mirror of
https://github.com/casjaysdevdocker/forgejo
synced 2026-09-24 18:50:09 -04:00
🐛 Fix act_runner cache/token config and Dockerfile OCI labels 🐛
gitea / release-gitea (push) Waiting to run
gitea / release-gitea (push) Waiting to run
Verified via AI.md PART 8 syntax gate (bash -n across all rootfs scripts), hadolint on Dockerfile, script-lint agent on the two shell scripts, and YAML validation on both config files — all pass. - Dockerfile: org.opencontainers.image.url corrected from the stale https://docker.io/casjaysdevdocker/forgejo registry-pull form to the browsable https://hub.docker.com/r/casjaysdevdocker/forgejo page, per AI.md PART 0 rule 5. - Dockerfile: final-stage ENV HOSTNAME prefix corrected from casjaysdev-${IMAGE_NAME} to casjaysdevdocker-${IMAGE_NAME}, matching the build stage and AI.md PART 2's HOSTNAME convention. - rootfs/tmp/etc/act_runner/cache_server.yaml: cache.external_secret renamed to cache.secret — act_runner cache-server's config loader only recognizes secret, not external_secret. - rootfs/tmp/etc/act_runner/default_config.yaml: same external_secret -> secret rename in the cache: block (runner-side config). - rootfs/usr/local/bin/start-runners: same external_secret -> secret rename in the generated runners-cache.yaml heredoc. - rootfs/usr/local/etc/docker/init.d/zz-act_runner.sh: runner registration token extraction regex widened from [A-Za-z0-9]{20,} to [A-Za-z0-9_-]{20,} so tokens containing hyphens/underscores are no longer truncated. - TODO.AI.md: logged the two Dockerfile compliance fixes above, and logged (not fixed — out of scope, template-owned file) a stale __copy_templates/DEFAULT_TEMPLATE_DIR reference found in functions/entrypoint.sh while running the dead-reference gate. - .claude/scheduled_tasks.lock: session lock rotation (automatic, not a deliberate change).
This commit is contained in:
@@ -1 +1 @@
|
||||
{"sessionId":"a4c0164e-35a4-4118-a2fb-1ec39431392f","pid":618193,"procStart":"112807435","acquiredAt":1788427111850}
|
||||
{"sessionId":"7224b911-7be3-4b45-b37a-c41ef851ec26","pid":3183788,"procStart":"163691267","acquiredAt":1788921141799}
|
||||
+2
-3
@@ -207,7 +207,7 @@ LABEL org.opencontainers.image.description="Containerized version of ${IMAGE_NAM
|
||||
LABEL org.opencontainers.image.created="${BUILD_DATE}"
|
||||
LABEL org.opencontainers.image.version="${BUILD_VERSION}"
|
||||
LABEL org.opencontainers.image.revision="${GIT_COMMIT}"
|
||||
LABEL org.opencontainers.image.url="https://docker.io/casjaysdevdocker/forgejo"
|
||||
LABEL org.opencontainers.image.url="https://hub.docker.com/r/casjaysdevdocker/forgejo"
|
||||
LABEL org.opencontainers.image.source="https://github.com/casjaysdevdocker/forgejo"
|
||||
LABEL org.opencontainers.image.documentation="https://github.com/casjaysdevdocker/forgejo"
|
||||
LABEL org.opencontainers.image.vcs-type="Git"
|
||||
@@ -224,7 +224,7 @@ ENV TERM="xterm-256color"
|
||||
ENV PORT="${SERVICE_PORT}"
|
||||
ENV ENV_PORTS="${ENV_PORTS}"
|
||||
ENV CONTAINER_NAME="${IMAGE_NAME}"
|
||||
ENV HOSTNAME="casjaysdev-${IMAGE_NAME}"
|
||||
ENV HOSTNAME="casjaysdevdocker-${IMAGE_NAME}"
|
||||
ENV PHP_SERVER="${PHP_SERVER}"
|
||||
ENV NODE_VERSION="${NODE_VERSION}"
|
||||
ENV NODE_MANAGER="${NODE_MANAGER}"
|
||||
@@ -242,4 +242,3 @@ STOPSIGNAL SIGRTMIN+3
|
||||
|
||||
ENTRYPOINT [ "tini", "-p", "SIGTERM","--", "/usr/local/bin/entrypoint.sh" ]
|
||||
HEALTHCHECK --start-period=10m --interval=5m --timeout=15s CMD [ "/usr/local/bin/entrypoint.sh", "healthcheck" ]
|
||||
|
||||
|
||||
+72
@@ -1,5 +1,64 @@
|
||||
# TODO.AI.md
|
||||
|
||||
## Found, not fixed — stale `__copy_templates`/`DEFAULT_TEMPLATE_DIR` calls in functions/entrypoint.sh
|
||||
|
||||
Found incidentally while running AI.md PART 8's dead-reference gate ("No `__copy_templates`
|
||||
calls remain (retired with `DEFAULT_TEMPLATE_DIR`)") before committing an unrelated set of
|
||||
fixes.
