{ config, pkgs, inputs, lib, system, ... }: let unstable = inputs.nixpkgs-nixos-unstable; package = unstable.legacyPackages."${system}".gitea-actions-runner; in { sops.secrets."gitea-runner-token" = { sopsFile = ./gitea-runner-token.sops; format = "binary"; }; virtualisation.podman = { enable = true; autoPrune.enable = true; defaultNetwork.settings = { dns = ["9.9.9.9"]; dns_enabled = false; }; }; disabledModules = [ "services/continuous-integration/gitea-actions-runner.nix" ]; imports = [ "${unstable}/nixos/modules/services/continuous-integration/gitea-actions-runner.nix" ]; services.gitea-actions-runner = { inherit package; instances.bolty1 = { enable = true; url = "https://git.cyplo.dev"; tokenFile = config.sops.secrets."gitea-runner-token".path; name = "bolty1"; hostPackages = with pkgs; [ bash coreutils curl gawk gitMinimal gnused nodejs wget sudo nix ]; labels = [ "flakes-action:docker://git.cyplo.dev/cyplo/base-images/flakes-action:latest" "ubuntu-kinetic:docker://ubuntu:kinetic" "linux_amd64:host" # compat with github actions ]; }; }; }