Files
oh-my-pi/.github/actions/bun-install/action.yml
T
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00

78 lines
3.8 KiB
YAML

name: "bun install (shared cache)"
description: >
Ensure bun is on PATH, then run `bun install --frozen-lockfile` with a shared
package store. bun setup is skipped when the runner image already ships it
(the preloaded omp-kata image), and only fetched on runners that lack it
(e.g. GitHub-hosted). Self-hosted omp-kata runners use the mounted Bun store
PVC; GitHub-hosted runners use the stock actions/cache backend.
runs:
using: composite
steps:
- name: Detect environment
id: env
shell: bash
run: |
# bun is baked into the omp-kata runner image — only fetch it when the
# runner doesn't already provide it (GitHub-hosted), so we don't
# re-download bun from GitHub releases on every job.
if command -v bun >/dev/null 2>&1; then
echo "setup_bun=false" >> "$GITHUB_OUTPUT"
echo "bun present: $(bun --version) (preloaded image)"
else
echo "setup_bun=true" >> "$GITHUB_OUTPUT"
fi
# The repo keys "are we on can.internal infra?" off $BAZEL_REMOTE_USER
# (the bazel-remote-ci secret is envFrom-injected into every omp-kata
# runner pod). RUNNER_ENVIRONMENT is empty on ARC pods, so it is not a
# usable signal here. On infra, the ARC pod mounts the shared Bun
# store at the default cache path; off infra, actions/cache restores it.
if [ -n "${BAZEL_REMOTE_USER:-}" ]; then
echo "cache=mounted" >> "$GITHUB_OUTPUT"
echo "bun cache backend: mounted PVC (${BUN_INSTALL_CACHE_DIR:-${HOME}/.bun/install/cache})"
else
echo "cache=gha" >> "$GITHUB_OUTPUT"
echo "bun cache backend: GitHub Actions cache"
fi
- name: Install bun when absent
if: steps.env.outputs.setup_bun == 'true'
shell: bash
run: |
export BUN_INSTALL="${HOME}/.bun"
curl -fsSL https://bun.sh/install | bash -s "bun-v1.3.14"
echo "${BUN_INSTALL}/bin" >> "$GITHUB_PATH"
# Off-infra (GitHub-hosted): stock actions/cache for the bun store.
- name: Cache bun store (GitHub cache)
if: steps.env.outputs.cache == 'gha'
uses: actions/cache@v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
# On-infra (omp-kata): the pod mounts a shared PVC at bun's store path.
- name: Prepare mounted bun store
if: steps.env.outputs.cache == 'mounted'
shell: bash
run: mkdir -p "${BUN_INSTALL_CACHE_DIR:-${HOME}/.bun/install/cache}"
- name: Install dependencies
shell: bash
run: |
# The shared bun store (mounted PVC on omp-kata, actions/cache
# elsewhere) can hand a job a corrupt or partially written tarball
# when parallel jobs touch the same cache entry, so `bun install`
# aborts with `Fail extracting tarball for "<pkg>"`. That blob is
# content-hash-named, not derivable from the package name, so we
# can't evict just the bad entry — instead retry the install against
# a fresh job-local cache dir, forcing a clean re-download without
# mutating the shared store other concurrent jobs rely on. The warm
# shared cache stays the fast path; the cold retry only runs on the
# rare corruption (also covers a transient network blip on attempt 1).
if bun install --frozen-lockfile; then
exit 0
fi
echo "::warning title=bun install retry::shared bun store install failed; retrying with a clean job-local cache"
retry_cache="$(mktemp -d "${RUNNER_TEMP:-/tmp}/bun-cache-retry.XXXXXX")"
bun install --frozen-lockfile --cache-dir="$retry_cache"