Skip to content
Files and environment

Files and environment

Where Rungar keeps things, and the environment variables it reads. Rungar keeps no state of its own – the fleet is the record – so there is little: the binary, the configuration, the credentials it names, the socket the daemon serves its command line on, and its event log.

The daemon’s host

PathDescription
/usr/bin/rungarThe daemon and its command line, as the package installs it. install.sh puts it in /usr/local/bin.
/etc/rungar/config.yamlThe configuration. --config (-f) names another.
/etc/rungar/The configuration’s directory, root’s and readable by the rungar group alone. Credentials and TLS material the configuration names are best kept here, owned root:rungar, mode 0640.
/usr/lib/systemd/system/rungar.serviceThe service, as the package installs it. install.sh writes it to /etc/systemd/system. It runs rungar as the rungar user.
/usr/lib/sysusers.d/rungar.confThe rungar user and group, as the package declares them to systemd.
/usr/share/bash-completion/completions/rungar, /usr/share/fish/vendor_completions.d/rungar.fish, and _rungar in zsh’s directoryShell completions, as the package installs them. With install.sh, rungar completion bash (or zsh, fish) writes them.
/run/rungar/rungar.sockThe socket the daemon serves the other commands on, mode 0660: readable and writable by the rungar user, the rungar group and root alone. The socket key moves it.
/var/log/rungar/events.jsonlThe events rungar events shows, one JSON object a line, readable and writable by rungar alone. events.file moves it.

rungar writes nothing to disk but its socket and its events. The service gives it /run/rungar for the socket, which goes when it stops, and /var/log/rungar for the events, which stays; it runs it with the filesystem read-only but for those and /tmp, which is its own. The events are history: removing the file loses what rungar events shows, and nothing else.

The paths a configuration names – github.token_path, github.app_private_key_path, and a provider’s credential and TLS files, such as Proxmox’s token_secret_path or Google Cloud’s credentials_file – are read as the rungar user, and must be readable by it. They are read when the daemon starts, as the configuration file is, so a change to one is taken up by restarting it; see GitHub credentials. The exception is a Dicer provider’s client certificate and key, tls.cert_file and tls.key_file, which are read again for every connection, so a renewed certificate is taken up without a restart.

A provider that reaches a Dicer daemon on the same machine by its socket needs the socket’s group: add it to the service with SupplementaryGroups=.

The container

PathDescription
/usr/local/bin/rungarThe daemon, which is the image’s entrypoint.
/etc/rungar/config.yamlThe configuration it is started with, by default: mount it, and the credentials it names, into the container.
/run/rungar/rungar.sockThe socket docker exec runs the other commands against. With the root filesystem read-only, /run/rungar needs a tmpfs of its own.
/var/log/rungar/events.jsonlThe events. /var/log/rungar is a volume, so that they outlive the container: name one to keep them across a new container too.

The image is distroless, and runs as the nonroot user, UID 65532: what is mounted in must be readable by it. It exposes port 9102, the metrics port, which can be reached from outside the container only with metrics.enable set and metrics.listen at 0.0.0.0:9102, rather than the default loopback. See Installation.

On a runner

What Rungar puts on a runner’s machine, for every provider:

WhatDescription
Labelsrungar.sh/managed, rungar.sh/installation, rungar.sh/scale-set, rungar.sh/runner and rungar.sh/revision, in whatever form the backend keeps labels. See Labels.
The registrationThe runner’s just-in-time configuration, delivered as the provider’s backend allows.

The dicer provider delivers the registration in the machine’s environment:

VariableDescription
ACTIONS_RUNNER_INPUT_JITCONFIGThe registration, which the runner reads at start. It cannot be set in env.
RUNNER_ALLOW_RUNASROOT1, so that the runner starts as root: the VM is the isolation. env can override it.

Environment variables

VariableDescription
NO_COLORSet to anything to turn colour off in every command’s output. Output that is not to a terminal never has any.
RUNGAR_SOCKETThe daemon’s socket, for the commands that ask it, where it is not /run/rungar/rungar.sock. --socket says the same, and wins.
HTTPS_PROXY, HTTP_PROXY, NO_PROXYA proxy for Rungar’s connections. They apply to GitHub, and to a provider’s backend reached over the network – a Dicer host’s API included, so list the hosts in NO_PROXY if they are to be reached directly.

Everything else Rungar is told comes from its configuration file: there is no setting of the daemon’s that an environment variable changes.