argand-site-registry/ci/README.md
nicweyand e83f43d00f
All checks were successful
Standalone registry checks / check (push) Successful in 3m43s
feat: harden reviewed registry releases
2026-09-13 01:19:27 -04:00

19 lines
827 B
Markdown

# Isolated Forgejo runner image
Build the reviewed pinned image and register a repository-scoped runner with only
the container label below:
```bash
docker build --pull -t argand-site-registry-ci:0.2.0 -f ci/Dockerfile .
forgejo-runner register --no-interactive \
--instance https://git.argand.org \
--token REPOSITORY_REGISTRATION_TOKEN \
--name argand-site-registry-isolated \
--labels site-registry-isolated:docker://argand-site-registry-ci:0.2.0
```
Run the daemon with capacity one, no host label, no bind-volume allowlist, no
Docker socket inside jobs, `privileged: false`, and container limits of two CPUs,
4 GiB memory and 4 GiB memory plus swap. The workflow fetches the exact public
commit without repository credentials. This runner contains no dataset, reviewer,
release-signing or activation authority.