ci: upgraded continuous integration workflows and migrated bazel dependency locking

- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
This commit is contained in:
can1357
2026-07-28 12:53:23 +02:00
parent 0820085890
commit b550858265
11 changed files with 11654 additions and 61727 deletions
+42 -6
View File
@@ -4,13 +4,33 @@ name: Warm bazel disk cache
# actions/cache entries created on the default branch. Bazel action keys do
# not transfer across runner environments (a kata-produced disk cache misses
# every action on ubuntu-22.04), so seed the disk cache from the same image
# PR jobs run on. A warm run restores the exact-key archive, builds
# incrementally, and saves nothing; a lockfile/config change misses, rebuilds,
# and saves the new key.
# PR jobs run on. Runs the full hosted action set — Rust validation (test,
# clippy, rustfmt) plus the native addons — so one exact-key archive covers
# both rust_validate and native_addons for this source generation. The v3
# key embeds a crates/** source fingerprint, so a native change on main
# means an exact miss: the build seeds from the previous generation via the
# config-scoped prefix and the refreshed archive is saved. An exact hit
# makes every invocation a cache replay and saves nothing.
on:
schedule:
- cron: "23 */6 * * *"
push:
branches: [main]
paths:
- "packages/**"
- "crates/**"
- "scripts/**"
- "bazel/**"
- "MODULE.bazel"
- "MODULE.bazel.lock"
- "BUILD.bazel"
- ".bazelrc"
- ".bazelignore"
- ".bazelversion"
- "Cargo.toml"
- "Cargo.lock"
- "rust-toolchain.toml"
- "rustfmt.toml"
- ".github/**"
workflow_dispatch:
permissions:
@@ -30,10 +50,26 @@ jobs:
uses: ./.github/actions/bazel-cache
with:
scope: linux
- name: Build native addons
# Invocation set mirrors the hosted CI jobs (rust_validate +
# native_addons) so the saved archive serves both.
- name: Rust tests
run: |
set -euo pipefail
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/...
- name: Clippy (workspace lint policy on opted-in crates)
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy-strict --
- name: Clippy (default lints elsewhere)
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/... - (//crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...) - //crates/vendor/brush-core/... - //crates/vendor/brush-builtins/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy --
- name: Rustfmt
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
- name: Build native addons
run: |
set -euo pipefail
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-x64-baseline //:natives-linux-x64-modern
- name: Save bazel disk cache
if: steps.cache.outputs.save-needed == 'true'