Skip to content

Commit dda2376

Browse files
committed
ci: switch to rootful podman for image builds
Replace all rootless docker/podman calls with explicit 'sudo podman' to eliminate the class of user namespace failures on the self-hosted RISC-V runner (stale boot IDs, UID mapping permission denied, and 'cannot re-exec process to join existing user namespace'). Replace docker/login-action with direct 'sudo podman login' since the GitHub Action can't use sudo. Add explicit logout step. Requires runner-side setup: /usr/local/bin/docker wrapper that calls 'sudo podman' (needed for K8s build scripts that call docker internally) and a passwordless sudoers entry for podman.
1 parent fa5298a commit dda2376

1 file changed

Lines changed: 30 additions & 33 deletions

File tree

‎.github/workflows/build-riscv64.yml‎

Lines changed: 30 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -138,11 +138,6 @@ jobs:
138138
- name: Clean workspace
139139
run: sudo rm -rf _output/ || true
140140

141-
- name: Reset Podman state
142-
run: |
143-
rm -rf /tmp/storage-run-$(id -u)/containers /tmp/storage-run-$(id -u)/libpod/tmp || true
144-
podman system prune --force 2>/dev/null || true
145-
146141
- name: Checkout
147142
uses: actions/checkout@v4
148143
with:
@@ -175,11 +170,9 @@ jobs:
175170
echo "K8S_VERSION=${K8S_VERSION}" >> "$GITHUB_ENV"
176171
177172
- name: Log in to GHCR
178-
uses: docker/login-action@v3
179-
with:
180-
registry: ghcr.io
181-
username: ${{ github.actor }}
182-
password: ${{ secrets.GITHUB_TOKEN }}
173+
run: |
174+
echo "${{ secrets.GITHUB_TOKEN }}" | \
175+
sudo podman login ghcr.io -u "${{ github.actor }}" --password-stdin
183176
184177
- name: Build dependency images
185178
run: |
@@ -195,24 +188,24 @@ jobs:
195188
echo "KUBE_CROSS_TAG=${KUBE_CROSS_TAG}" >> "$GITHUB_ENV"
196189
197190
# kube-cross
198-
docker build \
191+
sudo podman build \
199192
--build-arg GO_VERSION="${GO_VERSION}" \
200193
-t "${REGISTRY}/kube-cross:${KUBE_CROSS_TAG}" \
201194
riscv64/images/kube-cross/
202195
203196
# go-runner
204-
docker build \
197+
sudo podman build \
205198
--build-arg GO_VERSION="${GO_VERSION}" \
206199
-t "${REGISTRY}/go-runner:${GO_RUNNER_TAG}" \
207200
riscv64/images/go-runner/
208201
209202
# setcap
210-
docker build \
203+
sudo podman build \
211204
-t "${REGISTRY}/setcap:${SETCAP_TAG}" \
212205
riscv64/images/setcap/
213206
214207
# distroless-iptables
215-
docker build \
208+
sudo podman build \
216209
--build-arg GORUNNERIMAGE="${REGISTRY}/go-runner:${GO_RUNNER_TAG}" \
217210
-t "${REGISTRY}/distroless-iptables:${IPTABLES_TAG}" \
218211
riscv64/images/distroless-iptables/
@@ -222,10 +215,10 @@ jobs:
222215
# BuildKit pulls base images from the registry rather than the
223216
# local Docker store, so dependency images must be pushed before
224217
# building server images.
225-
docker push "${REGISTRY}/kube-cross:${KUBE_CROSS_TAG}"
226-
docker push "${REGISTRY}/go-runner:${GO_RUNNER_TAG}"
227-
docker push "${REGISTRY}/setcap:${SETCAP_TAG}"
228-
docker push "${REGISTRY}/distroless-iptables:${IPTABLES_TAG}"
218+
sudo podman push "${REGISTRY}/kube-cross:${KUBE_CROSS_TAG}"
219+
sudo podman push "${REGISTRY}/go-runner:${GO_RUNNER_TAG}"
220+
sudo podman push "${REGISTRY}/setcap:${SETCAP_TAG}"
221+
sudo podman push "${REGISTRY}/distroless-iptables:${IPTABLES_TAG}"
229222
230223
- name: Build Kubernetes component images
231224
run: |
@@ -259,28 +252,28 @@ jobs:
259252
gcc -Os -Wall -Werror -static -DVERSION=v${PAUSE_TAG}-${REV} \
260253
-o bin/pause-linux-riscv64 linux/pause.c
261254
strip bin/pause-linux-riscv64
262-
docker buildx build --pull --output=type=docker --platform linux/riscv64 \
255+
sudo podman build --platform linux/riscv64 \
263256
-t "${REGISTRY}/pause:${PAUSE_TAG}-linux-riscv64" \
264257
