175#issuecomment-1235984381.

Adapted from https://github.com/cli/cli/issues/6175#issuecomment-1236264607

Fixes #236
2022-09-06 09:59:23 -04:00
James Stocker 2cffdf6b9a Update logic at the end as requested 2022-09-02 12:26:29 +02:00
a779a7f993 Update entrypoint.sh
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2022-09-02 12:23:31 +02:00
217117d3bc Update entrypoint.sh
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2022-09-02 12:23:22 +02:00
829c6ccd91 Update entrypoint.sh
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2022-09-02 12:23:16 +02:00
d414c3a388 Update entrypoint.sh
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2022-09-02 12:22:36 +02:00
Marcus Young 28cb729624 [Automated 🤖 ] Bump to version 2.296.1 2022-08-31 12:45:45 -05:00
James Stocker 733ff44be5 Check to see if not running as root
Change logic slightly avoid edge case
2022-08-30 10:22:25 +02:00
myoung34andGitHub 0f9d476978 Merge pull request #179 from jarrett-confrey/feat/add-gh-cli
feat: add github cli (gh)
2022-08-29 13:43:48 -05:00
jarrett-confrey 6d189b3bae feat: add github cli (gh) 2022-08-29 11:04:46 -07:00
Marcus Young 36d8efe0c3 [Automated 🤖 ] Bump to version 2.296.0 2022-08-23 09:57:53 -05:00
myoung34andGitHub 9afc3108fc Merge pull request #231 from nikeee/master
Add git-lfs to base image
2022-08-17 09:27:15 -05:00
cc396abd59 Update Dockerfile.base
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2022-08-17 16:19:18 +02:00
Niklas MollenhauerandGitHub e8ff100cc0 Add git-lfs to base image
Using the checkout action with `lfs: true` currently fails with the error: 
```
Unable to locate executable file: git-lfs.
```

See: https://git-lfs.github.com
2022-08-17 13:54:58 +02:00
Marcus Young 3d2c69648f [Automated 🤖 ] Bump to version 2.295.0 2022-08-10 09:54:08 -05:00
Marcus Young bc2c03d8c9 Dont run as non-root by default 2022-08-01 16:52:32 -05:00
myoung34andGitHub 51125e863e Merge pull request #226 from marcus-bcl/patch-1
Set ownership of /opt/hostedtoolcache
2022-07-27 09:47:23 -05:00
Marcus AspinandGitHub 18afadab14 Set ownership of /opt/hostedtoolcache 2022-07-27 15:45:02 +01:00
Marcus Young ab8b9d7e6b Fix sudoers for runner user 2022-07-27 07:53:48 -05:00
Marcus Young b9622cc4e7 Last changes for run-as runner user 2022-07-26 12:07:03 -05:00
myoung34andGitHub 62a7a5f10c Merge pull request #223 from marcus-bcl/master
Run as non-root user by default
2022-07-26 11:47:59 -05:00
Marcus AspinandGitHub 36f4ed430a Merge pull request #1 from myoung34/user_fixes
Swap USER directive for gosu for runtime permissions
2022-07-26 16:31:32 +01:00
Marcus Young a257b7ad38 Guarantee base dirs for -u runner 2022-07-26 10:27:48 -05:00
Marcus Young ba8c7f86a9 Move user add to docker base 2022-07-26 09:55:51 -05:00
Marcus Young cda2ba1fb4 Swap USER directive for gosu for runtime permissions 2022-07-26 09:44:02 -05:00
Marcus Aspin 8d4afae3d2 Move entrypoint after user-creation 2022-07-26 08:20:40 +01:00
myoung34andGitHub 96aaa5c17c Merge pull request #224 from Uzlopak/remove-awscliv2.zip
remove awscliv2.zip after unzipping
2022-07-25 12:25:43 -05:00
uzlopak 5e529f979a remove awscliv2.zip after unzipping 2022-07-25 10:59:53 +02:00
Marcus Aspin f6da106489 Add runner user to group 121, and mark as system user 2022-07-25 09:23:30 +01:00
Marcus Aspin d2a3df72e6 Run as non-root user by default 2022-07-22 15:05:33 +01:00
Marcus Young 133c12574c Remove temporary workaround for liblttng-ust0/1 https://github.com/actions/runner/issues/1584 2022-06-22 11:31:46 -05:00
13 changed files with 161 additions and 53 deletions
+2 -2
View File
@@ -38,7 +38,7 @@ jobs:
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
ubuntu_base_deploy:
runs-on: ubuntu-latest
strategy:
@@ -72,7 +72,7 @@ jobs:
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
debian_base_deploy:
runs-on: ubuntu-latest
strategy:
+29 -7
View File
@@ -10,6 +10,10 @@ on:
schedule:
- cron: '59 23 * * *'
permissions:
contents: read
packages: write
jobs:
ubuntu_latest_deploy:
runs-on: ubuntu-latest
@@ -23,12 +27,18 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Update Dockerfile FROM org
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -36,7 +46,7 @@ jobs:
file: Dockerfile
pull: true
push: true
tags: ${{ env.ORG }}/github-runner:latest
