Files
oh-my-pi/.github/actions/bazel-cache/action.yml
T
can1357 2092f9330c fix(ci): moved bazel output root off the root-owned kata cache dir
kubelet materializes /home/runner/.cache as root when creating the
omp-bazel-repo subPath mountpoint, so bazel's default output_user_root
under it fails with EACCES. Kata jobs now point output_user_root at
RUNNER_TEMP via the bazel-cache rc fragment (pods are single-job
ephemeral; toolchain/crate downloads stay on the PVC repository cache),
and the runner image pre-owns ~/.cache for the next rebake.
2026-07-27 12:24:35 +02:00

71 lines
3.2 KiB
YAML

name: "Compose bazel cache config"
description: >
Single source of truth for how a CI job caches bazel work, emitted as a
bazelrc fragment (rc output) consumers pass via `bazelisk --bazelrc=...`.
omp-kata pods (detected via BAZEL_REMOTE_USER/BAZEL_REMOTE_PASSWORD from the
bazel-remote-ci secret) get read-write gRPC access to the in-cluster
bazel-remote service — an address that only resolves inside the cluster, so
nothing about the infrastructure leaks from this public repo. GitHub-hosted
runners never talk to that infrastructure: they use a local bazel disk cache
persisted with actions/cache, keyed on the crate lockfile and module
definition.
inputs:
scope:
description: >
Disk-cache key discriminator for GitHub-hosted runners; jobs building
different target sets (linux pair, darwin-all, msvc, validation) use
separate scopes so they don't evict each other's entries.
required: true
outputs:
rc:
description: Path to the generated bazelrc fragment
value: ${{ steps.compose.outputs.rc }}
runs:
using: composite
steps:
- name: Restore bazel disk cache (GitHub-hosted)
if: env.BAZEL_REMOTE_USER == ''
uses: actions/cache@v4
with:
path: |
~/.cache/omp-bazel-disk
~/.cache/omp-bazel-repo
key: bazel-disk-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('Cargo.Bazel.lock', 'MODULE.bazel', 'rust-toolchain.toml') }}
restore-keys: |
bazel-disk-${{ inputs.scope }}-${{ runner.os }}-${{ runner.arch }}-
- name: Compose cache config
id: compose
shell: bash
run: |
set -euo pipefail
rc="$RUNNER_TEMP/bazel-cache.rc"
if [ -n "${BAZEL_REMOTE_USER:-}" ]; then
auth="$(printf %s "${BAZEL_REMOTE_USER}:${BAZEL_REMOTE_PASSWORD}" | base64 | tr -d '\n')"
{
# kubelet creates $HOME/.cache root-owned when materializing the
# omp-bazel-repo subPath mountpoint, so bazel's default
# output_user_root ($HOME/.cache/bazel) is un-creatable; pods
# are single-job ephemeral, so RUNNER_TEMP is the right home.
echo "startup --output_user_root=$RUNNER_TEMP/bazel-root"
echo "common --config=ci"
echo "common --config=cache-rw"
echo "common --remote_cache=grpcs://bazel-remote.bazel-cache.svc.cluster.local:9092"
echo "common --tls_certificate=infra/bazel-remote/ca.crt"
echo "common --remote_header='authorization=Basic ${auth}'"
# PVC-backed shared repository cache (pods are ephemeral; without
# it every job re-downloads toolchains + crate archives).
echo "common --repository_cache=$HOME/.cache/omp-bazel-repo"
} > "$rc"
else
{
echo "common --config=ci"
echo "common --disk_cache=$HOME/.cache/omp-bazel-disk"
echo "common --repository_cache=$HOME/.cache/omp-bazel-repo"
} > "$rc"
fi
echo "rc=$rc" >> "$GITHUB_OUTPUT"