Extract runner-controller into its own repo (gitborg/runner-controller) with semver image releases #201
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#201
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Prerequisite for #38 (self-host infra deploy). Design tracked internally.
Why (the #38 blocker)
The runner that would deploy bitborg-infra is built inside bitborg-infra:
roles/runner-controller/tasks/main.ymlbuilds the controller image on the services host fromfiles/{Containerfile,controller.py}and tags it with a content hash. A self-deploy pipeline can't safely depend on CI substrate living in its own payload. Unblock = extract the controller into a neutral, externally-versioned artifact.Scope
New repo
gitborg/runner-controller(public, AGPL-3.0):controller.py,Containerfile(promote the pinned pip deps intopyproject.toml),test_controller_logic.py→tests/, the runner cloud-init template (decision: bake into the image), a config-schema README (the cross-repo contract). Add.forgejo/workflows/{ci.yml (ruff/mypy/pytest), release.yml (tag v* → build + pushgit.gitborg.se/gitborg/runner-controller:vX.Y.Z+:sha-XXXX+ Forgejo Release)}.Stays in infra:
config.yaml.j2(host-specific), the Quadlet unit template (change onlyImage=), the handlers, all group_vars wiring, both vault secrets + the readiness gate. Do NOT movevault_openstack_runner_cloud/runner_controller_os_network_id—backup-drillreuses them.Slim the consumer role + fix #63 in the same change: delete the on-host build plumbing; add a
containers.podman.podman_image: {pull: true}step before the Quadlet install (the forgejo-role pattern, tasks 199-235) + keep the unit-change→restart notify, else a pinned-tag consumer silently no-ops on a bump (the #63 class). RepointImage=to the pinned registry tag; add a Renovate annotation onrunner_controller_image_tag; reject:latest/AutoUpdate=registryfor this destructive control-plane daemon.Bootstrap (no gap)
Tag
v1.0.0at byte-parity with currentmain.release.ymlruns on the still-in-repo host-builtcipool → the existing controller mints the runner that builds its own replacement. Only afterv1.0.0is in the registry, PR the infra slim-down (apply via infra-apply). Don't delete the build plumbing untilv1.0.0is confirmed pushed.Risks
state: startedwould keep the old image. The pre-pull + unit-restart is mandatory. Verify the running digest actually changes on a bump.load_configfails loudly on missing keys; schema change = MAJOR bump.dockerdatasource resolvesgit.gitborg.se/gitborg/runner-controllertags anonymously on first bump; else add a hostRules token.ADR: amend #0021 (new ADR — extraction + semver releases; retire host-build). Blocks #38.
area/ci, area/infra, ready-for-implementation, type/task