Change runner container network from bridge to host to allow workflow containers to resolve Kubernetes service DNS names. With bridge network, containers couldn't resolve forgejo.forgejo.svc.cluster.local. Using host network gives containers access to the cluster's DNS resolver. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| forgejo-runner-config.yaml | ||
| forgejo-runner-deployment.yaml | ||
| forgejo-runner-serviceaccount.yaml | ||
| forgejo-runner-token-sealed.yaml | ||
| README.md | ||
Forgejo Actions Runner
This directory contains the deployment configuration for the Forgejo Actions runner.
Prerequisites
Before deploying the runner, you need to obtain a registration token from Forgejo.
Getting the Registration Token
Option 1: Via Forgejo Admin UI
- Log in to https://forgejo.basicstack.de as admin
- Navigate to Site Administration → Actions → Runners
- Click "Create new Runner"
- Copy the registration token
Option 2: Via API
export FORGEJO_TOKEN="your-api-token"
curl -X POST \
-H "Authorization: token $FORGEJO_TOKEN" \
https://forgejo.basicstack.de/api/v1/admin/runners/registration-token
Creating the Secret
Once you have the registration token, create a sealed secret:
# Create a temporary secret file
kubectl create secret generic forgejo-runner-token \
--from-literal=token='YOUR_REGISTRATION_TOKEN' \
--namespace=forgejo \
--dry-run=client -o yaml > /tmp/runner-token-secret.yaml
# Seal it with kubeseal
kubeseal --format=yaml < /tmp/runner-token-secret.yaml > apps/forgejo-runner/forgejo-runner-token-sealed.yaml
# Clean up
rm /tmp/runner-token-secret.yaml
Deployment
The runner is deployed via Argo CD. After creating the sealed secret, apply the Argo CD application:
kubectl apply -f apps/app-forgejo-runner.yaml
Runner Configuration
The runner is configured to:
- Run 2 concurrent jobs
- Use Docker-in-Docker for workflow execution
- Support ubuntu-latest and ubuntu-22.04 labels with Node.js 24
- Connect to Forgejo at http://forgejo.forgejo.svc.cluster.local:3000
Troubleshooting
Check runner logs:
kubectl logs -n forgejo -l app=forgejo-runner -f
Check if runner is registered:
kubectl exec -n forgejo deployment/forgejo-runner -- forgejo-runner list