Deploy from the hosted arm64 runner instead of building on the box - #13
Merged
Conversation
anv26's hardening pass deliberately purged the C toolchain (gcc, libc6-dev, make), so the on-box cabal build the deploy relied on cannot configure new dependencies. Build on ubuntu-24.04-arm instead - same Ubuntu and glibc as the Ampere box, runtime libraries verified present - and ship the binary over the existing Access tunnel. cloudflared switches to the arm64 asset, same pin-and-checksum discipline.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The 0.5.0.0 deploy failed with
ghc: could not execute: gcc: the production box's hardening pass deliberately purged the compiler toolchain (gcc, libc6-dev, make), and the deploy still built the server on-box - a design from before hosted arm64 runners were available to public repos.Build on
ubuntu-24.04-arminstead - the same Ubuntu and glibc as the Ampere box, with the needed runtime libraries (libgmp10, libffi8, zlib1g, libnuma1) verified present on the host - and ship the binary over the existing Cloudflare Access tunnel, exactly as the unit file already travels. The service keeps serving during the transfer and restarts only for the install. cloudflared switches to the arm64 asset (the runner is arm now) under the same pinned version + checksum discipline.Once this proves out over a few deploys, the box's now-unused 9 GB GHC toolchain (
~/.ghcup+~/.cabal) can be retired, completing the no-toolchain-on-prod hardening.