Skip to content

Commit bf067ab

Browse files
committed
Isolate CI snapshot creation from branch cache publishers
The optional snapshot producer executes checkout code without publishing branch caches; its artifacts are available only to consumers in the same workflow run.
1 parent 3b588c2 commit bf067ab

1 file changed

Lines changed: 37 additions & 16 deletions

File tree

‎.github/workflows/ci-image-build.yml‎

Lines changed: 37 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -399,12 +399,42 @@ jobs:
399399
if: >
400400
inputs.upload-mount-cache-artifact == 'true' &&
401401
steps.stashed-image.outputs.reusable != 'true'
402-
# Every job that prepares the CI image would otherwise `docker image load` the image stash,
403-
# unpacking and checksumming each layer again; a copy of the image store restores with one
404-
# extraction. Run after the authoritative image and mount-cache publications: snapshot
405-
# creation prunes the build cache and must not affect the artifacts those steps publish.
406-
# Snapshots are handoffs within this run, not branch caches. An arbitrary checkout ref
407-
# must not publish raw daemon state for a later run on the default branch.
402+
- name: "Check disk space after build"
403+
run: df -H
404+
405+
# Run checkout code in a separate job with no branch-cache publications. This optional
406+
# producer hands the snapshot only to consumers of the same workflow run.
407+
snapshot-ci-images:
408+
name: "Snapshot CI ${{ inputs.platform }} image ${{ matrix.python-version }}"
409+
needs: build-ci-images
410+
if: >
411+
github.event_name == 'pull_request' &&
412+
inputs.upload-image-artifact == 'true' && inputs.image-stash-ref == ''
413+
continue-on-error: true
414+
timeout-minutes: 20
415+
runs-on: ${{ fromJSON(inputs.runners) }}
416+
permissions:
417+
contents: read
418+
strategy:
419+
fail-fast: false
420+
matrix:
421+
python-version: ${{ fromJSON(inputs.python-versions) }}
422+
env:
423+
PYTHON_MAJOR_MINOR_VERSION: ${{ matrix.python-version }}
424+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
425+
steps:
426+
- name: "Checkout sources"
427+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
428+
with:
429+
ref: ${{ inputs.checkout-ref }}
430+
persist-credentials: false
431+
- name: "Prepare authoritative CI image"
432+
uses: ./.github/actions/prepare_breeze_and_image
433+
with:
434+
platform: ${{ inputs.platform }}
435+
python: ${{ matrix.python-version }}
436+
use-uv: ${{ inputs.use-uv }}
437+
make-mnt-writeable-and-cleanup: 'true'
408438
- name: "Snapshot CI image ${{ inputs.platform }}:${{ env.PYTHON_MAJOR_MINOR_VERSION }}"
409439
id: snapshot-export
410440
continue-on-error: true
@@ -414,10 +444,6 @@ jobs:
414444
./scripts/ci/docker_data_root_snapshot.sh create
415445
"/mnt/ci-image-snapshot-${PLATFORM//\//_}-${PYTHON_MAJOR_MINOR_VERSION}.tar.zst"
416446
shell: bash
417-
if: >
418-
github.event_name == 'pull_request' &&
419-
inputs.upload-image-artifact == 'true' && inputs.image-stash-ref == '' &&
420-
steps.stashed-image.outputs.reusable != 'true'
421447
- name: "Upload CI image snapshot ${{ inputs.platform }}:${{ env.PYTHON_MAJOR_MINOR_VERSION }}"
422448
continue-on-error: true
423449
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
@@ -429,9 +455,4 @@ jobs:
429455
if-no-files-found: 'error'
430456
compression-level: '0'
431457
retention-days: '2'
432-
if: >
433-
github.event_name == 'pull_request' && steps.snapshot-export.outcome == 'success' &&
434-
inputs.upload-image-artifact == 'true' && inputs.image-stash-ref == '' &&
435-
steps.stashed-image.outputs.reusable != 'true'
436-
- name: "Check disk space after build"
437-
run: df -H
458+
if: steps.snapshot-export.outcome == 'success'

0 commit comments

Comments
 (0)