Reduce Forgejo runner privileges and allowed volumes #7
Labels
No labels
area/automation
area/dedicated
area/dns
area/docs
area/identity
area/media
area/monitoring
area/network
area/security
area/storage
priority
p1
priority
p2
priority
p3
type/cleanup
type/decision
type/maintenance
type/migration
type/security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
stanta/homelab#7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
Reduce runner privileges without breaking trusted build and deployment workflows.
Current state
The global runner LXC is privileged. Runner jobs can require Docker access, but the allowed host surface needs a focused review.
Work
Validation
References
iac/guides/roadmap-phase-2.mdiac/ansible/roles/forgejo_runner/.forgejo/workflows/