Reusable repo template for homelab services on git.aridgwayweb.com. Bakes in (all verified live on armistace/wedding-photos): - Hard commit guard: shared pre-commit hook (git config core.hooksPath ~/dev/git-hooks) + master branch protection (push whitelist [armistace], merge whitelist [hermes, armistace]). - Gitea Actions CI (.gitea/workflows/build_push.yml): test + build-deploy, persistent remote buildkit cache, registry push, idempotent deploy that preserves hand-provisioned Secrets, cluster injection from repo secrets/vars via scripts/reconcile-cluster-inject.sh. - Persistent buildkit cache (ci/buildkit/): single-replica Longhorn backing. - scripts/reconcile-cluster-inject.sh: reconcile live Secret/ConfigMap from Gitea secrets/vars without clobbering hand-provisioned values. - RUNBOOK.md: handoff-complete ops doc. Placeholders (<APP> <OWNER> <NS> <KEY_*>) are filled per-service on repo creation.
78 lines
2.7 KiB
YAML
78 lines
2.7 KiB
YAML
# Dedicated long-lived buildkit daemon for CI image builds.
|
|
#
|
|
# Persists its build cache on a single-replica Longhorn volume (StorageClass
|
|
# buildkit-single-1r) so repeated CI image builds reuse the layer cache instead of
|
|
# re-pulling/building every time. The cache stays ONE copy on disk (not the 3x
|
|
# default replication) and is bounded by the 10Gi PVC. The workflow's buildx uses
|
|
# the REMOTE driver to point at this daemon via the ClusterIP Service below.
|
|
#
|
|
# Disk-pressure safety net: the buildkit-cache-monitor cron (monitoring/) reverts
|
|
# CI to the ephemeral buildx driver if any node crosses critical disk usage.
|
|
#
|
|
# NOTE: no toleration for the gitea-builder taint on archlinux-k3s-1, so this pod
|
|
# schedules on a worker node (2 or 3) away from the high-CPU control plane.
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: buildkit
|
|
namespace: gitea-runner
|
|
spec:
|
|
serviceName: buildkit
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: buildkit
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: buildkit
|
|
spec:
|
|
containers:
|
|
- name: buildkitd
|
|
image: moby/buildkit:buildx-stable-1
|
|
args:
|
|
- --addr
|
|
# Listen for the remote driver over TCP on 1234 (no TLS - internal cluster traffic).
|
|
- tcp://0.0.0.0:1234
|
|
# Keep the cache (do NOT use --oci-worker-no-process-sandbox or other
|
|
# flags that break rootless cache persistence).
|
|
ports:
|
|
- name: daemon
|
|
containerPort: 1234
|
|
resources:
|
|
requests:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
limits:
|
|
cpu: "2"
|
|
memory: 4Gi
|
|
ephemeral-storage: 2Gi
|
|
volumeMounts:
|
|
- name: cache
|
|
mountPath: /var/lib/buildkit
|
|
# BuildKit needs this for the CA/root store even when not using TLS.
|
|
- name: certs
|
|
mountPath: /etc/buildkit/certs
|
|
- name: config
|
|
mountPath: /etc/buildkit
|
|
securityContext:
|
|
# BuildKit's OCI/runc worker must bind-mount build contexts & layers.
|
|
# The old driver-spawned (working) buildkit pods ran privileged:true;
|
|
# false here caused "failed to mount snapshot ... operation not
|
|
# permitted" (runc-native can't mount). Match the proven-working pods.
|
|
privileged: true
|
|
volumes:
|
|
- name: certs
|
|
emptyDir: {}
|
|
- name: config
|
|
emptyDir: {}
|
|
volumeClaimTemplates:
|
|
- metadata:
|
|
name: cache
|
|
spec:
|
|
accessModes: ["ReadWriteOnce"]
|
|
storageClassName: buildkit-single-1r
|
|
resources:
|
|
requests:
|
|
storage: 10Gi
|