Files
oh-my-pi/.github/actions/bun-install/action.yml
T
can1357 a38a2f25cf ci: optimized github actions caching and workflows
- Updated GitHub Actions workflows and custom actions to optimize caching strategies and runners.
- Configured separate restore and save steps for bun store caching with non-PR restrictions.
- Added darwin release bazel cache seeding and fallback keys for cache restore.
- Removed native-inputs workflow action and disabled PR-side Rust validation.
2026-07-30 04:56:47 +02:00

99 lines
5.1 KiB
YAML

name: "bun install (shared cache)"
description: >
Ensure bun is on PATH, then run `bun install --frozen-lockfile` with a shared
package store. bun setup is skipped when the runner image already ships it
(the preloaded omp-kata image), and only fetched on runners that lack it
(e.g. GitHub-hosted). Self-hosted omp-kata runners use the mounted Bun store
PVC; GitHub-hosted runners use the stock actions/cache backend.
runs:
using: composite
steps:
- name: Detect environment
id: env
shell: bash
run: |
# bun is baked into the omp-kata runner image — only fetch it when the
# runner doesn't already provide it (GitHub-hosted), so we don't
# re-download bun from GitHub releases on every job.
if command -v bun >/dev/null 2>&1; then
echo "setup_bun=false" >> "$GITHUB_OUTPUT"
echo "bun present: $(bun --version) (preloaded image)"
else
echo "setup_bun=true" >> "$GITHUB_OUTPUT"
fi
# The repo keys "are we on can.internal infra?" off $BAZEL_REMOTE_USER
# (the bazel-remote-ci secret is envFrom-injected into every omp-kata
# runner pod). RUNNER_ENVIRONMENT is empty on ARC pods, so it is not a
# usable signal here. On infra, the ARC pod mounts the shared Bun
# store at the default cache path; off infra, actions/cache restores it.
if [ -n "${BAZEL_REMOTE_USER:-}" ]; then
echo "cache=mounted" >> "$GITHUB_OUTPUT"
echo "bun cache backend: mounted PVC (${BUN_INSTALL_CACHE_DIR:-${HOME}/.bun/install/cache})"
else
echo "cache=gha" >> "$GITHUB_OUTPUT"
echo "bun cache backend: GitHub Actions cache"
fi
- name: Install bun when absent
if: steps.env.outputs.setup_bun == 'true'
shell: bash
run: |
export BUN_INSTALL="${HOME}/.bun"
curl -fsSL https://bun.sh/install | bash -s "bun-v1.3.14"
echo "${BUN_INSTALL}/bin" >> "$GITHUB_PATH"
# Off-infra (GitHub-hosted): actions/cache for the bun store, split into
# restore + save. actions/cache entries are scoped per ref but count
# against the shared 10 GB repo quota — letting every PR branch save its
# own copy of the ~500 MB store duplicated it 19x, evicting the far more
# valuable bazel disk-cache archives (which is why release darwin builds
# kept going cold). PRs only restore; non-PR runs (main pushes, releases,
# dispatches) produce the shared entry every PR can see.
- name: Restore bun store (GitHub cache)
id: bun-cache
if: steps.env.outputs.cache == 'gha'
uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
# A lockfile change seeds from the previous store: entries are
# content-hash-named tarballs, so stale extras waste only space and
# bun downloads just the delta.
restore-keys: |
bun-${{ runner.os }}-
# On-infra (omp-kata): the pod mounts a shared PVC at bun's store path.
- name: Prepare mounted bun store
if: steps.env.outputs.cache == 'mounted'
shell: bash
run: mkdir -p "${BUN_INSTALL_CACHE_DIR:-${HOME}/.bun/install/cache}"
- name: Install dependencies
shell: bash
run: |
# The shared bun store (mounted PVC on omp-kata, actions/cache
# elsewhere) can hand a job a corrupt or partially written tarball
# when parallel jobs touch the same cache entry, so `bun install`
# aborts with `Fail extracting tarball for "<pkg>"`. That blob is
# content-hash-named, not derivable from the package name, so we
# can't evict just the bad entry — instead retry the install against
# a fresh job-local cache dir, forcing a clean re-download without
# mutating the shared store other concurrent jobs rely on. The warm
# shared cache stays the fast path; the cold retry only runs on the
# rare corruption (also covers a transient network blip on attempt 1).
if bun install --frozen-lockfile; then
exit 0
fi
echo "::warning title=bun install retry::shared bun store install failed; retrying with a clean job-local cache"
retry_cache="$(mktemp -d "${RUNNER_TEMP:-/tmp}/bun-cache-retry.XXXXXX")"
bun install --frozen-lockfile --cache-dir="$retry_cache"
# Producer half of the split cache: only non-PR runs save, so the store
# exists once per lockfile generation instead of once per PR ref.
- name: Save bun store (GitHub cache)
if: steps.env.outputs.cache == 'gha' && github.event_name != 'pull_request' && steps.bun-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}