-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.bootstrap.example
More file actions
67 lines (49 loc) · 4.66 KB
/
Copy path.env.bootstrap.example
File metadata and controls
67 lines (49 loc) · 4.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
# Input for ./bootstrap.sh: copy to .env.bootstrap (gitignored) and fill in. bootstrap.sh turns these into variables for the Ansible role and runs it against this machine, so this file is only for a host brought up without an Ansible control node - hosts managed from a control node use their inventory's host_vars instead (see examples/). Not to be confused with the .env the role itself generates on every run in the node's Compose project directory.
# ---- k3s -------------------------------------------------------------------
# Arbitrary shared secret for node-join auth inside the k3s cluster, unrelated to GitHub (e.g. `openssl rand -hex 32`). The same value on every server/agent host.
K3S_TOKEN=
# A reusable, pre-authorized Tailscale auth key: k3s's own --vpn-auth integration runs Tailscale inside each node's k3s container with it. See the README's Tailscale section for how it's provisioned.
K3S_VPN_AUTH_JOIN_KEY=
# Optional: a Tailscale API token. When set, the role also ensures the tailnet's ACL grants cross-node pod traffic (see roles/github_runner_cluster/tasks/mesh/tailscale_api.yml). Without it the ACL is left as it is.
TAILSCALE_API_TOKEN=
# Every server's own Tailscale hostname, space-separated, including this one's own. Leave empty on a single-server setup, which then uses this host's node name. A multi-server cluster needs every server's cert to cover every server's name; see the README's Architecture section.
K3S_TLS_SAN_LIST=
# This host's k3s node name, which is also its Tailscale device hostname. Leave empty to use this machine's own short hostname.
K3S_NODE_NAME=
# Only on a server joining an EXISTING cluster: an already-running server's https://<address>:6443. Leave empty on the server that bootstraps the cluster.
K3S_JOIN_SERVER_URL=
# Only on a pure worker (agent) host: a server's https://<address>:6443. Setting this makes bootstrap.sh join as an agent instead of a server; K3S_AGENT_NODE_NAME replaces K3S_NODE_NAME for it.
K3S_AGENT_SERVER_URL=
K3S_AGENT_NODE_NAME=
# k3s image version (rancher/k3s tag). Empty means latest.
K3S_VERSION=
# The directory the role keeps this node's Compose project, .env and kubeconfig in. Empty means ~/.github-runner.
GITHUB_RUNNER_CLUSTER_DIR=
# The Compose project name, which prefixes the volumes holding the cluster's data. Empty means github-runner. A host brought up by an earlier release, which ran Compose in the checkout, has volumes named after the checkout's directory: if that directory is not called github-runner, set this to its name, or the node starts again with empty volumes.
GITHUB_RUNNER_COMPOSE_PROJECT=
# ---- The org's runner scale set (leave RUNNER_APP_ID empty on a host that installs no org) ----
# The GitHub organisation the runners register with, and its GitHub App (see playbooks/github_app_setup.yml to create one). The installation ID is resolved automatically from the App ID and key when left empty.
RUNNER_ORG=
RUNNER_APP_ID=
RUNNER_APP_INSTALLATION_ID=
RUNNER_APP_PRIVATE_KEY_PATH=./secrets/app-private-key.pem
# The runner image the scale set's pods run (built from this repository's Dockerfile, or any actions-runner image).
RUNNER_IMAGE=
# The scale set's Helm values: either a values file (a Jinja template, relative to this checkout or absolute), or the ARC role's own template with this many runners at most.
RUNNER_VALUES_FILE=
RUNNER_MAX_RUNNERS=4
# A registry credential for pulling the runner image and the fleet-health platform's images, such as a GHCR personal access token with read:packages scope.
GHCR_PULL_USERNAME=
GHCR_PULL_TOKEN=
# ---- Fleet-health platform (heartbeat + autoscaler) ----
# HEARTBEAT_GH_TOKEN is a GitHub PAT with `gist` scope, used to refresh a secret gist a fallback action (such as ExaDev/runner-fallback-action) reads to decide between the self-hosted runners and GitHub-hosted ones. Leave HEARTBEAT_GIST_ID empty on first run and the role creates the gist and stops, printing its id to put here.
HEARTBEAT_GH_TOKEN=
HEARTBEAT_GIST_ID=
# The usage-driven autoscaler (see scripts/autoscaler.sh and the README's Autoscaler section) manages the scale set only when AUTOSCALER_USABLE_BUDGET_GI is set, and then also needs AUTOSCALER_MAX_CEILING and AUTOSCALER_FLOOR: the memory runner pods may use across every node in GiB, the highest maxRunners it may set, and the maxRunners in the scale set's values, which every Helm upgrade reverts to. They depend on the machines, so they have no defaults. The rest default to the role's own values (roles/github_runner_arc/defaults/main.yml).
# AUTOSCALER_USABLE_BUDGET_GI=
# AUTOSCALER_MAX_CEILING=
# AUTOSCALER_FLOOR=
# AUTOSCALER_DRY_RUN=true
# AUTOSCALER_POLL_SECONDS=45
# AUTOSCALER_RAISE_CONFIRM_POLLS=2
# AUTOSCALER_MEM_AVAILABLE_PRESSURE_PCT=15