Skip to content

Make the Docker build skip work it repeats - #316

Merged
ericmj merged 1 commit into
mainfrom
docker-build-cache
Oct 8, 2026
Merged

ericmj merged 1 commit into
mainfrom
docker-build-cache

Conversation

@ericmj

@ericmj ericmj commented Oct 8, 2026

Copy link
Copy Markdown
Member

A pull request from a branch in this repository built the commit the branch's push had already built: 22 builds and 1761 s of runner time from 2026-09-02 to 2026-10-08. The Docker job now runs for pushes and for pull requests from forks.

Only main writes the build cache, which builds on every branch read. A branch's entries are only read by that branch, and exporting took up to 40 s of a build.

The dependencies compile with config.exs and prod.exs, and runtime.exs is copied in right before the release. With all of config/ copied first, c119559, which only changed runtime.exs, recompiled them (24.4 s in https://github.com/hexpm/bob/actions/runs/37764676353).

The release is copied with --link and owned by nobody as it's copied, and /app, /boto, /persist and /app/.boto are given to nobody before it, instead of a chown -R that stored a second 13.4 MB copy of the release. A --link copy doesn't need the layers below it, so Docker's documentation says a build that has them cached doesn't download them: every build downloaded about 380 MB of runtime layers to copy the release onto them, 11-46 s. Every path under /app, /boto and /persist has the same owner and mode as in gcr.io/hexpm-prod/bob:e75b493, and the release still creates /app/tmp as nobody when it starts.

The branch's image built locally, and its /app file list (owner, group, mode, type, path) matches the image main pushed for the same commit. Run as nobody, each release created /app/tmp, wrote its runtime config there and evaluated runtime.exs, which then stopped on the production environment variables that aren't set locally.

A pull request from a branch in this repository built the commit the
branch's push had already built: 22 builds and 1761 s of runner time from
2026-09-02 to 2026-10-08. The Docker job now runs for pushes and for pull
requests from forks.

Only main writes the build cache, which builds on every branch read. A
branch's entries are only read by that branch, and exporting took up to
40 s of a build.

The dependencies compile with config.exs and prod.exs, and runtime.exs is
copied in right before the release. With all of config/ copied first,
c119559, which only changed
runtime.exs, recompiled them (24.4 s in
https://github.com/hexpm/bob/actions/runs/37764676353).

The release is copied with --link and owned by nobody as it's copied, and
/app, /boto, /persist and /app/.boto are given to nobody before it,
instead of a chown -R that stored a second 13.4 MB copy of the release. A
--link copy doesn't need the layers below it, so Docker's documentation
says a build that has them cached doesn't download them: every build
downloaded about 380 MB of runtime layers to copy the release onto them,
11-46 s. Every path under /app, /boto and /persist has the same owner and
mode as in gcr.io/hexpm-prod/bob:e75b493, and the release still creates
/app/tmp as nobody when it starts.
@ericmj
ericmj merged commit e5748bf into main Oct 8, 2026
4 checks passed
@ericmj
ericmj deleted the docker-build-cache branch October 8, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant