From 2092f9330c41475b78f1f440d21501c75666e490 Mon Sep 17 00:00:00 2001 From: can1357 Date: Mon, 27 Jul 2026 12:24:35 +0200 Subject: [PATCH] fix(ci): moved bazel output root off the root-owned kata cache dir kubelet materializes /home/runner/.cache as root when creating the omp-bazel-repo subPath mountpoint, so bazel's default output_user_root under it fails with EACCES. Kata jobs now point output_user_root at RUNNER_TEMP via the bazel-cache rc fragment (pods are single-job ephemeral; toolchain/crate downloads stay on the PVC repository cache), and the runner image pre-owns ~/.cache for the next rebake. --- .github/actions/bazel-cache/action.yml | 5 +++++ infra/runner.Dockerfile | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/.github/actions/bazel-cache/action.yml b/.github/actions/bazel-cache/action.yml index 60ef90bbb..ad9ff4a57 100644 --- a/.github/actions/bazel-cache/action.yml +++ b/.github/actions/bazel-cache/action.yml @@ -46,6 +46,11 @@ runs: if [ -n "${BAZEL_REMOTE_USER:-}" ]; then auth="$(printf %s "${BAZEL_REMOTE_USER}:${BAZEL_REMOTE_PASSWORD}" | base64 | tr -d '\n')" { + # kubelet creates $HOME/.cache root-owned when materializing the + # omp-bazel-repo subPath mountpoint, so bazel's default + # output_user_root ($HOME/.cache/bazel) is un-creatable; pods + # are single-job ephemeral, so RUNNER_TEMP is the right home. + echo "startup --output_user_root=$RUNNER_TEMP/bazel-root" echo "common --config=ci" echo "common --config=cache-rw" echo "common --remote_cache=grpcs://bazel-remote.bazel-cache.svc.cluster.local:9092" diff --git a/infra/runner.Dockerfile b/infra/runner.Dockerfile index 1926cf0eb..c0b9a54f7 100644 --- a/infra/runner.Dockerfile +++ b/infra/runner.Dockerfile @@ -86,6 +86,10 @@ RUN arch="$(dpkg --print-architecture)" \ && USE_BAZEL_VERSION="${BAZEL_VERSION}" bazelisk version RUN chmod -R a+rX "$BAZELISK_HOME" \ && rm -rf /root/.cache/bazel /root/.bazelrc +# Pre-own ~/.cache for the runner user: kubelet otherwise creates it root-owned +# as the parent of the omp-bazel-repo subPath mountpoint, breaking sibling dirs +# like bazel's default output_user_root. +RUN install -d -o 1001 -g 1001 -m 0755 /home/runner/.cache # rust toolchain + cargo helpers for the runner user; rustup default == pinned # nightly so Rust setup becomes a no-op on the preloaded image.