tags: ${{ env.ORG }}/github-runner:latest,ghcr.io/${{ github.repository }}:latest
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
@@ -59,10 +69,16 @@ jobs:
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.ubuntu-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:ubuntu-${{ matrix.release }}/" Dockerfile.ubuntu-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -70,7 +86,7 @@ jobs:
file: Dockerfile.ubuntu-${{ matrix.release }}
pull: true
push: true
tags: ${{env.ORG}}/github-runner:ubuntu-${{ matrix.release }}
tags: ${{env.ORG}}/github-runner:ubuntu-${{ matrix.release }},ghcr.io/${{ github.repository }}:ubuntu-${{ matrix.release }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
@@ -93,10 +109,16 @@ jobs:
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.debian-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:debian-${{ matrix.release }}/" Dockerfile.debian-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -104,7 +126,7 @@ jobs:
file: Dockerfile.debian-${{ matrix.release }}
pull: true
push: true
tags: ${{ env.ORG }}/github-runner:debian-${{ matrix.release }}
tags: ${{ env.ORG }}/github-runner:debian-${{ matrix.release }},ghcr.io/${{ github.repository }}:debian-${{ matrix.release }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
+29 -9
View File
@@ -4,6 +4,10 @@ on:
tags:
- '*'
permissions:
contents: write
packages: write
jobs:
create-release:
name: Create Release
@@ -37,12 +41,18 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Update Dockerfile FROM org
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -50,7 +60,7 @@ jobs:
file: Dockerfile
pull: true
push: true
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }}
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }},ghcr.io/${{ github.repository }}:${{ env.TAG }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
@@ -73,15 +83,19 @@ jobs:
uses: docker/setup-qemu-action@v1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Available platforms
run: echo ${{ steps.buildx.outputs.platforms }}
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.ubuntu-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:ubuntu-${{ matrix.release }}/" Dockerfile.ubuntu-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -89,7 +103,7 @@ jobs:
file: Dockerfile.ubuntu-${{ matrix.release }}
pull: true
push: true
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }}-ubuntu-${{ matrix.release }}
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }}-ubuntu-${{ matrix.release }},ghcr.io/${{ github.repository }}:${{ env.TAG }}-ubuntu-${{ matrix.release }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
@@ -115,10 +129,16 @@ jobs:
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.debian-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:debian-${{ matrix.release }}/" Dockerfile.debian-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v2
with:
@@ -126,7 +146,7 @@ jobs:
file: Dockerfile.debian-${{ matrix.release }}
pull: true
push: true
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }}-debian-${{ matrix.release }}
tags: ${{ env.ORG }}/github-runner:${{ env.TAG }}-debian-${{ matrix.release }},ghcr.io/${{ github.repository }}:${{ env.TAG }}-debian-${{ matrix.release }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
+15
View File
@@ -0,0 +1,15 @@
on:
pull_request:
name: "Trigger: Push action"
jobs:
tests:
name: Tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/setup-python@v3
- uses: pre-commit/action@v3.0.0
- name: Run ShellCheck
uses: ludeeus/action-shellcheck@master
+8 -4
View File
@@ -1,9 +1,13 @@
repos:
- repo: git://github.com/detailyang/pre-commit-shell
rev: 1.0.2
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.3.0
hooks:
- id: shell-lint
args: [-e, SC1008]
- id: check-yaml
- id: end-of-file-fixer
- id: trailing-whitespace
- id: check-case-conflict
- id: check-merge-conflict
- id: detect-private-key
- repo: https://github.com/stratasan/hadolint-pre-commit
rev: cdefcb096e520a6daa9552b1d4636f5f1e1729cd
hooks:
-3
View File
@@ -1,3 +0,0 @@
6/3/2021 (latest)
* `ORG_RUNNER` is now deprecated in favor of `RUNNER_SCOPE`. If you are currently using `ORG_RUNNER` please drop that in favor of `RUNNER_SCOPE="org"`
+17
View File
@@ -0,0 +1,17 @@
# Welcome to docker-github-actions-runner contributing guide <!-- omit in toc -->
Welcome!