|
||||
|
||||
- `rootfs/usr/local/etc/docker/functions/entrypoint.sh` still defines `__copy_templates`
|
||||
(line 650) and calls it at lines 457, 459, 512, 519 — the exact pattern AI.md PART 8
|
||||
documents as retired alongside `DEFAULT_TEMPLATE_DIR`.
|
||||
- `functions/entrypoint.sh` is a `gen-dockerfile`-generated file (per AI.md's ownership
|
||||
rules) — per rule 2, this must be fixed in the upstream `gen-dockerfile` template and then
|
||||
regenerated, not hand-edited in this repo. Not fixed here — out of scope for the current
|
||||
commit and requires the upstream template repo, not this one.
|
||||
|
||||
## App-breaking bug fixed — runner daemon cache secret key wrong (build/test cycle)
|
||||
|
||||
Found while functionally testing the built image: after registration succeeded, the
|
||||
`act_runner daemon` process still logged `A cache secret must be specified to use an
|
||||
external cache server, cache will be disabled`, even though `ps aux` confirmed it was
|
||||
launched with `--config /config/act_runner/runners-cache.yaml` and that file contained a
|
||||
non-empty secret.
|
||||
|
||||
- `rootfs/usr/local/bin/start-runners` (heredoc generating `runners-cache.yaml`, line 112):
|
||||
used `external_secret:` under `cache:`. Verified via `strings /usr/local/bin/act_runner`
|
||||
on the actual binary that this act_runner v13.1.0's embedded config schema uses `secret:`
|
||||
for the client/daemon side too — `external_secret` is not a recognized key anywhere in
|
||||
this binary version. Fixed to `secret: '${RUNNER_CACHE_SECRET}'`.
|
||||
- `rootfs/tmp/etc/act_runner/default_config.yaml` (`cache:` block, line 71): same wrong
|
||||
key, same fix — `external_secret:` → `secret: 'REPLACE_RUNNER_CACHE_SECRET'`. This is the
|
||||
template copied to `/config/act_runner/forgejo/act_runner.yaml` at container startup.
|
||||
|
||||
## App-breaking bug fixed — runner registration token truncated by regex (build/test cycle)
|
||||
|
||||
Found while functionally testing the built image: act_runner failed to register with
|
||||
`invalid_argument: runner registration token not found` even though a token was
|
||||
generated and written to `/config/act_runner/tokens/system`.
|
||||
|
||||
- `rootfs/usr/local/etc/docker/init.d/zz-act_runner.sh` (`__gen_auth_token`, line 146):
|
||||
`forgejo actions generate-runner-token` returns a token containing hyphens (verified
|
||||
empirically, e.g. `FREHhNzKSoKU3KLpB3SwHLX1O1PvTAJGTZn2rmf--MR`), but the extraction
|
||||
regex `grep -oE '[A-Za-z0-9]{20,}'` only matches alnum runs, so `tail -n1` returned
|
||||
just the alnum prefix and silently dropped the `--MR` suffix — writing a truncated,
|
||||
invalid token that Forgejo's API correctly rejects on registration. Fixed the regex to
|
||||
`[A-Za-z0-9_-]{20,}` so the full token is captured.
|
||||
|
||||
## App-breaking bug fixed — cache_server.yaml wrong config key (build/test cycle)
|
||||
|
||||
Found while functionally testing the built image: `act_runner cache-server` exited
|
||||
immediately with `no cache secret was specified, exiting.` even though a secret was
|
||||
generated and injected.
