service/ci: update with new profile for userns authored by Jérôme Charaoui's avatar Jérôme Charaoui
...@@ -452,6 +452,7 @@ After installation, the following steps were taken: ...@@ -452,6 +452,7 @@ After installation, the following steps were taken:
3. add the following blob in `tor-puppet.git`'s 3. add the following blob in `tor-puppet.git`'s
`hiera/nodes/ci-runner-x86-02.torproject.org.yaml`: `hiera/nodes/ci-runner-x86-02.torproject.org.yaml`:
profile::user_namespaces::enabled: true
profile::gitlab::runner::docker::backend: "podman" profile::gitlab::runner::docker::backend: "podman"
profile::gitlab::runner::defaults: profile::gitlab::runner::defaults:
executor: 'docker' executor: 'docker'
...@@ -459,10 +460,6 @@ After installation, the following steps were taken: ...@@ -459,10 +460,6 @@ After installation, the following steps were taken:
docker_host: "unix:///run/user/999/podman/podman.sock" docker_host: "unix:///run/user/999/podman/podman.sock"
docker_tlsverify: false docker_tlsverify: false
docker_image: "quay.io/podman/stable" docker_image: "quay.io/podman/stable"
profile::sysctl:
unprivileged_userns_clone:
key: "kernel.unprivileged_userns_clone"
value: "1"
4. run Puppet to deploy `gitlab-runner`, `podman` 4. run Puppet to deploy `gitlab-runner`, `podman`
... ...
......