Repository navigation
ci(docker): build the three images in parallel matrix jobs - #148
Merged
Merged
Conversation
The single build-and-push job built cryptpilot-fde/crypt/verity sequentially, ~2h wall clock (recent master runs: 2h22m): every Dockerfile's builder stage runs rpmbuild over the whole Rust workspace, and the shared builder-stage cache only helps the 2nd/3rd images. Split the job into a fail-fast=false matrix of three parallel jobs, one per image. To keep each job from paying the full workspace compile, add bcond switches (fde/crypt/verity) to cryptpilot.spec so a subset build skips the other crates' cargo install calls, subpackage definitions, %files and scriptlets. The Dockerfiles pass --without flags to rpmbuild and matching _without_* defines to yum-builddep (so BuildRequires like verity's cmake/fuse3-devel are skipped as well). The default expansion without flags builds everything as before - the existing RPM CI paths are unaffected. Validated locally with rpmspec -P under all flag combinations: the default parse keeps all 13 subpackage sections and 4 cargo installs; each --without combo drops exactly the disabled subpackages and their cargo install steps (e.g. --without crypt --without verity keeps only the two cryptpilot-fde binaries). Each job now compiles only the crate(s) its image packages, so the three parallel jobs should finish in roughly the time of a single-crate RPM build instead of ~2h. Assisted-by: Claude:glm-5.3 Signed-off-by: Kun Lai <[email protected]>
|
@imlk0 ,您好,您的请求已接收,请耐心等待结果。 |
|
@imlk0 ,您好,未检测到有镜像需要构建,如需重新检测请评论 /start 。 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The Build Docker Images workflow builds
cryptpilot-fde/cryptpilot-crypt/cryptpilot-veritysequentially in a single job. Wall clock is ~2h (recent master runs: 2h22m, other branches 1h52m+), because every Dockerfile's builder stage runsrpmbuildover the whole Rust workspace (all four cargo binaries), and the shared builder-stage cache only helps the 2nd and 3rd images.Relatedly, the spec's
%buildalways runs all fourcargo installinvocations no matter which RPMs are actually needed.Changes
.github/workflows/build-docker.yml: the single job becomes afail-fast: falsematrix of three parallel jobs (fde / crypt / verity). Per-job steps are unchanged in substance: checkout, buildx, docker/metadata-action (same tag rules: branch/pr/semver x2/sha/latest), build-push-action,docker load+--versionsmoke test, GHCR login, push loop. Triggers unchanged.cryptpilot.spec: new bcond switches%bcond_without fde / crypt / verity. SubpackageRequiresof the meta package,%package/%description,%buildcargo installs,%installstaging,%filesand scriptlets are wrapped in matching%ifblocks.dist/systemd/cryptpilot.service(claimed by both cryptpilot-fde-guest and cryptpilot-crypt) is guarded by%if %{with fde} || %{with crypt}. The default expansion (no flags) is unchanged: all subpackages build exactly as before, so the existing RPM CI paths are not affected.Dockerfile.fde/.crypt/.verity: the builder stage passes--withoutflags torpmbuild(and matching_without_*defines toyum-builddep, so e.g. verity'scmake/fuse3-develBuildRequires are skipped when not needed). Each image build now compiles only the crate(s) it packages.Validation
rpmspec -Punder all flag combinations: default parse keeps all 13 subpackage sections, 4 main-packageRequiresand 4cargo installsteps;--without crypt --without veritykeeps only the two cryptpilot-fde binaries and drops crypt/verity sections and their BuildRequires; the crypt-only and verity-only combos behave symmetrically.rpmbuild --without ...CLI form verified on rpm 4.14 (the version inside the alinux3 build container).cargo fmt --checkpasses (no Rust code touched).Expected effect
Each matrix job compiles one crate instead of four, in parallel: total wall clock should drop from ~2h to roughly a single-crate RPM build (~40min ballpark). Note the three jobs no longer share the sequential builder cache; each exports its own GHA cache.