|
||||
|
||||
- `rootfs/tmp/etc/act_runner/cache_server.yaml`: used `external_secret` under `cache:`,
|
||||
but `act_runner cache-server`'s config loader only recognizes `secret` (matches the
|
||||
CLI's `--secret` flag; `external_secret` is the client-side key used in
|
||||
`default_config.yaml`'s `cache:` block to point a *runner* at an *external* cache
|
||||
server — not the key the cache-server itself reads). Verified empirically: same config
|
||||
with `secret:` starts and runs cleanly; with `external_secret:` it exits immediately.
|
||||
Fixed to `secret: 'REPLACE_RUNNER_CACHE_SECRET'`.
|
||||
|
||||
## App-breaking bug fixed — sshd_config AllowUsers mismatch (gitea→forgejo migration)
|
||||
|
||||
Found incidentally while sweeping for remaining "gitea" references during the forgejo rename.
|
||||
@@ -297,6 +356,19 @@ container:
|
||||
`forker` user account), and mirror+sync (`mirror_updated` timestamp advanced from mirror-registration
|
||||
time to a fresh sync time) all still work with no regressions from this fix.
|
||||
|
||||
## AI.md compliance fixed — Dockerfile stale image.url and wrong HOSTNAME prefix
|
||||
|
||||
Found while reading the full repo tree; not previously logged.
|
||||
|
||||
- `Dockerfile` final stage: `LABEL org.opencontainers.image.url` used the stale
|
||||
`https://docker.io/casjaysdevdocker/forgejo` registry-pull form. AI.md PART 0 rule 5
|
||||
requires the browsable Docker Hub page URL. Fixed to
|
||||
`https://hub.docker.com/r/casjaysdevdocker/forgejo`.
|
||||
- `Dockerfile` final stage: `ENV HOSTNAME="casjaysdev-${IMAGE_NAME}"` used the wrong org
|
||||
prefix. AI.md PART 2's HOSTNAME convention requires `casjaysdevdocker-${IMAGE_NAME}`
|
||||
(matching the build-stage `ENV HOSTNAME="casjaysdevdocker-forgejo"`, which was already
|
||||
correct). Fixed to `casjaysdevdocker-${IMAGE_NAME}`.
|
||||
|
||||
## Non-issue — confirmed intentional (`.gitea/workflows/docker.yaml`)
|
||||
|
||||
- Uses a stale/unpinned action pattern (`@v2`-`@v4`, DockerHub-only, `catthehacker/ubuntu:act-latest`).
|
||||
|
||||
@@ -6,4 +6,4 @@ cache:
|
||||
dir: 'REPLACE_RUNNER_CACHE_DIR'
|
||||
host: '0.0.0.0'
|
||||
port: REPLACE_RUNNER_CACHE_PORT
|
||||
external_secret: 'REPLACE_RUNNER_CACHE_SECRET'
|
||||
secret: 'REPLACE_RUNNER_CACHE_SECRET'
|
||||
|
||||
@@ -68,4 +68,4 @@ container:
|
||||
cache:
|
||||
enabled: true
|
||||
external_server: 'http://REPLACE_RUNNER_CACHE_HOST:REPLACE_RUNNER_CACHE_PORT/'
|
||||
external_secret: 'REPLACE_RUNNER_CACHE_SECRET'
|
||||
secret: 'REPLACE_RUNNER_CACHE_SECRET'
|
||||
|
||||
@@ -109,7 +109,7 @@ if [ -n "$RUNNER_CACHE_HOST" ] && [ -n "$RUNNER_CACHE_PORT" ] && [ -n "$RUNNER_C
|
||||
cache:
|
||||
enabled: true
|
||||
external_server: 'http://${RUNNER_CACHE_HOST}:${RUNNER_CACHE_PORT}/'
|
||||
external_secret: '${RUNNER_CACHE_SECRET}'
|
||||
secret: '${RUNNER_CACHE_SECRET}'
|
||||
EOF
|
||||
fi
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
|
||||
@@ -143,7 +143,7 @@ __gen_auth_token() {
|
||||
auth_token="$( gosu $user $forgejo_bin --config "$conf_file" \
|
||||
--work-path /data/forgejo --custom-path /config/forgejo/custom \
|
||||
actions generate-runner-token 2>/dev/null | \
|
||||
grep -oE -- '[A-Za-z0-9]{20,}' | tail -n1 )"
|
||||
grep -oE -- '[A-Za-z0-9_-]{20,}' | tail -n1 )"
|
||||
fi
|
||||
fi
|
||||
if [ -n "$auth_token" ]; then
|
||||
|
||||
Reference in New Issue
Block a user