mirror of
https://gitea.com/gitea/act_runner
synced 2026-09-21 19:37:07 +02:00
enhance: bind-mount job paths through the docker proxy (#1226)
Containers a job starts through its Docker socket, for example `docker run -v "$PWD:/src"`, `./data:/data` in docker compose, or actions like dockerfile-roast, can now bind-mount the workspace and other paths the job sees, as on a host, without `bind_workdir`. The per-job Docker proxy rewrites container and volume create requests. A bind source, or the device of a `local` volume with `o: bind`, that lies under one of the job container's mounts is pointed at that mount's path on the daemon, read from inspecting the job container. Paths that already name a daemon path, like `GITEA_DOCKER_WORKSPACE`, and paths outside the job's mounts pass through unchanged. The proxy now also starts when the runner runs in a container given the host's Docker socket, by placing its socket in the runner's working directory, and in rootless dind, by granting the daemon socket's group through an ACL. Fixes https://gitea.com/gitea/runner/issues/1219 Fixes https://gitea.com/gitea/runner/issues/1193 Reviewed-on: https://gitea.com/gitea/runner/pulls/1226 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: silverwind <2021+silverwind@noreply.gitea.com>
This commit is contained in:
@@ -14,6 +14,7 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
"os"
|
||||
"path"
|
||||
"path/filepath"
|
||||
"reflect"
|
||||
"regexp"
|
||||
@@ -257,6 +258,27 @@ func containerInfoFromInspect(inspect container.InspectResponse) *Info {
|
||||
for _, mountPoint := range inspect.Mounts {
|
||||
info.Mounts[mountPoint.Destination] = mountPoint.Source
|
||||
}
|
||||
if hostConfig := inspect.HostConfig; hostConfig != nil { // Mounts omits --tmpfs targets and subpaths
|
||||
for target := range hostConfig.Tmpfs {
|
||||
info.Mounts[path.Clean(target)] = ""
|
||||
}
|
||||
for _, spec := range hostConfig.Mounts {
|
||||
subpath := ""
|
||||
if spec.VolumeOptions != nil {
|
||||
subpath = spec.VolumeOptions.Subpath
|
||||
} else if spec.ImageOptions != nil {
|
||||
subpath = spec.ImageOptions.Subpath
|
||||
}
|
||||
if target := path.Clean(spec.Target); subpath != "" && info.Mounts[target] != "" {
|
||||
info.Mounts[target] = path.Join(info.Mounts[target], subpath)
|
||||
}
|
||||
}
|
||||
}
|
||||
for _, target := range []string{"/etc/hosts", "/etc/hostname", "/etc/resolv.conf"} { // specific to the job's network namespace
|
||||
if _, mounted := info.Mounts[target]; !mounted {
|
||||
info.Mounts[target] = ""
|
||||
}
|
||||
}
|
||||
|
||||
if state := inspect.State; state != nil {
|
||||
info.State = string(state.Status)
|
||||
|
||||
Reference in New Issue
Block a user