docs(ci): document Forgejo deploy runner option #55
1 changed files with 19 additions and 0 deletions
19
README.md
19
README.md
|
|
@ -161,3 +161,22 @@ The env file must provide `AGENT_CONFIG_TOKEN`. Runtime defaults inside the
|
||||||
image set `HOST=0.0.0.0`, `PORT=3000`,
|
image set `HOST=0.0.0.0`, `PORT=3000`,
|
||||||
`DATABASE_URL=file:/data/dimensionlab.sqlite`, and
|
`DATABASE_URL=file:/data/dimensionlab.sqlite`, and
|
||||||
`DASHBOARD_MIGRATIONS_DIR=/repo/apps/web/drizzle`.
|
`DASHBOARD_MIGRATIONS_DIR=/repo/apps/web/drizzle`.
|
||||||
|
|
||||||
|
### Forgejo Actions Deployment
|
||||||
|
|
||||||
|
Merges to `main` run `.forgejo/workflows/dimensionlab-website.yml`. Pull
|
||||||
|
requests run check, test, and build only; the deploy job is guarded to run only
|
||||||
|
for `push` events on `refs/heads/main`.
|
||||||
|
|
||||||
|
The Dimension Lab runner exposes the rootless Podman socket to job containers as
|
||||||
|
`/var/run/docker.sock`. Because this host uses SELinux labeling, the runner
|
||||||
|
configuration must set:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
container:
|
||||||
|
options: --security-opt label=disable
|
||||||
|
```
|
||||||
|
|
||||||
|
The deploy job also performs a socket preflight against the
|
||||||
|
`dimensionlab-website.service` Podman label before it builds or restarts the
|
||||||
|
production container.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue