rig/changelog.d
cluade-reviewer-andresmgsl a45d84892f
Some checks failed
ci / check (pull_request) Failing after 7s
ci / install (pull_request) Successful in 4s
ci / db-integration (pull_request) Successful in 4s
labels / labels (pull_request) Failing after 7s
fix(forgejo-runner): the cache server can start
ProtectHome=read-only made the whole home read-only and only RUNNER_DIR was
punched back through, so forgejo-runner could not create $HOME/.cache and
disabled its cache server on every install. actions/cache was silently off on
every rig-installed Forgejo runner, evidenced by one error line in the journal
while `status` reported a healthy runner.

Both halves are required, and the obvious one-line version is WORSE than the
bug: a ReadWritePaths entry naming a path that does not exist makes systemd
refuse to start the unit at all — "Failed to set up mount namespacing", three
restart attempts, service down. Measured on a live runner before writing this.

So the directory is created at install, owned by the runner user like
RUNNER_DIR beside it, and the unit lists it. ProtectHome stays read-only: the
runner supervises job containers on this box's docker socket, and the cache is
not a reason to widen that.

Verified live from scratch: directory removed, unit removed, converge, then
zero cache-server errors and the two cache listeners bound.

Closes #135

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 16:59:03 +00:00
..
109.md docs: the changelog fragment cites bare #109 2026-07-28 09:26:17 +00:00
111.md docs: shorten changelog.d/111.md under the 300-char entry guard 2026-07-29 14:45:57 +00:00
112.md docs: the changelog fragment says what changed and stops 2026-07-29 12:22:08 +00:00
116.md fix: preserve triage across both forges 2026-07-30 18:31:16 +00:00
135.md fix(forgejo-runner): the cache server can start 2026-07-31 16:59:03 +00:00
152.md fix: group machine role changelog entry 2026-07-25 13:07:01 +00:00
153.md fix: group template snapshot changelog entry 2026-07-25 16:00:29 +00:00
160.md fix: scope the netmap tag read to Self 2026-07-25 16:02:54 +00:00
162.md fix: arm cron on agent tenant boxes 2026-07-25 18:54:27 +00:00
README.md feat: convert unreleased changelog to fragments 2026-07-24 13:55:28 +00:00

changelog.d/ — the next release's section, one fragment per issue

Machine-assembled by bin/changelog-assemble (#112): every PR that changes behavior writes one file here — <issue>.md, the exact prose that will be published, nothing else — and the release PR folds them all into the next ## X.Y.Z — DATE section of CHANGELOG.md, consuming them. Distinct filenames never conflict, which is this directory's whole reason to exist. This README is the marker that keeps the directory tracked when it holds no fragments (#112 D1) — changelog-armed refuses a tree without it; do not delete it.