ci: add probe-runner workflow for Docker and buildx capabilities #11

Merged
piscis merged 2 commits from piscis/forgejo-runner-implement into main 2026-09-30 13:28:43 +00:00
Owner

Summary

Adds a manually dispatched probe of what the docker runner can do for a multi-arch buildx build of the Image. Closes #3.

probe-runner (workflow_dispatch, runs-on: docker, container: docker:cli)
  Job container          os-release, hostname, uid
  Docker daemon          DOCKER_HOST, /var/run/docker.sock, docker info, is the job container visible to the daemon
  buildx                 buildx version, buildx ls, buildx inspect --bootstrap
  Host architecture      uname -m, docker info arch/NCPU/kernel
  arm64 emulation        binfmt_misc check, tonistiigi/binfmt --install arm64, arm64 alpine uname -m
  Full report            prints every section again (this Forgejo has no job summaries)

Every step is continue-on-error and every probe uses || true.

Evidence

  • Before: nobody knew whether the runner could reach a daemon or build arm64.
    After: run #2 (on the final commit) succeeded:
    DOCKER_HOST=tcp://docker_dind:2376
    job container visible to daemon: yes
    buildx v0.37.1 · platforms: linux/amd64, linux/amd64/v2, linux/amd64/v3, linux/arm64
    uname -m: x86_64
    docker run --platform linux/arm64 alpine uname -m → aarch64
    
    The full findings are in the comment on #3.

Merge Danger

Door: two-way

The workflow only runs when someone dispatches it. Running it registers qemu-aarch64 binfmt on the runner host kernel, and that stays until reboot. It is harmless, but it is a side effect on a shared runner.

Blast Radius: none

Nothing triggers it automatically, and it publishes nothing.

## Summary Adds a manually dispatched probe of what the `docker` runner can do for a multi-arch buildx build of the Image. Closes #3. ```text probe-runner (workflow_dispatch, runs-on: docker, container: docker:cli) Job container os-release, hostname, uid Docker daemon DOCKER_HOST, /var/run/docker.sock, docker info, is the job container visible to the daemon buildx buildx version, buildx ls, buildx inspect --bootstrap Host architecture uname -m, docker info arch/NCPU/kernel arm64 emulation binfmt_misc check, tonistiigi/binfmt --install arm64, arm64 alpine uname -m Full report prints every section again (this Forgejo has no job summaries) ``` Every step is `continue-on-error` and every probe uses `|| true`. ## Evidence - **Before:** nobody knew whether the runner could reach a daemon or build arm64. **After:** run #2 (on the final commit) succeeded: ```text DOCKER_HOST=tcp://docker_dind:2376 job container visible to daemon: yes buildx v0.37.1 · platforms: linux/amd64, linux/amd64/v2, linux/amd64/v3, linux/arm64 uname -m: x86_64 docker run --platform linux/arm64 alpine uname -m → aarch64 ``` The full findings are in the comment on #3. ## Merge Danger **Door:** two-way The workflow only runs when someone dispatches it. Running it registers qemu-aarch64 binfmt on the runner host kernel, and that stays until reboot. It is harmless, but it is a side effect on a shared runner. **Blast Radius:** none Nothing triggers it automatically, and it publishes nothing.
Manually dispatchable workflow on the docker runner label that reports
daemon reachability, buildx builders and platforms, host arch, and
arm64 emulation. All probes are non-fatal.

Refs #3
With network=host the job container's hostname is the dind container's,
so look up the job container ID from /proc/self/mountinfo instead.
buildx ls truncates platforms, so also run buildx inspect.

Refs #3
piscis merged commit 184028de1c into main 2026-09-30 13:28:43 +00:00
piscis deleted branch piscis/forgejo-runner-implement 2026-09-30 13:28:43 +00:00
Sign in to join this conversation.
No description provided.