gitea-repo-template/ci/buildkit/02-statefulset.yaml
Hermes Agent 883e264c42
Some checks failed
build-and-deploy / test (push) Failing after 2m36s
build-and-deploy / build-deploy (push) Has been skipped
chore: seed gitea-repo-template cookie-cutter
Reusable repo template for homelab services on git.aridgwayweb.com.

Bakes in (all verified live on armistace/wedding-photos):
- Hard commit guard: shared pre-commit hook (git config core.hooksPath
  ~/dev/git-hooks) + master branch protection (push whitelist [armistace],
  merge whitelist [hermes, armistace]).
- Gitea Actions CI (.gitea/workflows/build_push.yml): test + build-deploy,
  persistent remote buildkit cache, registry push, idempotent deploy that
  preserves hand-provisioned Secrets, cluster injection from repo secrets/vars
  via scripts/reconcile-cluster-inject.sh.
- Persistent buildkit cache (ci/buildkit/): single-replica Longhorn backing.
- scripts/reconcile-cluster-inject.sh: reconcile live Secret/ConfigMap from
  Gitea secrets/vars without clobbering hand-provisioned values.
- RUNBOOK.md: handoff-complete ops doc.

Placeholders (<APP> <OWNER> <NS> <KEY_*>) are filled per-service on repo creation.
2026-09-24 11:45:57 +10:00

78 lines
2.7 KiB
YAML

# Dedicated long-lived buildkit daemon for CI image builds.
#
# Persists its build cache on a single-replica Longhorn volume (StorageClass
# buildkit-single-1r) so repeated CI image builds reuse the layer cache instead of
# re-pulling/building every time. The cache stays ONE copy on disk (not the 3x
# default replication) and is bounded by the 10Gi PVC. The workflow's buildx uses
# the REMOTE driver to point at this daemon via the ClusterIP Service below.
#
# Disk-pressure safety net: the buildkit-cache-monitor cron (monitoring/) reverts
# CI to the ephemeral buildx driver if any node crosses critical disk usage.
#
# NOTE: no toleration for the gitea-builder taint on archlinux-k3s-1, so this pod
# schedules on a worker node (2 or 3) away from the high-CPU control plane.
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: buildkit
namespace: gitea-runner
spec:
serviceName: buildkit
replicas: 1
selector:
matchLabels:
app: buildkit
template:
metadata:
labels:
app: buildkit
spec:
containers:
- name: buildkitd
image: moby/buildkit:buildx-stable-1
args:
- --addr
# Listen for the remote driver over TCP on 1234 (no TLS - internal cluster traffic).
- tcp://0.0.0.0:1234
# Keep the cache (do NOT use --oci-worker-no-process-sandbox or other
# flags that break rootless cache persistence).
ports:
- name: daemon
containerPort: 1234
resources:
requests:
cpu: 500m
memory: 1Gi
limits:
cpu: "2"
memory: 4Gi
ephemeral-storage: 2Gi
volumeMounts:
- name: cache
mountPath: /var/lib/buildkit
# BuildKit needs this for the CA/root store even when not using TLS.
- name: certs
mountPath: /etc/buildkit/certs
- name: config
mountPath: /etc/buildkit
securityContext:
# BuildKit's OCI/runc worker must bind-mount build contexts & layers.
# The old driver-spawned (working) buildkit pods ran privileged:true;
# false here caused "failed to mount snapshot ... operation not
# permitted" (runc-native can't mount). Match the proven-working pods.
privileged: true
volumes:
- name: certs
emptyDir: {}
- name: config
emptyDir: {}
volumeClaimTemplates:
- metadata:
name: cache
spec:
accessModes: ["ReadWriteOnce"]
storageClassName: buildkit-single-1r
resources:
requests:
storage: 10Gi