## Code of conduct
Be kind, research before asking/contributing.
Please remember that my time is limited and my resources are as well. Solving "nuances" will likely require external contributions but I'm happy to help and guide.
### Issues
#### Create a new issue
If you spot an issue, [search if an issue already exists](https://docs.github.com/en/github/searching-for-information-on-github/searching-on-github/searching-issues-and-pull-requests#search-by-the-title-body-or-comments). If a related issue doesn't exist, you can open a new issue using a relevant issue.
Also use [the wiki](https://github.com/myoung34/docker-github-actions-runner/wiki) and contribute to it
+3 -5
View File
@@ -5,7 +5,7 @@ LABEL maintainer="myoung34@my.apsu.edu"
ENV AGENT_TOOLSDIRECTORY=/opt/hostedtoolcache
RUN mkdir -p /opt/hostedtoolcache
ARG GH_RUNNER_VERSION="2.294.0"
ARG GH_RUNNER_VERSION="2.299.1"
ARG TARGETPLATFORM
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
@@ -13,12 +13,10 @@ SHELL ["/bin/bash", "-o", "pipefail", "-c"]
WORKDIR /actions-runner
COPY install_actions.sh /actions-runner
# TODO: remove this terrible sed once
# https://github.com/actions/runner/pull/1585 is merged or similar
RUN chmod +x /actions-runner/install_actions.sh \
&& sed -i.bak 's/.\/bin\/installdependencies.sh/wget https:\/\/raw.githubusercontent.com\/myoung34\/runner\/main\/src\/Misc\/layoutbin\/installdependencies.sh -O .\/bin\/installdependencies.sh; bash .\/bin\/installdependencies.sh/g' /actions-runner/install_actions.sh \
&& /actions-runner/install_actions.sh ${GH_RUNNER_VERSION} ${TARGETPLATFORM} \
&& rm /actions-runner/install_actions.sh
&& rm /actions-runner/install_actions.sh \
&& chown runner /_work /actions-runner /opt/hostedtoolcache
COPY token.sh entrypoint.sh /
RUN chmod +x /token.sh /entrypoint.sh
+21 -11
View File
@@ -5,12 +5,13 @@ ARG DUMB_INIT_VERSION="1.2.2"
ARG GIT_CORE_PPA_KEY="A1715D88E1DF1F24"
ENV DOCKER_COMPOSE_VERSION="1.27.4"
ENV GIT_LFS_VERSION="3.2.0"
ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US.UTF-8
ENV LC_ALL=en_US.UTF-8
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
ENV DEBIAN_FRONTEND=noninteractive
# hadolint ignore=DL3003,DL4001,SC2086
# hadolint ignore=SC2086,DL3015,DL3008,DL3013
RUN echo en_US.UTF-8 UTF-8 >> /etc/locale.gen \
&& apt-get update \
&& apt-get install -y --no-install-recommends gnupg \
@@ -44,26 +45,35 @@ RUN echo en_US.UTF-8 UTF-8 >> /etc/locale.gen \
dumb-init \
nodejs \
rsync \
gosu \
&& DPKG_ARCH="$(dpkg --print-architecture)" \
&& LSB_RELEASE_CODENAME="$(lsb_release --codename | cut -f2)" \
&& sed -e 's/Defaults.*env_reset/Defaults env_keep = "HTTP_PROXY HTTPS_PROXY NO_PROXY FTP_PROXY http_proxy https_proxy no_proxy ftp_proxy"/' -i /etc/sudoers \
&& echo deb http://ppa.launchpad.net/git-core/ppa/ubuntu $([[ $(grep -E '^ID=' /etc/os-release | sed 's/.*=//g') == "ubuntu" ]] && (grep VERSION_CODENAME /etc/os-release | sed 's/.*=//g') || echo bionic) main>/etc/apt/sources.list.d/git-core.list \
&& apt-get update \
&& ( apt-get install -y --no-install-recommends git || apt-get install -t stable -y --no-install-recommends git || apt-get install -y --no-install-recommends git=1:2.33.1-0ppa1~ubuntu18.04.1 git-man=1:2.33.1-0ppa1~ubuntu18.04.1 ) \
&& ( [[ $(apt-cache search -n liblttng-ust0 | awk '{print $1}') == "liblttng-ust0" ]] && apt-get install -y --no-install-recommends liblttng-ust0 || : ) \
&& ( [[ $(apt-cache search -n liblttng-ust1 | awk '{print $1}') == "liblttng-ust1" ]] && apt-get install -y --no-install-recommends liblttng-ust1 || : ) \
