Skip to content

Deploy from the hosted arm64 runner instead of building on the box - #13

Merged
aoinoikaz merged 1 commit into
mainfrom
deploy-arm-runner
Jul 13, 2026
Merged

Deploy from the hosted arm64 runner instead of building on the box#13
aoinoikaz merged 1 commit into
mainfrom
deploy-arm-runner

Conversation

@aoinoikaz

Copy link
Copy Markdown
Contributor

The 0.5.0.0 deploy failed with ghc: could not execute: gcc: the production box's hardening pass deliberately purged the compiler toolchain (gcc, libc6-dev, make), and the deploy still built the server on-box - a design from before hosted arm64 runners were available to public repos.

Build on ubuntu-24.04-arm instead - the same Ubuntu and glibc as the Ampere box, with the needed runtime libraries (libgmp10, libffi8, zlib1g, libnuma1) verified present on the host - and ship the binary over the existing Cloudflare Access tunnel, exactly as the unit file already travels. The service keeps serving during the transfer and restarts only for the install. cloudflared switches to the arm64 asset (the runner is arm now) under the same pinned version + checksum discipline.

Once this proves out over a few deploys, the box's now-unused 9 GB GHC toolchain (~/.ghcup + ~/.cabal) can be retired, completing the no-toolchain-on-prod hardening.

anv26's hardening pass deliberately purged the C toolchain (gcc,
libc6-dev, make), so the on-box cabal build the deploy relied on cannot
configure new dependencies.  Build on ubuntu-24.04-arm instead - same
Ubuntu and glibc as the Ampere box, runtime libraries verified present -
and ship the binary over the existing Access tunnel.  cloudflared
switches to the arm64 asset, same pin-and-checksum discipline.
@aoinoikaz
aoinoikaz merged commit 7ad09df into main Jul 13, 2026
9 checks passed
@aoinoikaz
aoinoikaz deleted the deploy-arm-runner branch July 13, 2026 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant