Files
oh-my-pi/.github/actions/bazel-cache/action.yml
T
can1357 0820085890 ci: restructured workflow pipelines and introduced bazel cache actions
- Updated bazel cache key generation with v2 schema version and streamlined remote cache usage.
- Added native-inputs composite action to centralize change detection and artifact caching.
- Added a scheduled workflow to warm the hosted bazel disk cache.
- Split the rust validation job and integrated prebuilt native addon caching into the CI pipeline.
2026-07-28 11:55:57 +02:00

111 lines
4.5 KiB
YAML

name: "Compose bazel cache config"
description: >
Selects the CI cache backend and emits a bazelrc fragment. A shell probe
exposes the backend through step outputs before any action condition
uses it.
omp-kata jobs use the cluster remote cache. GitHub-hosted jobs use an
actions/cache-backed disk cache seeded by the bazel-cache-warm workflow
on the same runner image — cross-host action keys never hit, so the disk
cache is hosted-only and its key carries a schema version (v2; v1 was
poisoned by a kata-produced export that silently missed every action).
Consumers save a new exact-key archive after a miss.
inputs:
scope:
description: Disk-cache key discriminator shared by compatible consumers
required: true
outputs:
rc:
description: Path to the generated bazelrc fragment
value: ${{ steps.compose.outputs.rc }}
cache-key:
description: Exact GitHub cache key for a later explicit save
value: ${{ steps.backend.outputs.cache-key }}
save-needed:
description: Whether a disk-cache build can save a new exact-key archive
value: ${{ steps.compose.outputs.save-needed }}
remote:
description: Whether the shell probe selected the cluster remote cache
value: ${{ steps.backend.outputs.remote }}
runs:
using: composite
steps:
- name: Detect bazel cache backend
id: backend
shell: bash
env:
CACHE_KEY: bazel-disk-v2-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('Cargo.Bazel.lock', 'MODULE.bazel', 'MODULE.bazel.lock', 'rust-toolchain.toml', '.bazelrc', '.bazelversion', 'bazel/**') }}
run: |
set -euo pipefail
remote=false
if [ -n "${BAZEL_REMOTE_USER:-}" ] || [ -n "${BAZEL_REMOTE_PASSWORD:-}" ]; then
if [ -z "${BAZEL_REMOTE_USER:-}" ] || [ -z "${BAZEL_REMOTE_PASSWORD:-}" ]; then
echo "::error::BAZEL_REMOTE_USER and BAZEL_REMOTE_PASSWORD must both be set"
exit 1
fi
remote=true
fi
{
echo "remote=$remote"
echo "cache-key=$CACHE_KEY"
} >> "$GITHUB_OUTPUT"
- name: Restore bazel disk cache
id: restore
if: steps.backend.outputs.remote != 'true'
uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.cache/omp-bazel-disk
key: ${{ steps.backend.outputs.cache-key }}
restore-keys: |
bazel-disk-v2-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-
- name: Compose cache config
id: compose
shell: bash
env:
REMOTE: ${{ steps.backend.outputs.remote }}
RESTORE_HIT: ${{ steps.restore.outputs.cache-hit }}
run: |
set -euo pipefail
save_needed=false
if [ "$REMOTE" != "true" ] && [ "$RESTORE_HIT" != "true" ]; then
save_needed=true
fi
rc="$RUNNER_TEMP/bazel-cache.rc"
if [ "$REMOTE" = "true" ]; then
{
# The PVC mount lives outside $HOME. Pods are single-job and
# use RUNNER_TEMP for Bazel's output root.
echo "startup --output_user_root=$RUNNER_TEMP/bazel-root"
echo "common --config=ci"
echo "common --repository_cache=/opt/bazel-repo-cache"
echo "common --repo_env=OMP_XWIN_CACHE_DIR=/opt/bazel-repo-cache/xwin"
raw_auth="${BAZEL_REMOTE_USER}:${BAZEL_REMOTE_PASSWORD}"
auth="$(printf %s "$raw_auth" | base64 | tr -d '\n')"
echo "::add-mask::$raw_auth"
echo "::add-mask::$auth"
echo "common --config=cache-rw"
echo "common --remote_cache=grpcs://bazel-remote.bazel-cache.svc.cluster.local:9092"
echo "common --tls_certificate=infra/bazel-remote/ca.crt"
echo "common --remote_header='authorization=Basic ${auth}'"
echo "common --remote_download_toplevel"
} > "$rc"
else
mkdir -p "$HOME/.cache/omp-bazel-disk" "$HOME/.cache/omp-bazel-repo"
{
echo "common --config=ci"
echo "common --disk_cache=$HOME/.cache/omp-bazel-disk"
echo "common --repository_cache=$HOME/.cache/omp-bazel-repo"
} > "$rc"
fi
{
echo "rc=$rc"
echo "save-needed=$save_needed"
} >> "$GITHUB_OUTPUT"