&& ( ( curl "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o "awscliv2.zip" && unzip awscliv2.zip -d /tmp/ && /tmp/aws/install ) || pip3 install awscli ) \
# Determine the Distro name (Debian, Ubuntu, etc)
&& ( ( curl "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o "awscliv2.zip" && unzip awscliv2.zip -d /tmp/ && /tmp/aws/install && rm awscliv2.zip) || pip3 install --no-cache-dir awscli ) \
&& ( curl -s "https://github.com/git-lfs/git-lfs/releases/download/v${GIT_LFS_VERSION}/git-lfs-linux-${DPKG_ARCH}-v${GIT_LFS_VERSION}.tar.gz" -L -o /tmp/lfs.tar.gz && tar -xzf /tmp/lfs.tar.gz -C /tmp && /tmp/git-lfs-${GIT_LFS_VERSION}/install.sh && rm -rf /tmp/lfs.tar.gz /tmp/git-lfs-${GIT_LFS_VERSION}) \
&& distro=$(lsb_release -is | awk '{print tolower($0)}') \
# Determine the Distro version (bullseye, xenial, etc)
# Note: sid is aliased to bullseye, because Docker doesn't have a matching apt repo
&& mkdir -p /etc/apt/keyrings \
&& ( curl -fsSL https://download.docker.com/linux/${distro}/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg ) \
&& version=$(lsb_release -cs | awk '{gsub("sid", "bullseye"); print $0}') \
&& ( echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/${distro} ${version} stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ) \
&& version=$(lsb_release -cs | sed 's/bookworm\|n\/a/bullseye/g') \
&& ( echo "deb [arch=${DPKG_ARCH} signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/${distro} ${version} stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ) \
&& apt-get update \
&& apt-get install -y docker-ce docker-ce-cli containerd.io --no-install-recommends --allow-unauthenticated \
&& ( [[ $(lscpu -J | jq -r '.lscpu[] | select(.field == "Vendor ID:") | .data') == "ARM" ]] && echo "Not installing docker-compose. See https://github.com/docker/compose/issues/6831" || ( curl -sL "https://github.com/docker/compose/releases/download/${DOCKER_COMPOSE_VERSION}/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose && chmod +x /usr/local/bin/docker-compose ) ) \
&& ( [[ $(lsb_release --codename | cut -f2) == "focal" ]] && ( echo "deb https://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_20.04/ /" | tee /etc/apt/sources.list.d/devel:kubic:libcontainers:stable.list && curl -L "https://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_20.04/Release.key" | apt-key add - && apt-get update) || : ) \
&& ( [[ $(lsb_release --codename | cut -f2) == "focal" || $(lsb_release --codename | cut -f2) == "jammy" || $(lsb_release --codename | cut -f2) == "sid" || $(lsb_release --codename | cut -f2) == "bullseye" ]] && apt-get install -y --no-install-recommends podman buildah skopeo || : ) \
&& ( [[ $(lsb_release --codename | cut -f2) == "jammy" ]] && echo "Ubuntu Jammy is marked as beta. Please see https://github.com/actions/virtual-environments/issues/5490" || : ) \
&& ( [[ "${LSB_RELEASE_CODENAME}" == "focal" ]] && ( echo "deb https://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_20.04/ /" | tee /etc/apt/sources.list.d/devel:kubic:libcontainers:stable.list && curl -L "https://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_20.04/Release.key" | apt-key add - && apt-get update) || : ) \
&& ( [[ "${LSB_RELEASE_CODENAME}" == "focal" || "${LSB_RELEASE_CODENAME}" == "jammy" || "${LSB_RELEASE_CODENAME}" == "sid" || "${LSB_RELEASE_CODENAME}" == "bullseye" ]] && apt-get install -y --no-install-recommends podman buildah skopeo || : ) \
