From 0d9023f4cd8f68831763d047606b7d1b9b30c9ae Mon Sep 17 00:00:00 2001 From: fylorn <249551762+fylorn@users.noreply.github.com> Date: Thu, 8 Oct 2026 11:08:25 +0800 Subject: [PATCH] ci: save Rust caches only on pushes, and let releases read CI's image caches - ci.yml: `rust-cache` saves only on pushes to dev and main. A PR can read its own caches, its base branch's and the default branch's, never another PR's, so a cache saved on a PR served only a later push to that same PR while taking as much of the 10 GB quota as dev's (refs/pull/85/merge held 2.2 GB). - release.yml: image builds read the caches CI saves on main and write none. The release scopes (`server-linux-amd64`, `web-linux-amd64`, ...) never matched CI's (`server-linux/amd64`, `web`), and a tag run can read only its own caches and main's, so every release built the images from scratch and filed caches under the tag that no later run could read. The tag points at a main commit CI has just built from the same Dockerfiles. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ci.yml | 9 +++++++++ .github/workflows/release.yml | 9 +++++++-- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index abe08f1d..d84462f4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -62,7 +62,13 @@ jobs: - uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d # stable with: toolchain: stable + # Save only on pushes (dev, main). A PR can read its own caches, its + # base branch's and the default branch's, never another PR's, so a cache + # saved on a PR serves only a later push to that same PR, while taking as + # much of the repository's 10 GB cache quota as dev's and evicting it. - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + with: + save-if: ${{ github.event_name == 'push' }} - uses: taiki-e/install-action@183e4297cca2404691e9380e1307288dced5c82a # v2.87.25 with: tool: cargo-nextest @@ -158,6 +164,9 @@ jobs: with: toolchain: stable - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + with: + # See the `rust` job. + save-if: ${{ github.event_name == 'push' }} - uses: taiki-e/install-action@183e4297cca2404691e9380e1307288dced5c82a # v2.87.25 with: tool: cargo-nextest diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a77bce08..7d03ed04 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -104,8 +104,13 @@ jobs: org.opencontainers.image.version=${{ github.ref_name }} org.opencontainers.image.revision=${{ github.sha }} org.opencontainers.image.licenses=BUSL-1.1 - cache-from: type=gha,scope=${{ matrix.component }}-${{ steps.meta.outputs.platform_pair }} - cache-to: type=gha,scope=${{ matrix.component }}-${{ steps.meta.outputs.platform_pair }},mode=max + # Read the caches CI saves on main, never write. A tag run can read + # its own caches and the default branch's (main) only, and the tag + # points at a commit whose main push CI has just built from the same + # Dockerfile, so these scopes are CI's (`server-`, and `web` + # for both platforms). A cache written here would be filed under the + # tag, where no later run can read it. + cache-from: type=gha,scope=${{ matrix.component == 'web' && 'web' || format('server-{0}', matrix.platform) }} - name: Export digest run: |