No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Fynn Tristan Mahringer 13797b0bd5
Some checks failed
Build and Push Runner Images / build-and-push (push) Failing after 2m44s
Merge pull request 'fix: install pinned yq in java runner' (#2) from codex/runner-image-versioning into main
Reviewed-on: #2
2026-09-02 20:55:58 +02:00
.forgejo/workflows ci: harden runner image publishing 2026-09-02 20:27:06 +02:00
docs/superpowers docs: clarify latest runner tag policy 2026-09-02 20:21:56 +02:00
java-runner fix: install pinned yq in java runner 2026-09-02 20:53:09 +02:00
security-runner docs: document versioned runner images 2026-09-02 20:13:35 +02:00
README.md docs: tag local runner builds by version 2026-09-02 20:20:00 +02:00
VERSION feat: add runner image metadata 2026-09-02 19:57:29 +02:00

Forgejo Runner Images

This repository is split into two independent image trees so they can later become separate repos and separate Docker images:

  • java-runner/ for Java build workloads
  • security-runner/ for Trivy and security workloads

The Forgejo Runner daemon is managed by your existing runner-registration script. This repo only provides the job images that the script will reference in runner labels, such as java-ci:docker://docker-hosted.nexus.ftmahringer.com/forgejo-runner-java:1.0.0.

For the CI workflow in .forgejo/workflows/build-and-push.yml, register an ubuntu label in your runner script that points at the immutable docker-hosted.nexus.ftmahringer.com/forgejo-runner-java:${VERSION} tag. That image contains the Docker CLI and Buildx tooling needed to build and push both images.

Build and push

Use your Nexus secrets:

The Forgejo workflow performs the Nexus login and push directly. If you build locally, use:

printf '%s' "$NEXUS_PASSWORD" | docker login docker-hosted.nexus.ftmahringer.com -u "$NEXUS_USERNAME" --password-stdin
version="$(< VERSION)"
revision="$(git rev-parse HEAD)"
docker buildx build --push \
  --build-arg RUNNER_VERSION="${version}" \
  --build-arg VCS_REF="${revision}" \
  -t "docker-hosted.nexus.ftmahringer.com/forgejo-runner-java:${version}" \
  -t docker-hosted.nexus.ftmahringer.com/forgejo-runner-java:latest \
  ./java-runner
docker buildx build --push \
  --build-arg RUNNER_VERSION="${version}" \
  --build-arg VCS_REF="${revision}" \
  -t "docker-hosted.nexus.ftmahringer.com/forgejo-runner-security:${version}" \
  -t docker-hosted.nexus.ftmahringer.com/forgejo-runner-security:latest \
  ./security-runner

Release and runner selection

VERSION is manually maintained. To publish a release, update and commit VERSION, then create and push the matching Git tag v${VERSION}. For example, VERSION=1.0.0 requires the release tag v1.0.0.

A matching v${VERSION} release publishes and retains its immutable ${VERSION} image tag while overwriting latest. Main and manual workflow runs also overwrite latest, so latest is always the most recent published image and is convenience-only. Runner labels must select the immutable ${VERSION} image tag that was published for the intended release, not latest.

The workflow uses the following Nexus targets:

  • docker-hosted.nexus.ftmahringer.com/forgejo-runner-java
  • docker-hosted.nexus.ftmahringer.com/forgejo-runner-security

Scope

  • Build and publish the Java runner image
  • Build and publish the Security runner image
  • Keep the repository structure ready for later split into two repos