&& ( [[ "${LSB_RELEASE_CODENAME}" == "jammy" ]] && echo "Ubuntu Jammy is marked as beta. Please see https://github.com/actions/virtual-environments/issues/5490" || : ) \
&& GH_CLI_VERSION=$(curl -sL -H "Accept: application/vnd.github+json" https://api.github.com/repos/cli/cli/releases/latest | jq -r '.tag_name' | sed 's/^v//g') \
&& GH_CLI_DOWNLOAD_URL=$(curl -sL -H "Accept: application/vnd.github+json" https://api.github.com/repos/cli/cli/releases/latest | jq ".assets[] | select(.name == \"gh_${GH_CLI_VERSION}_linux_${DPKG_ARCH}.deb\")" | jq -r '.browser_download_url') \
&& curl -sSLo /tmp/ghcli.deb ${GH_CLI_DOWNLOAD_URL} && apt-get -y install /tmp/ghcli.deb && rm /tmp/ghcli.deb \
&& rm -rf /var/lib/apt/lists/* \
&& rm -rf /tmp/*
&& rm -rf /tmp/* \
&& groupadd -g 121 runner \
&& useradd -mr -d /home/runner -u 1001 -g 121 runner \
&& usermod -aG sudo runner \
&& usermod -aG docker runner \
&& echo '%sudo ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers
+3 -1
View File
@@ -8,6 +8,7 @@ This will run the [new self-hosted github actions runners](https://help.github.c
## Quick-Start (Examples and Usage) ##
Please see [the wiki](https://github.com/myoung34/docker-github-actions-runner/wiki/Usage)
Please read [the contributing guidelines](https://github.com/myoung34/docker-github-actions-runner/blob/master/CONTRIBUTING.md)
## Notes ##
@@ -52,10 +53,11 @@ These containers are built via Github actions that [copy the dockerfile](https:/
| Environment Variable | Description |
| --- | --- |
| `RUN_AS_ROOT` | Boolean to run as root. If `true`: will run as root. If `True` and the user is overridden it will error. If any other value it will run as the `runner` user and allow an optional override. Default is `true` |
| `RUNNER_NAME` | The name of the runner to use. Supercedes (overrides) `RUNNER_NAME_PREFIX` |
| `RUNNER_NAME_PREFIX` | A prefix for a randomly generated name (followed by a random 13 digit string). You must not also provide `RUNNER_NAME`. Defaults to `github-runner` |
| `ACCESS_TOKEN` | A [github PAT](https://docs.github.com/en/github/authenticating-to-github/creating-a-personal-access-token) to use to generate `RUNNER_TOKEN` dynamically at container start. Not using this requires a valid `RUNNER_TOKEN` |
| `RUNNER_SCOPE` | The scope the runner will be registered on. Valid values are `repo`, `org` and `ent`. For 'org' and 'enterprise', `ACCESS_TOKEN` is required and `REPO_URL` is unneccesary. If 'org', requires `ORG_NAME`; if 'enterprise', requires `ENTERPRISE_NAME`. Default is 'repo'. |
| `RUNNER_SCOPE` | The scope the runner will be registered on. Valid values are `repo`, `org` and `ent`. For 'org' and 'enterprise', `ACCESS_TOKEN` is required and `REPO_URL` is unnecessary. If 'org', requires `ORG_NAME`; if 'enterprise', requires `ENTERPRISE_NAME`. Default is 'repo'. |
| `ORG_NAME` | The organization name for the runner to register under. Requires `RUNNER_SCOPE` to be 'org'. No default value. |
| `ENTERPRISE_NAME` | The enterprise name for the runner to register under. Requires `RUNNER_SCOPE` to be 'enterprise'. No default value. |
| `LABELS` | A comma separated string to indicate the labels. Default is 'default' |
+1 -1
View File
@@ -4,7 +4,7 @@ If you believe you have found a security vulnerability, please report it to me a
## Reporting Security Issues
**Please do not report security vulnerabilities through public GitHub issues.** Instead, please report them to me directly at [myoung34@my.apsu.edu](mailto:myoung34@my.apsu.edu).
