[isar-cip-core][PATCH v3 5/5] ci: Select rootless runner
flat view
From: Jan Kiszka <jan.kiszka@siemens.com>
Date: 2026-08-27 06:23:05
Subsystem:
the rest · Maintainer:
Linus Torvalds
From: Jan Kiszka <jan.kiszka@siemens.com> We need to explicitly select a runner that is launching build containers in unprivileged mode. This is primarily due to the bug in kas 5.4 which breaks the parallel start of multiple kas-isar containers on the same host. At the same time, such tagging allows us to phase out the privileged runner at some point in way that would clearly block legacy jobs. Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com> --- .gitlab-ci.yml | 8 ++++---- .reproducible-check-ci.yml | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index 9aa186c6..8dbe62d2 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml@@ -1,7 +1,7 @@ # # CIP Core, generic profile # -# Copyright (c) Siemens AG, 2019-2025 +# Copyright (c) Siemens AG, 2019-2026 # Copyright (c) Toshiba Corporation, 2020 # # Authors:
@@ -53,7 +53,7 @@ default: when: never - if: $CI_COMMIT_BRANCH != "master" tags: - - large + - large-rootless variables: base_yaml: "kas-cip.yml:kas/board/${target}.yml" script:
@@ -917,7 +917,7 @@ cve-checks: needs: [] image: registry.gitlab.com/cip-project/cip-core/debian-cve-checker:build-latest tags: - - large + - large-rootless script: - scripts/run-cve-checks.sh rules:
@@ -936,7 +936,7 @@ lavacli-container: stage: build image: quay.io/buildah/stable:v1.41.4 tags: - - large + - large-rootless before_script: - buildah login -u $CI_REGISTRY_USER --password $CI_REGISTRY_PASSWORD $CI_REGISTRY script:
diff --git a/.reproducible-check-ci.yml b/.reproducible-check-ci.yml
index 4f4649ee..de9f3fbd 100644
--- a/.reproducible-check-ci.yml
+++ b/.reproducible-check-ci.yml@@ -21,7 +21,7 @@ extension: security stage: build tags: - - large + - large-rootless rules: - if: $CI_PIPELINE_SOURCE == "schedule" && $REPRODUCIBLE_BUILDS script:
--
2.47.3