From 749173a9d538cbf11826aae4986420f29457e9ef Mon Sep 17 00:00:00 2001 From: Cloud User Date: Wed, 11 Mar 2026 13:16:23 +0900 Subject: [PATCH] Revert "Replace K8s pod runner with VM runner (soo-runner)" This reverts commit 17a0761d97408a60946ded3556c039b66190d7d4. --- README.md | 37 ++++++----- config.yaml | 14 ++--- gitea-runner/deployment.yaml | 116 +++++++++++++++++++++++++++++++++++ 3 files changed, 143 insertions(+), 24 deletions(-) create mode 100644 gitea-runner/deployment.yaml diff --git a/README.md b/README.md index 0e5607d..997ea88 100644 --- a/README.md +++ b/README.md @@ -23,7 +23,7 @@ https://gitea.inje-private.com/selee/mlops-architecture | 컴포넌트 | 상태 | 위치 | |----------|------|------| | Gitea | installed | 외부 클러스터 | -| Gitea Runner | **installed** (v0.3.0) | VM (`soo-runner`) | +| Gitea Runner | **installed** (v0.3.0) | 이 클러스터 (`soo` ns) | | ArgoCD | installed + **repo 연동 완료** | 이 클러스터 (`argocd` ns) | | DVC | **installed** (v3.66.1) | 로컬 + NAS (`/ainas/dvc-storage`) | @@ -78,29 +78,30 @@ git push -u origin main --- -## 2. Gitea Runner (설치 완료 — VM 방식) +## 2. Gitea Runner (설치 완료) -전용 VM(`soo-runner`)에 act_runner를 직접 설치하여 systemd 서비스로 운영. +이 클러스터 `soo` 네임스페이스에 배포. Docker-in-Docker(DinD) sidecar 방식. -- **호스트**: `ssh ubuntu@runner` (호스트명: `soo-runner`) -- **Runner 이름**: `soo-runner` -- **바이너리**: `/usr/local/bin/act_runner` -- **작업 디렉토리**: `/opt/act_runner/` -- **서비스**: `/etc/systemd/system/act_runner.service` (enabled, auto-restart) -- **Labels**: `ubuntu-latest`, `ubuntu-22.04` (Docker), `self-hosted` (Host) -- **Gitea instance**: `https://gitea.inje-private.com` +- Runner 이름: `mlops-runner` +- 이미지: `gitea/act_runner:latest` (v0.3.0) +- Labels: `ubuntu-latest`, `ubuntu-22.04`, `self-hosted` +- Gitea instance: `https://gitea.inje-private.com` ```bash -# 상태 확인 -ssh ubuntu@runner "sudo systemctl status act_runner" +# 1. repo에서 Actions 활성화 (API) +curl -sk -X PATCH "https://gitea.inje-private.com/api/v1/repos/selee/mlops-architecture" \ + -u "$GITEA_ADMIN_USER:$GITEA_ADMIN_PASSWORD" \ + -H "Content-Type: application/json" \ + -d '{"has_actions": true}' -# 로그 확인 -ssh ubuntu@runner "journalctl -u act_runner -f" +# 2. Runner 배포 +kubectl apply -f gitea-runner/deployment.yaml -# 재시작 -ssh ubuntu@runner "sudo systemctl restart act_runner" +# 3. 상태 확인 +kubectl get pods -n soo -l app=gitea-runner +kubectl logs -n soo -l app=gitea-runner -c runner --tail=20 -# Gitea에서 Runner 등록 확인 +# 4. Gitea에서 Runner 등록 확인 # https://gitea.inje-private.com/selee/mlops-architecture/settings/actions/runners ``` @@ -209,6 +210,8 @@ mlops_architecture/ ├── argocd/ │ └── application.yaml # ArgoCD Application 정의 ├── config.yaml # 인프라 구성 정보 +├── gitea-runner/ +│ └── deployment.yaml # Gitea Runner K8s 배포 ├── manifests/ # K8s 배포 manifest (ArgoCD 감시) │ └── deployment.yaml # 서빙 Deployment + Service └── README.md # 설치 가이드 (이 파일) diff --git a/config.yaml b/config.yaml index 51ffd16..07231e1 100644 --- a/config.yaml +++ b/config.yaml @@ -34,14 +34,14 @@ components: installed: true # 외부에서 운영 중 gitea_runner: - location: vm # 전용 VM에 직접 설치 - host: soo-runner # ssh ubuntu@runner + location: this_cluster + namespace: soo version: v0.3.0 # act_runner version - deploy_type: systemd # systemd service on VM - runner_name: soo-runner - binary: /usr/local/bin/act_runner - workdir: /opt/act_runner - service_file: /etc/systemd/system/act_runner.service + image: gitea/act_runner:latest + deploy_type: kubernetes # Deployment + DinD sidecar + runner_name: mlops-runner + node_selector: + nodegroup: nd labels: - ubuntu-latest - ubuntu-22.04 diff --git a/gitea-runner/deployment.yaml b/gitea-runner/deployment.yaml new file mode 100644 index 0000000..6783d8a --- /dev/null +++ b/gitea-runner/deployment.yaml @@ -0,0 +1,116 @@ +apiVersion: v1 +kind: Secret +metadata: + name: gitea-runner-secret + namespace: soo +type: Opaque +stringData: + token: cLwr1iibt23oBSMqcWUJ6vcn3Wj8DQI9huCe2ATK +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: gitea-runner-config + namespace: soo +data: + config.yaml: | + log: + level: info + runner: + file: .runner + capacity: 1 + timeout: 3h + labels: + - "ubuntu-latest:docker://catthehacker/ubuntu:act-22.04" + - "ubuntu-22.04:docker://catthehacker/ubuntu:act-22.04" + - "self-hosted:host" + container: + network: "" + privileged: false + options: + valid_volumes: [] + host: + workdir_parent: /data/cache +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: gitea-runner + namespace: soo + labels: + app: gitea-runner +spec: + replicas: 1 + selector: + matchLabels: + app: gitea-runner + template: + metadata: + labels: + app: gitea-runner + spec: + nodeSelector: + nodegroup: nd + containers: + - name: runner + image: gitea/act_runner:latest + command: + - sh + - -c + - | + # Wait for DinD TLS certs to be ready + echo "Waiting for Docker daemon..." + while [ ! -f /certs/client/ca.pem ]; do sleep 1; done + sleep 2 + echo "Docker daemon is ready" + # Register if not already registered + if [ ! -f /data/.runner ]; then + act_runner register --no-interactive \ + --instance https://gitea.inje-private.com \ + --token $(cat /secrets/token) \ + --name mlops-runner \ + --labels "ubuntu-latest:docker://catthehacker/ubuntu:act-22.04,ubuntu-22.04:docker://catthehacker/ubuntu:act-22.04,self-hosted:host" + fi + act_runner daemon --config /config/config.yaml + env: + - name: DOCKER_HOST + value: tcp://localhost:2376 + - name: DOCKER_TLS_VERIFY + value: "1" + - name: DOCKER_CERT_PATH + value: /certs/client + volumeMounts: + - name: runner-data + mountPath: /data + - name: runner-config + mountPath: /config + - name: runner-secret + mountPath: /secrets + - name: docker-certs + mountPath: /certs + - name: docker-in-docker + image: docker:dind + args: + - --mtu=1340 + - --default-network-opt=bridge=com.docker.network.driver.mtu=1340 + securityContext: + privileged: true + env: + - name: DOCKER_TLS_CERTDIR + value: /certs + volumeMounts: + - name: docker-certs + mountPath: /certs + - name: runner-data + mountPath: /data + volumes: + - name: runner-data + emptyDir: {} + - name: docker-certs + emptyDir: {} + - name: runner-config + configMap: + name: gitea-runner-config + - name: runner-secret + secret: + secretName: gitea-runner-secret