mirror of
https://github.com/garrytan/gstack.git
synced 2026-08-22 05:57:18 +02:00
ci: stop version bumps rebuilding the eval Docker image (cache key trio)
Three coupled fixes, atomic because any subset is worse than none: 1. Image tag keys on hashFiles(Dockerfile.ci, bun.lock) — package.json is out: its version field changed on 60/60 recent commits, forcing a ~2min image rebuild per PR for a dependency set only bun.lock determines. 2. ci-image.yml now pushes that same content-hash tag (previously only :latest/:sha, so the weekly prebuild never warmed the tag the eval matrix actually looks up) and both eval workflows get registry layer cache (cache-to export gated to same-repo runs; fork tokens cannot write GHCR). 3. Dockerfile bakes /opt/node_modules_cache/.bun.lock and the runtime Restore-deps guard diffs bun.lock instead of package.json — otherwise every version-only bump made all 14 matrix jobs fall back to a live bun install, which is slower than today's behavior. Worst-case failure mode is self-healing: a missing tag or cache falls back to exactly the previous rebuild-and-install path. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
e96152fcd2
commit
6e20913f66
@@ -113,7 +113,8 @@ RUN bun --version && node --version && claude --version && jq --version && gh --
|
||||
# if we move it out of the way and symlink back
|
||||
# Save node_modules + package.json snapshot for cache validation at runtime
|
||||
RUN mv /workspace/node_modules /opt/node_modules_cache \
|
||||
&& cp /workspace/package.json /opt/node_modules_cache/.package.json
|
||||
&& cp /workspace/package.json /opt/node_modules_cache/.package.json \
|
||||
&& cp /workspace/bun.lock /opt/node_modules_cache/.bun.lock
|
||||
|
||||
# Claude CLI refuses --dangerously-skip-permissions as root.
|
||||
# Create a non-root user for eval runs (GH Actions overrides USER, so
|
||||
|
||||
Reference in New Issue
Block a user