Make v0.1.0 Unraid-ready: multi-arch image, correct image path, registry-login docs
CI Smoke / toolchain (push) Successful in 1s

- Publish v0.1.0/latest as multi-arch (linux/amd64+arm64); amd64 passes 17/17 smoke
- publish-image.sh: add PLATFORMS multi-arch buildx mode (reproducible amd64 build)
- compose + unraid notes: fix image path to include jason/ namespace
- unraid notes: document required docker login (private package) and host label
  for docker build/push jobs

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Jason Stedwell
2026-06-29 22:18:38 -05:00
parent ffc75cc25f
commit 1ad33c2396
4 changed files with 50 additions and 4 deletions
+4 -2
View File
@@ -7,7 +7,7 @@
services:
gitea-runner:
image: registry.alwisp.com/custom-gitea-runner:v0.1.0 # pin your version here
image: registry.alwisp.com/jason/custom-gitea-runner:v0.1.0 # pin your version here (Gitea CR requires the owner namespace)
container_name: gitea-runner
restart: unless-stopped
@@ -18,7 +18,9 @@ services:
GITEA_RUNNER_TOKEN: ${GITEA_RUNNER_TOKEN} # set in .env file
# ── Optional ──────────────────────────────────────────────────────────
GITEA_RUNNER_LABELS: ubuntu-latest:docker://node:20-bullseye
# `host` runs steps in the runner container (Docker CLI + socket available),
# needed for docker build/push. `ubuntu-latest` runs in a clean node container.
GITEA_RUNNER_LABELS: ubuntu-latest:docker://node:20-bullseye,host:host
RUNNER_CONFIG_PATH: /config/runner.yaml
RUNNER_WORKDIR: /work
TZ: America/Chicago
+19 -2
View File
@@ -8,13 +8,26 @@ This document covers the recommended Unraid Docker container configuration for t
| Field | Value |
|---|---|
| Repository | `registry.alwisp.com/custom-gitea-runner:v0.1.0` |
| Repository | `registry.alwisp.com/jason/custom-gitea-runner:v0.1.0` |
| Container name | `gitea-runner` |
| Network type | `Bridge` |
| Privileged | `No` (leave unchecked — socket mount handles Docker access) |
---
## Registry authentication (required — image is private)
The image is published as a **private** package on the Gitea Container Registry, so the Unraid host must authenticate before it can pull it. Do this once via the Unraid terminal (or SSH):
```bash
docker login registry.alwisp.com -u <gitea-user>
# password: a Gitea access token with at least read:package scope
```
Credentials are stored in `/root/.docker/config.json` and persist across container recreations (but not necessarily across a full Unraid reboot if `/root` is on tmpfs — re-run if pulls start failing with `unauthorized`). Alternatively, make the package public in Gitea (Packages → custom-gitea-runner → Settings) to allow unauthenticated pulls.
---
## Environment variables
Set these in the "Environment Variables" section of the Unraid container template.
@@ -24,7 +37,7 @@ Set these in the "Environment Variables" section of the Unraid container templat
| `GITEA_INSTANCE_URL` | Yes | `https://git.example.com` |
| `GITEA_RUNNER_TOKEN` | Yes | Registration token from Gitea admin |
| `GITEA_RUNNER_NAME` | Yes | e.g. `unraid-runner-01` |
| `GITEA_RUNNER_LABELS` | No | `ubuntu-latest:docker://node:20-bullseye` |
| `GITEA_RUNNER_LABELS` | No | `ubuntu-latest:docker://node:20-bullseye,host:host` |
| `RUNNER_CONFIG_PATH` | No | `/config/runner.yaml` |
| `RUNNER_WORKDIR` | No | `/work` |
| `TZ` | No | `America/Chicago` |
@@ -73,3 +86,7 @@ Set these in the "Environment Variables" section of the Unraid container templat
## Notes on Docker socket
Mounting `/var/run/docker.sock` gives the runner access to the host Docker daemon. This is intentional for build/push workflows. Understand this means jobs running on this runner can interact with all containers on the Unraid host. For a self-owned, trusted environment this is acceptable. Future hardening options are documented in `docs/architecture.md`.
## Labels: which to use for Docker build/push
`docker build`/`docker push` steps need the bundled Docker CLI and the mounted socket, which only exist in the runner container itself — not inside the `ubuntu-latest` job container (a plain `node` image). Run Docker-centric jobs with `runs-on: host`. Use `ubuntu-latest:docker://…` for jobs that should run in a clean throwaway container. Registering with both labels (`ubuntu-latest:…,host:host`) covers both patterns. This was validated end-to-end against `git.alwisp.com` (see `forgerunner.src/ROADMAP.md` Phase 3).