ci: use dedicated host deploy runner
All checks were successful
Dimension Lab website / ci (pull_request) Successful in 19s
Dimension Lab website / deploy (pull_request) Has been skipped

This commit is contained in:
vince 2026-06-20 17:34:09 +02:00
parent da9a5a942d
commit a3bcd33961
3 changed files with 18 additions and 16 deletions

View file

@ -168,15 +168,18 @@ Merges to `main` run `.forgejo/workflows/dimensionlab-website.yml`. Pull
requests run check, test, and build only; the deploy job is guarded to run only
for `push` events on `refs/heads/main`.
The Dimension Lab runner exposes the rootless Podman socket to job containers as
`/var/run/docker.sock`. Because this host uses SELinux labeling, the runner
configuration must set:
The workflow uses two runner classes. Pull request CI runs on the containerized
`docker` runner. Production deployment runs on a separate host runner with the
`deploy:host` label so the guarded deploy script can use the user's rootless
`podman` and `systemctl --user` commands directly.
```yaml
container:
options: --security-opt label=disable
runner:
labels:
- deploy:host
```
The deploy job also performs a socket preflight against the
The deploy job also performs a host preflight against the
`dimensionlab-website.service` Podman label before it builds or restarts the
production container.
production container. Do not give the general pull request runner deployment
socket access; keep deploy privileges on the dedicated `deploy` runner.