**Please do not report security vulnerabilities through public GitHub issues.** Instead, please report them to me directly at [myoung34@my.apsu.edu](mailto:myoung34@my.apsu.edu).
If you'd like to communicate securely, my keybase is [here](https://keybase.io/3vilpenguin)
+29 -10
View File
@@ -1,4 +1,5 @@
#!/usr/bin/dumb-init /bin/bash
# shellcheck shell=bash
export RUNNER_ALLOW_RUNASROOT=1
export PATH=$PATH:/actions-runner
@@ -25,6 +26,7 @@ _RUNNER_WORKDIR=${RUNNER_WORKDIR:-/_work}
_LABELS=${LABELS:-default}
_RUNNER_GROUP=${RUNNER_GROUP:-Default}
_GITHUB_HOST=${GITHUB_HOST:="github.com"}
_RUN_AS_ROOT=${RUN_AS_ROOT:="true"}
# ensure backwards compatibility
if [[ -z $RUNNER_SCOPE ]]; then
@@ -59,24 +61,22 @@ case ${RUNNER_SCOPE} in
esac
configure_runner() {
ARGS=()
if [[ -n "${ACCESS_TOKEN}" ]]; then
echo "Obtaining the token of the runner"
_TOKEN=$(ACCESS_TOKEN="${ACCESS_TOKEN}" bash /token.sh)
RUNNER_TOKEN=$(echo "${_TOKEN}" | jq -r .token)
fi
# shellcheck disable=SC2153
if [ -n "${EPHEMERAL}" ]; then
echo "Ephemeral option is enabled"
_EPHEMERAL="--ephemeral"
else
_EPHEMERAL=""
ARGS+=("--ephemeral")
fi
if [ -n "${DISABLE_AUTO_UPDATE}" ]; then
echo "Disable auto update option is enabled"
_AUTO_UPDATE="--disableupdate"
else
_AUTO_UPDATE=""
ARGS+=("--disableupdate")
fi
echo "Configuring"
@@ -89,8 +89,10 @@ configure_runner() {
--runnergroup "${_RUNNER_GROUP}" \
--unattended \
--replace \
${_EPHEMERAL} \
${_AUTO_UPDATE}
"${ARGS[@]}"
[[ ! -d "${_RUNNER_WORKDIR}" ]] && mkdir "${_RUNNER_WORKDIR}"
}
@@ -124,5 +126,22 @@ if [[ ${_DISABLE_AUTOMATIC_DEREGISTRATION} == "false" ]]; then
trap deregister_runner SIGINT SIGQUIT SIGTERM INT TERM QUIT
fi
# Container's command (CMD) execution
"$@"
# Container's command (CMD) execution as runner user
if [[ ${_RUN_AS_ROOT} == "true" ]]; then
if [[ $(id -u) -eq 0 ]]; then
"$@"
else
echo "ERROR: RUN_AS_ROOT env var is set to true but the user has been overridden and is not running as root, but UID '$(id -u)'"
exit 1
fi
else
if [[ $(id -u) -eq 0 ]]; then
[[ -n "${CONFIGURED_ACTIONS_RUNNER_FILES_DIR}" ]] && /usr/bin/chown -R runner "${CONFIGURED_ACTIONS_RUNNER_FILES_DIR}"
/usr/bin/chown -R runner "${_RUNNER_WORKDIR}" /opt/hostedtoolcache/ /actions-runner
/usr/sbin/gosu runner "$@"
else
"$@"
fi
fi
+4
View File
@@ -0,0 +1,4 @@
linter:
actionlint:
ignore:
- ".*Quote this to prevent word splitting.*"