Skip to content

fix(svc-gh-runner-logs): silence ./run line 228 /proc/PID/cmdline race #19

fix(svc-gh-runner-logs): silence ./run line 228 /proc/PID/cmdline race

fix(svc-gh-runner-logs): silence ./run line 228 /proc/PID/cmdline race #19

Workflow file for this run

# Caller for the hub's `bos-launchpad.yml` (Blackout Secure Launchpad) reusable.
#
# monitor (github_release mode → actions/runner) → release (docker → balena → github release)
#
# Required vars: DOCKERHUB_NAMESPACE, BALENA_NAMESPACE
# Required secrets: DOCKERHUB_USERNAME, DOCKERHUB_TOKEN, BALENA_API_TOKEN
#
# `balena.yml` is rendered by the hub on each run from the `balena_*` inputs
# below. See blackoutsecure/bos-automation-hub for the full input reference.
name: Blackout Secure Launchpad
on:
schedule:
- cron: '17 */6 * * *' # stagger off :00 to dodge org cron pile-ups
push:
branches:
- main
paths:
- 'Dockerfile'
- '.dockerignore'
- 'build/**'
- 'root/**'
- 'docker-compose.yml'
- 'README.md'
- '.github/upstream/**'
- '.github/workflows/bos-launchpad.yml'
workflow_dispatch:
inputs:
stage_docker:
description: 'Stage: docker build & push'
type: boolean
default: true
stage_balena:
description: 'Stage: balena block publish'
type: boolean
default: true
stage_github_release:
description: 'Stage: GitHub Release publish'
type: boolean
default: true
# Push events always rebuild via the `with: force_run:`
# expression below; this checkbox only affects on-demand
# `workflow_dispatch` runs.
force_run:
description: 'Force: run pipeline even if upstream unchanged'
type: boolean
default: false
# `auto` lets the hub decide prerelease from the SemVer suffix.
# `'true'`/`'false'` force the flag. Ignored unless
# `stage_github_release` is on.
release_prerelease:
description: 'Release: prerelease flag (only for stage_github_release)'
type: choice
options: [auto, 'true', 'false']
default: auto
# No top-level `concurrency:` — the hub workflow owns serialization.
# Declaring it on both sides triggers a GHA self-deadlock.
permissions:
contents: read
jobs:
release:
permissions:
contents: write # monitor tracking-file commit + GitHub Release publish
actions: write # nested monitor (`gh workflow run`)
pull-requests: write # nested Docker Scout PR annotations
security-events: write # nested Docker Scout SARIF upload
uses: blackoutsecure/bos-automation-hub/.github/workflows/bos-launchpad.yml@main
with:
# Schedule + push runs use the defaults; manual runs honour the
# dispatch checkboxes. Every launchpad stage defaults to `false`
# in the hub — opt in explicitly.
docker: ${{ github.event_name != 'workflow_dispatch' || inputs.stage_docker }}
balena: ${{ github.event_name != 'workflow_dispatch' || inputs.stage_balena }}
github_release: ${{ github.event_name != 'workflow_dispatch' || inputs.stage_github_release }}
upstream_repo: actions/runner
track_file: .github/upstream/actions-runner.json
# Push always rebuilds; schedule only when upstream moves.
force_run: ${{ github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && inputs.force_run) }}
# When force_run is a manual dispatch, also bypass downstream caches
# so the rebuild ACTUALLY produces a fresh image + balena release.
# Without these, docker re-uses GHA layer cache (same digest) and balena
# returns the existing release for the same source SHA — the "force"
# ends up being a no-op deploy from the device's perspective.
docker_force: ${{ github.event_name == 'workflow_dispatch' && inputs.force_run }}
balena_force: ${{ github.event_name == 'workflow_dispatch' && inputs.force_run }}
image_name: github-runner
dockerhub_namespace: ${{ vars.DOCKERHUB_NAMESPACE }}
balena_namespace: ${{ vars.BALENA_NAMESPACE }}
# Render balena.yml dynamically — no checked-in copy.
balena_generate_yml: true
# Preserve the historical device-type matrix from the old balena.yml.
balena_default_device_type: raspberrypi3-64
balena_supported_device_types: |
raspberrypi3
raspberrypi3-64
raspberrypi4
raspberrypi4-64
raspberrypi400
raspberrypi400-64
intel-nuc
genericx86-64-ext
balena_description: >-
Containerized GitHub Actions self-hosted runner with s6 process supervision,
non-root defaults, and ephemeral mode support. Features automatic token
generation via GitHub PAT, Docker-in-Docker support, and built-in health
monitoring for CI/CD workloads on IoT and edge devices.
balena_post_provisioning: |
## Usage instructions
Include this snippet in your docker-compose.yml file under 'services':
```
gh-runner:
image: docker.io/${{ vars.DOCKERHUB_NAMESPACE }}/github-runner:latest
restart: unless-stopped
environment:
- TZ=Etc/UTC
- RUNNER_URL=https://github.com/OWNER/REPO
- RUNNER_TOKEN=YOUR_REGISTRATION_TOKEN
- RUNNER_NAME=my-runner
- LOG_LEVEL=info
volumes:
- '/path/to/runner/config:/config'
- '/var/run/docker.sock:/var/run/docker.sock'
security_opt:
- 'no-new-privileges:true'
```
Repository: https://github.com/${{ github.repository }}
Upstream application: https://github.com/actions/runner
# `release_prerelease`: `auto` collapses to empty (hub decides from
# the SemVer suffix); `'true'`/`'false'` force the flag. Collapses
# to `''` outside `workflow_dispatch`.
release_prerelease: ${{ (github.event_name == 'workflow_dispatch' && inputs.release_prerelease != 'auto') && inputs.release_prerelease || '' }}
secrets:
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
BALENA_API_TOKEN: ${{ secrets.BALENA_API_TOKEN }}