Make the Gitlab Runner exclusive choices.

This commit is contained in:
Greg Hellings
2025-11-02 22:33:05 -06:00
parent e60d62ce45
commit a227302e36
5 changed files with 46 additions and 48 deletions
+3 -4
View File
@@ -33,10 +33,9 @@
podman.enable = true; podman.enable = true;
print.enable = true; print.enable = true;
tailscale.enable = true; tailscale.enable = true;
runner.enable = true; runner = {
vmdev = { enable = true;
enable = false; qemu = true;
system = "intel";
}; };
}; };
+4 -1
View File
@@ -41,7 +41,10 @@
}; };
tailscale.enable = true; tailscale.enable = true;
remote-builder.enable = true; remote-builder.enable = true;
runner.enable = true; runner = {
enable = true;
qemu = true;
};
}; };
fileSystems = { fileSystems = {
+1
View File
@@ -85,6 +85,7 @@ in
runner = { runner = {
enable = true; enable = true;
threads = 3; threads = 3;
qemu = true;
}; };
}; };
+10 -1
View File
@@ -22,7 +22,10 @@
priority = 253; priority = 253;
}; };
remote-builder.enable = true; remote-builder.enable = true;
runner.enable = true; runner = {
enable = true;
vbox = true;
};
tailscale.enable = true; tailscale.enable = true;
}; };
@@ -86,4 +89,10 @@
"kvm" "kvm"
"podman" "podman"
]; ];
virtualisation.virtualbox.host = {
enableExtensionPack = true;
headless = true;
enableWebService = true;
};
} }
+26 -40
View File
@@ -10,7 +10,14 @@ let
EFI_DIR = "${pkgs.OVMF.fd}/FV/"; EFI_DIR = "${pkgs.OVMF.fd}/FV/";
STORAGE_URL = "s3.thehellings.lan:9000"; STORAGE_URL = "s3.thehellings.lan:9000";
}; };
runnerCfg = file: {
inherit environmentVariables;
authenticationTokenConfigFile = file;
executor = "shell";
limit = cfg.threads;
};
in in
# We want exactly one of these to be true, but not both. Neither can both be false
{ {
options.greg.runner = { options.greg.runner = {
enable = lib.mkEnableOption "Enable as a gitlab-runner with both libvirt and virtualbox"; enable = lib.mkEnableOption "Enable as a gitlab-runner with both libvirt and virtualbox";
@@ -20,24 +27,30 @@ in
type = lib.types.int; type = lib.types.int;
description = "The maximum number of concurrent jobs"; description = "The maximum number of concurrent jobs";
}; };
qemu = lib.mkEnableOption "Enable the qemu host (mutually exclusive with vbox)";
vbox = lib.mkEnableOption "Enable the vbox host (mutually exclusive with qemu)";
}; };
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable ({
# assertions = [
# {
# assertion = cfg.qemu || cfg.vbox && (cfg.qemu != cfg.vbox);
# message = "You must enable exactly one of qemu or vbox";
# }
# ];
# Shared configurations # Shared configurations
age.secrets = { age.secrets = {
qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age; qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age;
vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age; vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age;
}; };
# Defaults to running libvirt support
services.gitlab-runner = { services.gitlab-runner = {
enable = true; enable = true;
settings.concurrent = cfg.threads; settings.concurrent = cfg.threads;
services.qemu = { services = {
inherit environmentVariables; qemu = lib.mkIf cfg.qemu (runnerCfg config.age.secrets.qemu.path);
executor = "shell"; vbox = lib.mkIf cfg.vbox (runnerCfg config.age.secrets.vbox.path);
limit = cfg.threads;
authenticationTokenConfigFile = config.age.secrets.qemu.path;
}; };
}; };
@@ -49,9 +62,11 @@ in
}; };
}; };
users.extraGroups.vboxusers.members = lib.optional cfg.vbox "greg";
virtualisation = { virtualisation = {
libvirtd = { libvirtd = lib.mkIf cfg.qemu {
enable = lib.mkDefault true; enable = true;
allowedBridges = [ allowedBridges = [
"br0" "br0"
"virbr0" "virbr0"
@@ -59,39 +74,10 @@ in
onBoot = "ignore"; # only restart VMs labeled 'autostart' onBoot = "ignore"; # only restart VMs labeled 'autostart'
qemu.ovmf.enable = true; qemu.ovmf.enable = true;
}; };
}; virtualbox.host = lib.mkIf cfg.vbox {
# Boot into this specialisation if you want to build vbox hosts
# with this box at that time
specialisation = {
vbox.configuration = {
users.extraGroups.vboxusers.members = [ "greg" ];
virtualisation = {
libvirtd.enable = false;
virtualbox.host = {
enable = true; enable = true;
enableExtensionPack = true; enableExtensionPack = true;
}; };
}; };
});
services.gitlab-runner.services = lib.mkForce {
vbox = {
inherit environmentVariables;
authenticationTokenConfigFile = config.age.secrets.vbox.path;
executor = "shell";
limit = 5;
};
};
systemd.services.gitlab-runner = {
serviceConfig = {
DevicePolicy = lib.mkForce "auto";
User = "root";
DynamicUser = lib.mkForce false;
};
};
};
};
};
} }