10 Commits

Author SHA1 Message Date
can1357 053dbfa605 fix(ci): stopped mtime prune from gutting extracted bazel repos
- The hosted disk-cache prune swept ~/.cache/omp-bazel-repo file-by-file;
  extracted repository contents keep upstream-archive mtimes (months old),
  so a restored archive lost most of rules_rust while bazel still trusted
  the entry's recorded_inputs — both darwin release legs failed with
  'BUILD file not found' in release run 30519253683. Prune only the
  action disk cache, whose files carry bazel-written mtimes.
- Gave the logger burst-order contract an explicit 30 s budget: two probe
  children measure ~4.4 s unloaded and bun's 5 s default test timeout
  SIGTERMed them (exit 143) on shared-core runners.
2026-07-30 08:33:27 +02:00
can1357 52bd191b34 build: optimized Bazel repository and toolchain caching for CI
- Pin Rust toolchain component checksums in MODULE.bazel to enable Bazel's repo contents cache.
- Opt MSVC LLVM tools, XWin sysroot, and Zig repositories into reproducible repo metadata caching.
- Extend GitHub Actions cache paths to include the Bazel repository download and contents cache.
2026-07-30 07:21:43 +02:00
can1357 a38a2f25cf ci: optimized github actions caching and workflows
- Updated GitHub Actions workflows and custom actions to optimize caching strategies and runners.
- Configured separate restore and save steps for bun store caching with non-PR restrictions.
- Added darwin release bazel cache seeding and fallback keys for cache restore.
- Removed native-inputs workflow action and disabled PR-side Rust validation.
2026-07-30 04:56:47 +02:00
can1357 b550858265 ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
2026-07-28 12:53:23 +02:00
can1357 0820085890 ci: restructured workflow pipelines and introduced bazel cache actions
- Updated bazel cache key generation with v2 schema version and streamlined remote cache usage.
- Added native-inputs composite action to centralize change detection and artifact caching.
- Added a scheduled workflow to warm the hosted bazel disk cache.
- Split the rust validation job and integrated prebuilt native addon caching into the CI pipeline.
2026-07-28 11:55:57 +02:00
can1357 ed4c78bc0f feat: streamlined native addon builds and caching in ci workflows
- Enhance CI workflows to build and reuse native addon artifacts instead of recompiling.
- Update bazel cache actions with selective backend detection and separate remote and disk modes.
- Add `--source` CLI option to install prebuilt native targets without requiring Bazel.
- Increase Kata runner memory configuration from 12Gi to 24Gi.
2026-07-28 02:06:13 +02:00
can1357 a7abeff1b7 perf(ci): cut warm CI time via download-skipping, splat reuse, PR gating
Four levers on top of the green pipeline:
- kata jobs pass --remote_download_toplevel, so fully cache-hit builds
  stay metadata-only instead of pulling every intermediate artifact from
  bazel-remote (the bulk of the previous 6-minute TS-only main runs).
- the xwin MSVC splat caches its ~1GiB CDN payload on the runner-cache
  PVC (OMP_XWIN_CACHE_DIR), instead of re-downloading per ephemeral pod.
- main-push rust jobs export their bazel disk cache to the GitHub cache
  (once per lockfile change, shared linux scope). GitHub only shares
  default-branch caches across PRs, and main runs on kata where
  actions/cache never saved — so every fresh PR was building cold.
- TS-only pull requests skip Rust validation entirely (gh pr diff path
  gate); their test jobs restore addons from the main-exported cache.

Export runs disable top-level-only downloading: remote hits would
otherwise export action entries whose blobs were never materialized.
2026-07-27 14:31:24 +02:00
can1357 02c50eb6f3 fix(ci): moved bazel repo cache mount outside the runner home
kubelet creates missing subPath mountpoint parents as root, so mounting
the PVC repository cache under ~/.cache left the directory root-owned
and broke both bazel's default output root and zig's wrapper cache
compile (AccessDenied). The mount now lives at /opt/bazel-repo-cache.
2026-07-27 12:27:31 +02:00
can1357 2092f9330c fix(ci): moved bazel output root off the root-owned kata cache dir
kubelet materializes /home/runner/.cache as root when creating the
omp-bazel-repo subPath mountpoint, so bazel's default output_user_root
under it fails with EACCES. Kata jobs now point output_user_root at
RUNNER_TEMP via the bazel-cache rc fragment (pods are single-job
ephemeral; toolchain/crate downloads stay on the PVC repository cache),
and the runner image pre-owns ~/.cache for the next rebake.
2026-07-27 12:24:35 +02:00
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00