Skip to content

ci(docker): build the three images in parallel matrix jobs - #148

Merged
imlk0 merged 1 commit into
masterfrom
parallel-docker-builds
Oct 9, 2026
Merged

imlk0 merged 1 commit into
masterfrom
parallel-docker-builds

Conversation

@imlk0

@imlk0 imlk0 commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Problem

The Build Docker Images workflow builds cryptpilot-fde / cryptpilot-crypt / cryptpilot-verity sequentially in a single job. Wall clock is ~2h (recent master runs: 2h22m, other branches 1h52m+), because every Dockerfile's builder stage runs rpmbuild over the whole Rust workspace (all four cargo binaries), and the shared builder-stage cache only helps the 2nd and 3rd images.

Relatedly, the spec's %build always runs all four cargo install invocations no matter which RPMs are actually needed.

Changes

  • .github/workflows/build-docker.yml: the single job becomes a fail-fast: false matrix of three parallel jobs (fde / crypt / verity). Per-job steps are unchanged in substance: checkout, buildx, docker/metadata-action (same tag rules: branch/pr/semver x2/sha/latest), build-push-action, docker load + --version smoke test, GHCR login, push loop. Triggers unchanged.
  • cryptpilot.spec: new bcond switches %bcond_without fde / crypt / verity. Subpackage Requires of the meta package, %package/%description, %build cargo installs, %install staging, %files and scriptlets are wrapped in matching %if blocks. dist/systemd/cryptpilot.service (claimed by both cryptpilot-fde-guest and cryptpilot-crypt) is guarded by %if %{with fde} || %{with crypt}. The default expansion (no flags) is unchanged: all subpackages build exactly as before, so the existing RPM CI paths are not affected.
  • Dockerfile.fde / .crypt / .verity: the builder stage passes --without flags to rpmbuild (and matching _without_* defines to yum-builddep, so e.g. verity's cmake/fuse3-devel BuildRequires are skipped when not needed). Each image build now compiles only the crate(s) it packages.

Validation

  • rpmspec -P under all flag combinations: default parse keeps all 13 subpackage sections, 4 main-package Requires and 4 cargo install steps; --without crypt --without verity keeps only the two cryptpilot-fde binaries and drops crypt/verity sections and their BuildRequires; the crypt-only and verity-only combos behave symmetrically. rpmbuild --without ... CLI form verified on rpm 4.14 (the version inside the alinux3 build container).
  • cargo fmt --check passes (no Rust code touched).
  • The per-PR run of this workflow is the end-to-end check: three parallel Build Docker Images jobs, each doing a subset RPM build.

Expected effect

Each matrix job compiles one crate instead of four, in parallel: total wall clock should drop from ~2h to roughly a single-crate RPM build (~40min ballpark). Note the three jobs no longer share the sequential builder cache; each exports its own GHA cache.

The single build-and-push job built cryptpilot-fde/crypt/verity
sequentially, ~2h wall clock (recent master runs: 2h22m): every
Dockerfile's builder stage runs rpmbuild over the whole Rust workspace,
and the shared builder-stage cache only helps the 2nd/3rd images.

Split the job into a fail-fast=false matrix of three parallel jobs, one
per image. To keep each job from paying the full workspace compile, add
bcond switches (fde/crypt/verity) to cryptpilot.spec so a subset build
skips the other crates' cargo install calls, subpackage definitions,
%files and scriptlets. The Dockerfiles pass --without flags to rpmbuild
and matching _without_* defines to yum-builddep (so BuildRequires like
verity's cmake/fuse3-devel are skipped as well). The default expansion
without flags builds everything as before - the existing RPM CI paths
are unaffected.

Validated locally with rpmspec -P under all flag combinations: the
default parse keeps all 13 subpackage sections and 4 cargo installs;
each --without combo drops exactly the disabled subpackages and their
cargo install steps (e.g. --without crypt --without verity keeps only
the two cryptpilot-fde binaries).

Each job now compiles only the crate(s) its image packages, so the
three parallel jobs should finish in roughly the time of a single-crate
RPM build instead of ~2h.

Assisted-by: Claude:glm-5.3
Signed-off-by: Kun Lai <[email protected]>
@ostest-bot

Copy link
Copy Markdown

@imlk0 ,您好,您的请求已接收,请耐心等待结果。

@ostest-bot

Copy link
Copy Markdown

@imlk0 ,您好,未检测到有镜像需要构建,如需重新检测请评论 /start 。

@imlk0
imlk0 merged commit b243eb7 into master Oct 9, 2026
44 of 48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants