rig/commands
cluade-reviewer-andresmgsl a45d84892f
Some checks failed
ci / check (pull_request) Failing after 7s
ci / install (pull_request) Successful in 4s
ci / db-integration (pull_request) Successful in 4s
labels / labels (pull_request) Failing after 7s
fix(forgejo-runner): the cache server can start
ProtectHome=read-only made the whole home read-only and only RUNNER_DIR was
punched back through, so forgejo-runner could not create $HOME/.cache and
disabled its cache server on every install. actions/cache was silently off on
every rig-installed Forgejo runner, evidenced by one error line in the journal
while `status` reported a healthy runner.

Both halves are required, and the obvious one-line version is WORSE than the
bug: a ReadWritePaths entry naming a path that does not exist makes systemd
refuse to start the unit at all — "Failed to set up mount namespacing", three
restart attempts, service down. Measured on a live runner before writing this.

So the directory is created at install, owned by the runner user like
RUNNER_DIR beside it, and the unit lists it. ProtectHome stays read-only: the
runner supervises job containers on this box's docker socket, and the cache is
not a reason to widen that.

Verified live from scratch: directory removed, unit removed, converge, then
zero cache-server errors and the two cache listeners bound.

Closes #135

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 16:59:03 +00:00
..
lib fix: the --version read cannot die ahead of its own refusal 2026-07-28 09:26:17 +00:00
bootstrap-tenant.sh test: drive cron converge against stubbed systemctl 2026-07-25 19:11:13 +00:00
bootstrap-undo.sh feat: Forgejo-native CI — a ci-box tenant and a forgejo-runner family 2026-07-27 20:40:54 +00:00
bootstrap.sh fix: emit BOX_MANUAL line-by-line; bare command for single candidate 2026-07-29 22:38:32 +00:00
coolify-backup-install.sh fix: release channel is tag-only; revert coolify Documentation= 2026-07-29 14:45:40 +00:00
coolify-install.sh feat(bootstrap)!: machine roles carry a -server suffix; staging-server restored 2026-07-20 00:36:00 +00:00
db.sh feat(db): bring ad-hoc dump/restore on-box as rig db 2026-07-17 15:16:35 +00:00
forgejo-runner-install.sh fix(forgejo-runner): the cache server can start 2026-07-31 16:59:03 +00:00
forgejo-runner-remove.sh fix: one checksum policy, labeler coverage, orphaned-unit removal 2026-07-27 21:19:33 +00:00
forgejo-runner-status.sh feat: Forgejo-native CI — a ci-box tenant and a forgejo-runner family 2026-07-27 20:40:54 +00:00
manifest.sh feat: /etc/rig/manifest — which rig converged this machine, and when 2026-07-20 12:48:39 +00:00
platform.sh feat(platform): ID names the machine — a namespaced sha256 of /etc/machine-id, computed at run time, stored nowhere (#95) 2026-07-24 07:48:45 +00:00
runner-install.sh fix: headless credential prompts refuse loudly, naming their variable (#42) 2026-07-19 12:15:08 +00:00
runner-remove.sh fix: headless credential prompts refuse loudly, naming their variable (#42) 2026-07-19 12:15:08 +00:00
runner-repoint.sh fix: headless credential prompts refuse loudly, naming their variable (#42) 2026-07-19 12:15:08 +00:00
runner-status.sh fix(runner): install refuses a box registered to another repo 2026-07-13 14:57:28 +00:00
template-lint.sh test: cover machine template registry 2026-07-25 11:00:21 +00:00
users-apply.sh fix: gate 'users apply' on an empty file that would revoke everyone 2026-07-20 12:25:09 +00:00
users-close-root.sh fix: don't read a missing /run/sshd as a broken sshd config 2026-07-20 17:58:10 +00:00
users-status.sh fix(users): review findings — invoker gate, real SSH revocation, StrictModes-shaped close-root gate, trait-aware box role 2026-07-17 20:01:19 +00:00