Gitlab 16.0+ Method for creating Gitlab Runners on Kubernetes
As the title suggests, there are new ways of configuring Gitlab Runners. In GitLab 16.0, a new runner creation workflow was introduced that uses authentication tokens to register runners. The legacy workflow that uses registration tokens is deprecated and will be removed in GitLab 17.0.
We will be starting the process in the GitLab Web GUI.
- Go to Settings > CI/CD in a Project
- Select Runners > New Runner
- Select Linux; Write a tag, description, and edit configurations if desired.
NOTE: Runner TAGS are deprecated in the TOML/HELM, so this is where they are set now.
Copy the runner token, and save it in 1Pass or Vault. If you are using Kubernetes, we will need it for the next step.
Encoding the Token#
Follow the steps below -- in order to use this runner token in Kubernetes, you will need to Base64 encode it for the Secret.
echo -n 'glrt-isC-rVy7MUy1cWoxrV4b' | base64
Creating the Namespace#
Depending if one exists, we may need to make a namespace. Make sure you use this namespace throughout this deployment:
kubectl create namespace gitlab-runner
Creating the Secret#
Create the Kubernetes manifest for the Secret in the namespace for the gitlab runner, we will call it secret.yml:
apiVersion: v1
kind: Secret
metadata:
name: gitlab-runner-secret
namespace: gitlab-runner
type: Opaque
data:
runner-registration-token: "" # need to leave as an empty string for compatibility reasons
runner-token: "Z2xydC1pc0MtclZ5N01VeTFjV294clY0Yg==" # This is our Base64 string
Apply the secret to the namespace:
kubectl apply -f secret.yml
Helm Chart#
This is the fun part. We will be using a Helmfile for this deployment, which uses the helm chart by GitLab for the deployment of the app gitlab-runner.
Here is the helmfile.yml using the external values file (recommended since we have RBAC also attached):
repositories:
- name: gitlab
url: https://charts.gitlab.io
releases:
- name: gitlab-runner
chart: gitlab/gitlab-runner
namespace: gitlab-runner
createNamespace: true
version: 0.55.0
installed: true
values:
- gl-runner-values.yaml
Runner Values#
While there are many values and settings we can set, only crucial ones will be listed here. For a full list of available values, see the ArtifactHUB Chart.
## GitLab Runner Image
image:
registry: registry.gitlab.com
image: gitlab-org/gitlab-runner
imagePullPolicy: IfNotPresent
gitlabUrl: https://gitlab.com/
unregisterRunners: true
replicas: 1
concurrent: 10
## RBAC
rbac:
create: true
rules:
- resources: ["deployments", "configmaps", "pods", "pods/attach", "pods/exec",
"secrets", "services", "namespaces", "serviceaccounts"]
apiGroups: ["*"]
verbs: ["get", "list", "watch", "create", "patch", "delete", "update"]
- resources: ["clusterroles", "clusterrolebindings", "secrets", "events"]
apiGroups: ["*"]
verbs: ["get", "patch", "update", "create", "list", "watch"]
clusterWideAccess: true
serviceAccountName: gitlab-runner
## Runner Configuration
runners:
config: |
[[runners]]
[runners.kubernetes]
namespace = "{{.Release.Namespace}}"
image = "ubuntu:16.04"
service_account = "gitlab-runner"
service_account_overwrite_allowed = ".*"
pull_policy = ["always", "if-not-present"]
executor: kubernetes
name: "gitlab-new-runner"
secret: gitlab-runner-secret
Apply the Helmfile:
helmfile apply -f helmfile.yml
If done correctly, you should see these runners in your GitLab!
