Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Publish verified main images for reuse in CI - #73094

Draft
jason810496 wants to merge 6 commits into
apache:mainfrom
jason810496:ci/image-reuse/04-publisher
Draft

Publish verified main images for reuse in CI#73094
jason810496 wants to merge 6 commits into
apache:mainfrom
jason810496:ci/image-reuse/04-publisher

Conversation

@jason810496

@jason810496 jason810496 commented Sep 13, 2026

Copy link
Copy Markdown
Member

Part 4/5 of the CI image reuse series.

Why

Provide verified main images before enabling reuse in PR tests.

How

Publish CI images, production images, and dependency layers on both architectures; keep publication opt-in and shared artifacts immutable across retries.

Series impact (audit draft)

Sept 6–12, 2026 UTC PR census and CI timing:

Metric Figure
Merged PRs / into main 364 / 240
No dependency-manifest / CI-image / prod-image input changes 218 (90.8%) / 141 (58.8%) / 47 (19.6%)
Full AMD/ARM census execution 17,175.6 h
Image-prep latency, today → 100% hit rate (CI, Py3.10) 19.74 → 5.77 min (−71%)
Latency break-even hit rate ~3.5%
Compute ceiling, cost-free → cost-priced replacement download 106.4 h → ~65.7 h/week
This PR's publisher budget proxy (daily-only cadence) 8.0 h/run → 55.7 h/week
Compute break-even hit rate (daily-only publisher) ~85%

The purpose is to avoid rebuilding the CI image when a PR doesn't change package dependencies — currently, even a PR that only touches the API server or the UI still triggers a full CI image rebuild on every push — and real hit rate and end-to-end PR latency remain unmeasured pending a pilot.

  • Happy path: a cache hit cuts image-prep latency by ~71% (19.74 → 5.77 min for the dominant Python 3.10 CI case). A miss only costs about 30 extra seconds, so even a low cache-hit rate (as little as ~3.5%) already makes this a net time saver overall.
  • Smart fallback: the consumer probes transfer speed over the first 30 seconds of a selected image's download; if that regresses below the reuse floor (added in ci/image-reuse/03-artifact-selection), it falls back to a regular image build — today's existing behavior — instead of waiting out a degraded transfer.
  • Daily image publish workflow: this PR adds the centralized periodic workflow that publishes CI and production images, keyed by a fingerprint of build inputs (dependency lockfiles, base-image digest, build args), as GitHub Actions artifacts for PRs to reuse.
  • Retention: a published artifact is only selected if produced within the last 48 hours, and is retained for 7 days.

Was generative AI tooling used to co-author this PR?

Generated-by: Codex (GPT-6)

Shared CI environments must fail when their locked dependencies cannot be installed, so consumers never reuse a silently re-resolved environment.
Application-only changes should not repeat dependency installation. Separate metadata inputs retain resolver checks while current wheels replace application files.
CI needs a stable compatibility and provenance contract before it can safely reuse an image produced by another workflow run.
A cross-run artifact download that degrades to a crawl instead of
failing outright previously had no circuit breaker: nothing aborted
it, and the consumer would just wait far longer than a fresh build
would have taken. Measure the average transfer rate after the first
30 seconds and abandon the download in favor of building locally
once it falls under 50 MB/s, the rate below which finishing the
transfer is expected to cost more time than it saves.
A retained publisher gives CI a trusted source of compatible environments and dependency caches. Publication must finish successfully and preserve artifacts across retries before consumers can rely on them.
Comment on lines +65 to +76
- name: Fingerprint and resolve
id: resolve
shell: bash
env:
IMAGE_KIND: ${{ inputs.kind }}
IMAGE_PYTHON: ${{ inputs.python }}
IMAGE_PLATFORM: ${{ inputs.platform }}
IMAGE_BASE: ${{ inputs.base-image }}
IMAGE_CONSTRAINTS_FILE: ${{ inputs.constraints-file }}
IMAGE_PUBLISH: ${{ inputs.publish }}
IMAGE_REUSE_DISABLED: ${{ inputs.disabled }}
run: ./scripts/ci/resolve_main_image.sh
Comment on lines +159 to +161
- name: "Install Breeze"
uses: ./.github/actions/breeze
- name: "Resolve compatible main CI image"
Installing Breeze before freeing disk space left the venv's Python
symlinked into the runner's hosted toolcache, which the disk-space
script then deletes outright — every later step that shells out to
python3 failed with "No such file or directory" once the space was
freed. Restore the original ordering so cleanup runs first.
Comment on lines +159 to +162
- name: "Install Breeze"
uses: ./.github/actions/breeze
- name: "Resolve compatible main CI image"
id: main-image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dev-tools area:production-image Production image improvements and fixes backport-to-v3-3-test Backport to v3-3-test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants