albatros/hcl/builder.hcl

174 lines
3.5 KiB
HCL
Raw Normal View History

2023-03-15 08:21:42 +00:00
job "builder" {
namespace = "ci"
type = "batch"
datacenters = ["neptune", "jupiter", "corrin", "bespin"]
priority = 100
parameterized {
2023-03-15 09:28:09 +00:00
payload = "optional"
2023-03-15 09:16:49 +00:00
meta_required = [ "REPO_URL", "COMMIT", "BRANCH", "FLAVOR" ]
2023-03-15 08:21:42 +00:00
}
reschedule {
attempts = 0
unlimited = false
}
2023-03-22 15:21:15 +00:00
constraint {
distinct_hosts = true
}
2023-03-22 15:24:45 +00:00
group "runner" {
2023-03-22 15:21:15 +00:00
task "warmup-cache" {
driver = "docker"
config {
image = "nixpkgs/nix:nixos-22.11"
args = [ "/tmp/warmup.sh" ]
volumes = [
"local/warmup.sh:/tmp/warmup.sh",
"/var/cache/albatros/nix:/mnt/nix"
]
}
lifecycle {
hook = "prestart"
sidecar = false
}
template {
data = <<EOH
#!/usr/bin/env bash
set -euxo pipefail
if [[ ! -f /mnt/nix/nixos-22.11 ]]; then
rm -rf /mnt/nix/*
cp -r /nix/* /mnt/nix/
touch /mnt/nix/nixos-22.11
echo "initialized cache"
else
echo "cache already initialized"
fi
EOH
destination = "local/warmup.sh"
perms = "555"
}
}
2023-03-22 15:24:45 +00:00
task "executor" {
2023-03-15 08:21:42 +00:00
driver = "docker"
config {
image = "nixpkgs/nix:nixos-22.11"
args = [ "/tmp/builder.sh" ]
volumes = [
"local/builder.sh:/tmp/builder.sh",
2023-03-15 09:28:09 +00:00
"local/nix.conf:/etc/nix/nix.conf",
2023-03-16 11:50:06 +00:00
"local/secrets:/var/run/secrets/albatros",
2023-03-22 15:21:15 +00:00
"/var/cache/albatros/nix:/nix:ro"
2023-03-15 08:21:42 +00:00
]
}
2023-03-15 09:28:09 +00:00
dispatch_payload {
2023-03-16 11:50:06 +00:00
file = "secrets/secret.txt"
2023-03-15 09:28:09 +00:00
}
2023-03-22 15:21:15 +00:00
env {
COMMIT = "${NOMAD_META_COMMIT}"
BRANCH = "${NOMAD_META_BRANCH}"
REPO_URL = "${NOMAD_META_REPO_URL}"
FLAVOR = "${NOMAD_META_FLAVOR}"
NIX_REMOTE = "daemon"
}
2023-03-15 08:21:42 +00:00
template {
data = <<EOH
#!/usr/bin/env bash
set -euxo pipefail
mkdir /workspace
cd /workspace
git init
git remote add origin ${NOMAD_META_REPO_URL}
git fetch origin ${NOMAD_META_COMMIT}
git checkout ${NOMAD_META_COMMIT} -b ${NOMAD_META_BRANCH}
2023-03-16 12:27:57 +00:00
if [[ -s /var/run/secrets/albatros/secret.txt ]]; then
2023-03-16 11:50:06 +00:00
export SECRET_PATH=/var/run/secrets/albatros/secret.txt
fi
2023-03-15 09:16:49 +00:00
./.albatros
2023-03-15 08:21:42 +00:00
EOH
destination = "local/builder.sh"
perms = "555"
}
template {
data = <<EOH
substituters = https://cache.nixos.org https://nix.web.deuxfleurs.fr
trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix.web.deuxfleurs.fr:eTGL6kvaQn6cDR/F9lDYUIP9nCVR/kkshYfLDJf1yKs=
max-jobs = auto
cores = 0
log-lines = 200
filter-syscalls = false
sandbox = false
keep-outputs = true
keep-derivations = true
2023-03-16 11:32:11 +00:00
experimental-features = nix-command flakes
2023-03-15 08:21:42 +00:00
EOH
destination = "local/nix.conf"
}
restart {
attempts = 0
}
2023-03-22 15:21:15 +00:00
resources {
# actual work should be done in the nix daemon
cpu = 100
memory = 500
}
}
task "daemon" {
driver = "docker"
config {
image = "nixpkgs/nix:nixos-22.11"
command = "nix-daemon"
volumes = [
"/var/cache/albatros/nix:/nix"
]
}
template {
data = <<EOH
substituters = https://cache.nixos.org https://nix.web.deuxfleurs.fr
trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix.web.deuxfleurs.fr:eTGL6kvaQn6cDR/F9lDYUIP9nCVR/kkshYfLDJf1yKs=
max-jobs = auto
cores = 0
log-lines = 200
filter-syscalls = false
sandbox = false
keep-outputs = true
keep-derivations = true
experimental-features = nix-command flakes
EOH
destination = "local/nix.conf"
}
restart {
attempts = 0
}
2023-03-15 08:21:42 +00:00
resources {
cpu = 1000
memory = 4000
}
2023-03-22 15:21:15 +00:00
lifecycle {
hook = "prestart"
2023-03-22 15:21:15 +00:00
sidecar = true
}
}
2023-03-15 08:21:42 +00:00
}
}