Files
oh-my-pi/infra/bazel-remote/runner-egress-patch.yaml
T
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00

25 lines
1.0 KiB
YAML

# JSON-patch (kubectl --type=json --patch-file) appending the bazel-remote
# egress rule to the arc-runners `runner-egress-lockdown` NetworkPolicy.
# Mirrors the existing sccache/RustFS rule (service CIDR + namespaceSelector).
#
# NOT idempotent on its own - `add` on `/spec/egress/-` appends every time.
# setup.sh guards it with a jq presence check; apply by hand the same way:
#
# kubectl -n arc-runners get networkpolicy runner-egress-lockdown -o json \
# | jq -e '.spec.egress[].to[]? | select(.namespaceSelector.matchLabels["kubernetes.io/metadata.name"] == "bazel-cache")' >/dev/null \
# || kubectl -n arc-runners patch networkpolicy runner-egress-lockdown \
# --type=json --patch-file=infra/bazel-remote/runner-egress-patch.yaml
- op: add
path: /spec/egress/-
value:
# bazel-remote shared cache (gRPC) over the cluster network.
to:
- ipBlock:
cidr: 10.43.0.0/16
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: bazel-cache
ports:
- port: 9092
protocol: TCP