8facd237d5
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for windows-msvc (bazel/toolchains/msvc). - All eight shipped addons build as //:natives-<target> via the release transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical .node naming); scripts/bazel-natives.ts is the single driver for local dev and CI. - Rust validation moved to bazel test + clippy aspects (strict workspace policy for opted-in crates, default lints elsewhere, mirroring cargo semantics) and the rustfmt aspect; cargo stays as the dev-iteration surface, with brush-core/brush-builtins promoted to workspace members and excluded from cargo dev tasks to keep their historical scope. - CI caches through an in-cluster bazel-remote action cache (TLS + basic auth, cluster-internal only); GitHub-hosted runners never touch the infrastructure and use an actions/cache-backed disk cache instead. - Deleted the hand-rolled caching machinery: ci-target-cache, ci-native-artifact-cache, ci-build-native, native-source-hash, find-native-artifacts, restore-linux-native, native-prewarm workflow, ensure-* toolchain actions, and all sccache/Swatinem wiring. - Warm native rebuilds drop from ~20 minutes to seconds; a cold client with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
25 lines
1.0 KiB
YAML
25 lines
1.0 KiB
YAML
# JSON-patch (kubectl --type=json --patch-file) appending the bazel-remote
|
|
# egress rule to the arc-runners `runner-egress-lockdown` NetworkPolicy.
|
|
# Mirrors the existing sccache/RustFS rule (service CIDR + namespaceSelector).
|
|
#
|
|
# NOT idempotent on its own - `add` on `/spec/egress/-` appends every time.
|
|
# setup.sh guards it with a jq presence check; apply by hand the same way:
|
|
#
|
|
# kubectl -n arc-runners get networkpolicy runner-egress-lockdown -o json \
|
|
# | jq -e '.spec.egress[].to[]? | select(.namespaceSelector.matchLabels["kubernetes.io/metadata.name"] == "bazel-cache")' >/dev/null \
|
|
# || kubectl -n arc-runners patch networkpolicy runner-egress-lockdown \
|
|
# --type=json --patch-file=infra/bazel-remote/runner-egress-patch.yaml
|
|
- op: add
|
|
path: /spec/egress/-
|
|
value:
|
|
# bazel-remote shared cache (gRPC) over the cluster network.
|
|
to:
|
|
- ipBlock:
|
|
cidr: 10.43.0.0/16
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: bazel-cache
|
|
ports:
|
|
- port: 9092
|
|
protocol: TCP
|