--build-arg BASE=scratch --build-arg ARCH=riscv64 .
265258
266259
- name: Build ecosystem images
267260
run: |
268261
# etcd
269-
docker build \
262+
sudo podman build \
270263
--build-arg ETCD_VERSION="${ETCD_VERSION}" \
271264
--build-arg GO_VERSION="${GO_VERSION}" \
272265
-t "${REGISTRY}/etcd:${ETCD_VERSION}-riscv64" \
273266
riscv64/ecosystem/etcd/
274267
275268
# CoreDNS
276-
docker build \
269+
sudo podman build \
277270
--build-arg COREDNS_VERSION="${COREDNS_VERSION}" \
278271
--build-arg GO_VERSION="${GO_VERSION}" \
279272
-t "${REGISTRY}/coredns:${COREDNS_VERSION}-riscv64" \
280273
riscv64/ecosystem/coredns/
281274
282275
# Flannel
283-
docker build \
276+
sudo podman build \
284277
--build-arg FLANNEL_VERSION="${FLANNEL_VERSION}" \
285278
--build-arg GO_VERSION="${GO_VERSION}" \
286279
-t "${REGISTRY}/flannel:${FLANNEL_VERSION}-riscv64" \
@@ -291,7 +284,7 @@ jobs:
291284
echo "=== Kubernetes component images ==="
292285
for img in kube-apiserver kube-controller-manager kube-scheduler kube-proxy; do
293286
echo -n "${img}-riscv64: "
294-
docker inspect "${REGISTRY}/${img}-riscv64:${K8S_VERSION}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
287+
sudo podman inspect "${REGISTRY}/${img}-riscv64:${K8S_VERSION}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
295288
done
296289
297290
echo "=== Dependency images ==="
@@ -300,38 +293,42 @@ jobs:
300293
"setcap:${SETCAP_TAG}" \
301294
"pause:${PAUSE_TAG}-linux-riscv64"; do
302295
echo -n "${img}: "
303-
docker inspect "${REGISTRY}/${img}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
296+
sudo podman inspect "${REGISTRY}/${img}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
304297
done
305298
306299
echo "=== Ecosystem images ==="
307300
for img in "etcd:${ETCD_VERSION}-riscv64" \
308301
"coredns:${COREDNS_VERSION}-riscv64" \
309302
"flannel:${FLANNEL_VERSION}-riscv64"; do
310303
echo -n "${img}: "
311-
docker inspect "${REGISTRY}/${img}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
304+
sudo podman inspect "${REGISTRY}/${img}" --format '{{.Architecture}}' 2>/dev/null || echo "MISSING"
312305
done
313306
314307
- name: Push images
315308
if: inputs.publish == true || github.event_name == 'schedule'
316309
run: |
317310
# Kubernetes components (arch-suffixed per upstream convention)
318311
for img in kube-apiserver kube-controller-manager kube-scheduler kube-proxy; do
319-
docker push "${REGISTRY}/${img}-riscv64:${K8S_VERSION}"
312+
sudo podman push "${REGISTRY}/${img}-riscv64:${K8S_VERSION}"
320313
done
321314
322315
# Pause
323-
docker push "${REGISTRY}/pause:${PAUSE_TAG}-linux-riscv64"
316+
sudo podman push "${REGISTRY}/pause:${PAUSE_TAG}-linux-riscv64"
324317
325318
# Dependency images (already pushed before make release-images,
326319
# re-push is a no-op but keeps the release gate explicit)
327-
docker push "${REGISTRY}/go-runner:${GO_RUNNER_TAG}"
328-
docker push "${REGISTRY}/distroless-iptables:${IPTABLES_TAG}"
329-
docker push "${REGISTRY}/setcap:${SETCAP_TAG}"
320+
sudo podman push "${REGISTRY}/go-runner:${GO_RUNNER_TAG}"
321+
sudo podman push "${REGISTRY}/distroless-iptables:${IPTABLES_TAG}"
322+
sudo podman push "${REGISTRY}/setcap:${SETCAP_TAG}"
330323
331324
# Ecosystem
332-
docker push "${REGISTRY}/etcd:${ETCD_VERSION}-riscv64"
333-
docker push "${REGISTRY}/coredns:${COREDNS_VERSION}-riscv64"
334-
docker push "${REGISTRY}/flannel:${FLANNEL_VERSION}-riscv64"
325+
sudo podman push "${REGISTRY}/etcd:${ETCD_VERSION}-riscv64"
326+
sudo podman push "${REGISTRY}/coredns:${COREDNS_VERSION}-riscv64"
327+
sudo podman push "${REGISTRY}/flannel:${FLANNEL_VERSION}-riscv64"
328+
329+
- name: Log out of GHCR
330+
if: always()
331+
run: sudo podman logout ghcr.io || true
335332

336333
release:
337334
name: Create release

0 commit comments

Comments
 (0)