2092f9330c
kubelet materializes /home/runner/.cache as root when creating the omp-bazel-repo subPath mountpoint, so bazel's default output_user_root under it fails with EACCES. Kata jobs now point output_user_root at RUNNER_TEMP via the bazel-cache rc fragment (pods are single-job ephemeral; toolchain/crate downloads stay on the PVC repository cache), and the runner image pre-owns ~/.cache for the next rebake.
71 lines
3.2 KiB
YAML
71 lines
3.2 KiB
YAML
name: "Compose bazel cache config"
|
|
description: >
|
|
Single source of truth for how a CI job caches bazel work, emitted as a
|
|
bazelrc fragment (rc output) consumers pass via `bazelisk --bazelrc=...`.
|
|
omp-kata pods (detected via BAZEL_REMOTE_USER/BAZEL_REMOTE_PASSWORD from the
|
|
bazel-remote-ci secret) get read-write gRPC access to the in-cluster
|
|
bazel-remote service — an address that only resolves inside the cluster, so
|
|
nothing about the infrastructure leaks from this public repo. GitHub-hosted
|
|
runners never talk to that infrastructure: they use a local bazel disk cache
|
|
persisted with actions/cache, keyed on the crate lockfile and module
|
|
definition.
|
|
|
|
inputs:
|
|
scope:
|
|
description: >
|
|
Disk-cache key discriminator for GitHub-hosted runners; jobs building
|
|
different target sets (linux pair, darwin-all, msvc, validation) use
|
|
separate scopes so they don't evict each other's entries.
|
|
required: true
|
|
|
|
outputs:
|
|
rc:
|
|
description: Path to the generated bazelrc fragment
|
|
value: ${{ steps.compose.outputs.rc }}
|
|
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- name: Restore bazel disk cache (GitHub-hosted)
|
|
if: env.BAZEL_REMOTE_USER == ''
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cache/omp-bazel-disk
|
|
~/.cache/omp-bazel-repo
|
|
key: bazel-disk-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('Cargo.Bazel.lock', 'MODULE.bazel', 'rust-toolchain.toml') }}
|
|
restore-keys: |
|
|
bazel-disk-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-
|
|
|
|
- name: Compose cache config
|
|
id: compose
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
rc="$RUNNER_TEMP/bazel-cache.rc"
|
|
if [ -n "${BAZEL_REMOTE_USER:-}" ]; then
|
|
auth="$(printf %s "${BAZEL_REMOTE_USER}:${BAZEL_REMOTE_PASSWORD}" | base64 | tr -d '\n')"
|
|
{
|
|
# kubelet creates $HOME/.cache root-owned when materializing the
|
|
# omp-bazel-repo subPath mountpoint, so bazel's default
|
|
# output_user_root ($HOME/.cache/bazel) is un-creatable; pods
|
|
# are single-job ephemeral, so RUNNER_TEMP is the right home.
|
|
echo "startup --output_user_root=$RUNNER_TEMP/bazel-root"
|
|
echo "common --config=ci"
|
|
echo "common --config=cache-rw"
|
|
echo "common --remote_cache=grpcs://bazel-remote.bazel-cache.svc.cluster.local:9092"
|
|
echo "common --tls_certificate=infra/bazel-remote/ca.crt"
|
|
echo "common --remote_header='authorization=Basic ${auth}'"
|
|
# PVC-backed shared repository cache (pods are ephemeral; without
|
|
# it every job re-downloads toolchains + crate archives).
|
|
echo "common --repository_cache=$HOME/.cache/omp-bazel-repo"
|
|
} > "$rc"
|
|
else
|
|
{
|
|
echo "common --config=ci"
|
|
echo "common --disk_cache=$HOME/.cache/omp-bazel-disk"
|
|
echo "common --repository_cache=$HOME/.cache/omp-bazel-repo"
|
|
} > "$rc"
|
|
fi
|
|
echo "rc=$rc" >> "$GITHUB_OUTPUT"
|