mirror of
https://gitea.com/gitea/runner.git
synced 2026-09-03 01:47:46 +00:00
fix: automatically add the workspace mount to allowed volumes (#1203)
Automatically allow workspace mounts in `valid_volumes` for the mounts done via `bind_workdir`, this obsoletes the need for `/workspace/**` or other insecure configurations which would expose workspaces between tasks. Reviewed-on: https://gitea.com/gitea/runner/pulls/1203 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
@@ -246,6 +246,9 @@ func (rc *RunContext) validVolumes() []string {
|
|||||||
if rc.Config.SharedToolCache {
|
if rc.Config.SharedToolCache {
|
||||||
volumes = append(volumes, sharedToolCacheVolume)
|
volumes = append(volumes, sharedToolCacheVolume)
|
||||||
}
|
}
|
||||||
|
if rc.Config.BindWorkdir {
|
||||||
|
volumes = append(volumes, rc.Config.Workdir)
|
||||||
|
}
|
||||||
// TODO: add a new configuration to control whether the docker daemon can be mounted
|
// TODO: add a new configuration to control whether the docker daemon can be mounted
|
||||||
return append(volumes, name, name+"-env",
|
return append(volumes, name, name+"-env",
|
||||||
getDockerDaemonSocketMountPath(rc.containerDaemonSocket()))
|
getDockerDaemonSocketMountPath(rc.containerDaemonSocket()))
|
||||||
|
|||||||
@@ -604,6 +604,11 @@ func TestRunContextValidVolumes(t *testing.T) {
|
|||||||
// a job may mount it only while the runner does
|
// a job may mount it only while the runner does
|
||||||
rc.Config.SharedToolCache = false
|
rc.Config.SharedToolCache = false
|
||||||
assert.NotContains(t, rc.validVolumes(), sharedToolCacheVolume)
|
assert.NotContains(t, rc.validVolumes(), sharedToolCacheVolume)
|
||||||
|
|
||||||
|
rc.Config.Workdir = "/workspace/1/owner/repo"
|
||||||
|
assert.NotContains(t, rc.validVolumes(), rc.Config.Workdir)
|
||||||
|
rc.Config.BindWorkdir = true
|
||||||
|
assert.Contains(t, rc.validVolumes(), rc.Config.Workdir)
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCleanupJobResourcesCleansServicesWithoutJobContainer(t *testing.T) {
|
func TestCleanupJobResourcesCleansServicesWithoutJobContainer(t *testing.T) {
|
||||||
|
|||||||
@@ -260,7 +260,7 @@ container:
|
|||||||
# This is required for Docker-in-Docker (DinD) setups when jobs use docker compose
|
# This is required for Docker-in-Docker (DinD) setups when jobs use docker compose
|
||||||
# with bind mounts (e.g., ".:/app"), as volume-based workspaces are not accessible
|
# with bind mounts (e.g., ".:/app"), as volume-based workspaces are not accessible
|
||||||
# from the DinD daemon's filesystem. When enabled, ensure the workspace parent
|
# from the DinD daemon's filesystem. When enabled, ensure the workspace parent
|
||||||
# directory is also mounted into the runner container and listed in valid_volumes.
|
# directory is also mounted into the runner container.
|
||||||
#bind_workdir: false
|
#bind_workdir: false
|
||||||
# How long a job waits for a service container that declares a healthcheck to become
|
# How long a job waits for a service container that declares a healthcheck to become
|
||||||
# healthy. A negative value (e.g. -1s) starts the steps without waiting.
|
# healthy. A negative value (e.g. -1s) starts the steps without waiting.
|
||||||
|
|||||||
Reference in New Issue
Block a user