Files
ObsiGate/scripts/install-gitea-runner.sh
T
bruno 65a0221557
CI / lint (push) Successful in 25s
CI / security (push) Successful in 13s
CI / test (push) Successful in 27s
CI / build (push) Successful in 10s
CI / e2e (push) Failing after 20s
fix: add root privilege check to install-gitea-runner.sh
- Exits early with clear error if not run as root
- Suggests 'doas' on Alpine, 'sudo' on Debian/Arch
- Prevents silent failure from apk add / apt-get requiring root
2026-07-25 10:09:31 -04:00

154 lines
5.3 KiB
Bash
Executable File

#!/bin/sh
# ================================================================
# install-gitea-runner.sh
# Installation automatisée d'un runner Gitea Actions
#
# Usage:
# sudo ./install-gitea-runner.sh <TOKEN> <NAME> <LABELS>
#
# Exemple (Alpine) :
# doas ./install-gitea-runner.sh abc123 "dev-lab" "self-hosted,lab,docker,obsigate"
#
# Exemple (Debian) :
# sudo ./install-gitea-runner.sh abc123 "dev-lab" "self-hosted,lab,docker,obsigate"
#
# ⚠️ Doit être exécuté en root (sudo / doas)
# ================================================================
set -e
TOKEN="$1"
NAME="$2"
LABELS="$3"
if [ -z "$TOKEN" ] || [ -z "$NAME" ] || [ -z "$LABELS" ]; then
echo "❌ Usage: sudo ./install-gitea-runner.sh <TOKEN> <NAME> <LABELS>"
echo " Example: sudo ./install-gitea-runner.sh abc123 dev-lab 'self-hosted,lab,docker,obsigate'"
exit 1
fi
# ── 0. Require root ────────────────────────────────────────────────
if [ "$(id -u)" -ne 0 ]; then
echo "❌ This script must be run as root."
if [ -f /etc/alpine-release ]; then
echo " Use: doas $0 $*"
else
echo " Use: sudo $0 $*"
fi
exit 1
fi
# ── 0. Detect OS + privilege elevation method ──────────────────────
if [ -f /etc/alpine-release ]; then
OS="alpine"
# Alpine: utilise doas, mais si on est déjà root (via doas), on continue
# On vérifie juste que curl et les outils de base sont là
elif [ -f /etc/debian_version ]; then
OS="debian"
elif [ -f /etc/arch-release ]; then
OS="arch"
else
echo "⚠️ Unknown OS — assuming Debian-based"
OS="debian"
fi
echo "🖥️ Detected OS: $OS"
# ── 1. Install prerequisites ──────────────────────────────────────
echo "[1/5] Installing prerequisites..."
if [ "$OS" = "alpine" ]; then
apk add --no-cache curl docker > /dev/null 2>&1
rc-update add docker boot 2>/dev/null || true
service docker start 2>/dev/null || true
elif [ "$OS" = "debian" ]; then
apt-get update -qq
apt-get install -y -qq docker.io curl
elif [ "$OS" = "arch" ]; then
pacman -S --noconfirm docker curl
systemctl enable --now docker
fi
echo " ✅ Prerequisites OK (curl, docker)"
# ── 2. Download runner ─────────────────────────────────────────────
echo "[2/5] Downloading Gitea act_runner v0.2.11..."
ARCH=$(uname -m)
case "$ARCH" in
x86_64) RUNNER_ARCH="amd64" ;;
aarch64) RUNNER_ARCH="arm64" ;;
armv7l) RUNNER_ARCH="armv7" ;;
*) echo "❌ Unsupported architecture: $ARCH"; exit 1 ;;
esac
RUNNER_URL="https://dl.gitea.com/act_runner/0.2.11/act_runner-0.2.11-linux-${RUNNER_ARCH}"
curl -sL -o /usr/local/bin/act_runner "$RUNNER_URL"
chmod +x /usr/local/bin/act_runner
echo " ✅ act_runner v0.2.11 installed"
# ── 3. Register ────────────────────────────────────────────────────
echo "[3/5] Registering runner with Gitea..."
/usr/local/bin/act_runner register \
--no-interactive \
--instance https://git.dracodev.net \
--token "$TOKEN" \
--name "$NAME" \
--labels "$LABELS"
echo " ✅ Runner registered"
# ── 4. Install as service ─────────────────────────────────────────
echo "[4/5] Installing as system service..."
if [ "$OS" = "alpine" ]; then
# Alpine OpenRC — le script est exécuté en root via doas
cat > /etc/init.d/gitea-runner <<'OPENRC_EOF'
#!/sbin/openrc-run
name="Gitea Actions Runner"
command="/usr/local/bin/act_runner"
command_args="daemon"
command_background=true
pidfile="/run/${RC_SVCNAME}.pid"
output_log="/var/log/gitea-runner.log"
error_log="/var/log/gitea-runner.log"
OPENRC_EOF
chmod +x /etc/init.d/gitea-runner
rc-update add gitea-runner default
service gitea-runner start
else
# Systemd (Debian, Arch)
# act_runner cherche .runner dans WorkingDirectory → home de l'utilisateur
TARGET_USER="${SUDO_USER:-bruno}"
TARGET_HOME=$(eval echo "~$TARGET_USER")
cat > /etc/systemd/system/gitea-runner.service <<SYSTEMD_EOF
[Unit]
Description=Gitea Actions Runner ($NAME)
After=network.target docker.service
Requires=docker.service
[Service]
ExecStart=/usr/local/bin/act_runner daemon
WorkingDirectory=$TARGET_HOME
User=$TARGET_USER
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
SYSTEMD_EOF
systemctl daemon-reload
systemctl enable --now gitea-runner
fi
echo " ✅ Service installed and started"
# ── 5. Verify ──────────────────────────────────────────────────────
echo "[5/5] Verifying..."
sleep 2
if [ "$OS" = "alpine" ]; then
service gitea-runner status 2>&1 | head -3
else
systemctl status gitea-runner --no-pager -l 2>&1 | head -5
fi
echo ""
echo "============================================="
echo " ✅ Runner '$NAME' installed successfully!"
echo " Labels : $LABELS"
echo " Vérifier dans Gitea → Admin → Runners"
echo "============================================="