💚 Bake Node into the CI job image
setup-node never consults `node` on PATH; its only fast path is a probe of /opt/hostedtoolcache, which the ephemeral act_runner job containers always miss, so every job paid a ~50 MB Node download. docker/Dockerfile extends the runner's default catthehacker/act image with the Node distribution overlaid at the exact tool-cache layout, so setup-node finds 26.8.2 and skips the fetch while node-version-file, cache: npm and registry-url keep working unchanged. Image layers dedupe against the base the host already pulled and prune via normal docker hygiene — the cleanup story a host bind of /opt/hostedtoolcache lacks. To make the bake deterministic, .node-version is pinned to the exact 26.8.2 the image carries; scripts/runner-image.sh guards that coupling and builds/pushes the tag the three node jobs now reference via container.image. Ops follow-up (outside the repo): build once with `npm run build:runner-image -- --push` on a machine with registry creds. If the package is private, the runner needs container registry credentials in its config.
This commit is contained in:
1 parent
b9fe21175f
commit
245dfaf198
6 files changed
+88
-5
No files matched your search
+17
-4
@@ -49,11 +49,16 @@ jobs:
|
||||
needs: release-gate
|
||||
if: needs.release-gate.outputs.skip != 'true'
|
||||
runs-on: ubuntu-latest
|
||||
# Bind-mount the shared pages tree so the coverage step below can write
|
||||
# into it. The runner whitelists this path via `container.valid_volumes`
|
||||
# (docker-space `setup/gitea.sh`); `image` is omitted on purpose so the
|
||||
# runner keeps using its default job image.
|
||||
# `image` extends the runner's default job image (catthehacker/act)
|
||||
# with Node 26 pre-planted in the tool cache layout, so setup-node's
|
||||
# version probe hits and never downloads (see docker/Dockerfile). The
|
||||
# tag MUST equal the exact version pinned in `.node-version`; rebuild
|
||||
# via `npm run build:runner-image -- --push` and repoint here on every
|
||||
# Node bump. The volume bind-mounts the shared pages tree so the
|
||||
# coverage step below can write into it; the runner whitelists this
|
||||
# path via `container.valid_volumes` (docker-space `setup/gitea.sh`).
|
||||
container:
|
||||
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||
volumes:
|
||||
- /data/gitea-pages:/data/gitea-pages
|
||||
steps:
|
||||
@@ -108,6 +113,10 @@ jobs:
|
||||
if: needs.release-gate.outputs.skip != 'true'
|
||||
runs-on: ubuntu-latest
|
||||
continue-on-error: true
|
||||
# Same baked image as `build` — without it this job re-downloads Node
|
||||
# per run (see docker/Dockerfile).
|
||||
container:
|
||||
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-node@v4
|
||||
@@ -121,6 +130,10 @@ jobs:
|
||||
if: startsWith(gitea.ref, 'refs/tags/')
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
# Same baked image as `build` — setup-node still owns the registry-url
|
||||
# `.npmrc` rewrite here; only the Node download is skipped.
|
||||
container:
|
||||
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||
# The release page is created with the run's automatic Gitea token
|
||||
# (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`.
|
||||
permissions:
|
||||
|
||||
Reference in new issue
Block a user