From 245dfaf1987383ed8cdd8abe4eb1d58ebd062498 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Mon, 14 Sep 2026 12:37:58 +0000 Subject: [PATCH] :green_heart: Bake Node into the CI job image MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit setup-node never consults `node` on PATH; its only fast path is a probe of /opt/hostedtoolcache, which the ephemeral act_runner job containers always miss, so every job paid a ~50 MB Node download. docker/Dockerfile extends the runner's default catthehacker/act image with the Node distribution overlaid at the exact tool-cache layout, so setup-node finds 26.8.2 and skips the fetch while node-version-file, cache: npm and registry-url keep working unchanged. Image layers dedupe against the base the host already pulled and prune via normal docker hygiene — the cleanup story a host bind of /opt/hostedtoolcache lacks. To make the bake deterministic, .node-version is pinned to the exact 26.8.2 the image carries; scripts/runner-image.sh guards that coupling and builds/pushes the tag the three node jobs now reference via container.image. Ops follow-up (outside the repo): build once with `npm run build:runner-image -- --push` on a machine with registry creds. If the package is private, the runner needs container registry credentials in its config. --- .gitea/workflows/ci.yml | 21 +++++++++++++++++---- .node-version | 2 +- cspell.json | 6 ++++++ docker/Dockerfile | 30 ++++++++++++++++++++++++++++++ package.json | 1 + scripts/runner-image.sh | 33 +++++++++++++++++++++++++++++++++ 6 files changed, 88 insertions(+), 5 deletions(-) create mode 100644 docker/Dockerfile create mode 100755 scripts/runner-image.sh diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index cb147a2..b6085d6 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -49,11 +49,16 @@ jobs: needs: release-gate if: needs.release-gate.outputs.skip != 'true' runs-on: ubuntu-latest - # Bind-mount the shared pages tree so the coverage step below can write - # into it. The runner whitelists this path via `container.valid_volumes` - # (docker-space `setup/gitea.sh`); `image` is omitted on purpose so the - # runner keeps using its default job image. + # `image` extends the runner's default job image (catthehacker/act) + # with Node 26 pre-planted in the tool cache layout, so setup-node's + # version probe hits and never downloads (see docker/Dockerfile). The + # tag MUST equal the exact version pinned in `.node-version`; rebuild + # via `npm run build:runner-image -- --push` and repoint here on every + # Node bump. The volume bind-mounts the shared pages tree so the + # coverage step below can write into it; the runner whitelists this + # path via `container.valid_volumes` (docker-space `setup/gitea.sh`). container: + image: gitea.e1nsnull.de/tmu/act-ci:26.8.2 volumes: - /data/gitea-pages:/data/gitea-pages steps: @@ -108,6 +113,10 @@ jobs: if: needs.release-gate.outputs.skip != 'true' runs-on: ubuntu-latest continue-on-error: true + # Same baked image as `build` — without it this job re-downloads Node + # per run (see docker/Dockerfile). + container: + image: gitea.e1nsnull.de/tmu/act-ci:26.8.2 steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 @@ -121,6 +130,10 @@ jobs: if: startsWith(gitea.ref, 'refs/tags/') needs: build runs-on: ubuntu-latest + # Same baked image as `build` — setup-node still owns the registry-url + # `.npmrc` rewrite here; only the Node download is skipped. + container: + image: gitea.e1nsnull.de/tmu/act-ci:26.8.2 # The release page is created with the run's automatic Gitea token # (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`. permissions: diff --git a/.node-version b/.node-version index 978b4e8..707210d 100644 --- a/.node-version +++ b/.node-version @@ -1 +1 @@ -26 \ No newline at end of file +26.8.2 diff --git a/cspell.json b/cspell.json index 58d50e3..a31d295 100644 --- a/cspell.json +++ b/cspell.json @@ -27,6 +27,12 @@ "knope", "runwisp", "glab", + "hostedtoolcache", + "catthehacker", + "nsnull", + "dedup", + "dedupe", + "repoint", "postversion", "prebuild", "Zilla", diff --git a/docker/Dockerfile b/docker/Dockerfile new file mode 100644 index 0000000..2650cb5 --- /dev/null +++ b/docker/Dockerfile @@ -0,0 +1,30 @@ +# CI job image for the Gitea act_runner: the runner's default job image with +# Node pre-planted where actions/setup-node looks first. +# +# Why this layout: setup-node ignores `node` on PATH; its only fast path is a +# probe of /opt/hostedtoolcache/node//. Without an entry there +# it downloads the ~50 MB distribution on EVERY job (the runner's job +# containers are ephemeral, so its tool cache never survives a job). The +# official node images keep exactly the layout setup-node expects under +# /usr/local, so this layer is a pure file overlay — no scripts, no env. +# +# Why not a host bind of /opt/hostedtoolcache: binds never self-prune. Docker +# images are content-addressed: the base layers dedupe against the act image +# the host already has, and `docker image prune` / re-pulls are the cleanup +# story. +# +# NODE_VERSION must match `.node-version` exactly. setup-node resolves a float +# like `26` to the latest known patch at runtime, so a bump silently busts the +# baked entry; `.node-version` is pinned to x.y.z and scripts/runner-image.sh +# guards the coupling. Rebuild + repoint `container.image` in +# .gitea/workflows/ci.yml on every bump. +FROM catthehacker/ubuntu:act-latest + +ARG NODE_VERSION=26.8.2 + +# node image: bin/ + lib/ under /usr/local → tool cache: bin/ + lib/ under /x64. +COPY --from=node:${NODE_VERSION} /usr/local /opt/hostedtoolcache/node/${NODE_VERSION}/x64 + +# Fail the build (not CI) if the overlay or the version arg were wrong. +# Shell form on purpose: exec form (`RUN [...]`) does not expand ARG values. +RUN "/opt/hostedtoolcache/node/${NODE_VERSION}/x64/bin/node" --version diff --git a/package.json b/package.json index aca4c28..3a9db00 100644 --- a/package.json +++ b/package.json @@ -38,6 +38,7 @@ }, "scripts": { "build": "tsc -p tsconfig.build.json", + "build:runner-image": "./scripts/runner-image.sh", "prebuild": "rm -rf dist", "check": "npm run check:tsc && npm run check:oxlint && npm run check:oxfmt && npm run check:cspell", "check:cspell": "cspell lint ${LEFTHOOK_FILES:-.}", diff --git a/scripts/runner-image.sh b/scripts/runner-image.sh new file mode 100755 index 0000000..6205cbd --- /dev/null +++ b/scripts/runner-image.sh @@ -0,0 +1,33 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Build (and optionally push) the CI job image from docker/Dockerfile. +# Run wherever docker + registry credentials live (the runner host, or any +# machine that can reach the registry). The registry/repo below MUST match +# the `container.image` references in .gitea/workflows/ci.yml — the runner +# pulls the image by name. +# +# Usage: scripts/runner-image.sh [--push] + +IMAGE_REPO="gitea.e1nsnull.de/tmu/act-ci" + +NODE_VERSION="$(tr -d '[:space:]' < .node-version)" +if [[ ! "${NODE_VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + echo "error: .node-version must be pinned to an exact x.y.z, got '${NODE_VERSION}'." >&2 + echo " setup-node resolves floats like '26' to the latest patch at runtime," >&2 + echo " which silently busts the tool-cache entry baked into the image." >&2 + exit 1 +fi + +IMAGE="${IMAGE_REPO}:${NODE_VERSION}" + +# --pull: refresh the act base layer so the derivative does not float on an +# aging default image forever (layer dedup keeps this cheap). +docker build --pull --build-arg "NODE_VERSION=${NODE_VERSION}" -t "${IMAGE}" -f docker/Dockerfile . + +if [[ "${1:-}" == "--push" ]]; then + docker push "${IMAGE}" +fi + +echo "built ${IMAGE}" +echo "reminder: bump container.image in .gitea/workflows/ci.yml to this tag"