Skip to content

Scope each run's cache-to writes to its own tag suffix - #63

Merged
bartgol merged 1 commit into
mainfrom
claude/cache-suffix-isolation
Sep 26, 2026
Merged

bartgol merged 1 commit into
mainfrom
claude/cache-suffix-isolation

Conversation

@bartgol

@bartgol bartgol commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Summary

Recreated after E3SM-Project/containers#62 was accidentally merged (base was mistakenly re-fast-forwarded, mixing both fixes into one branch). Same commit, same content — GitHub doesn't allow reopening a merged PR, so this is a fresh PR number.

Stacked on E3SM-Project/containers#61 (base branch is that PR's branch, so this diff only shows the new changes; merge/rebase #61 first).

Even with #61's fix, a non-fork PR (or merge_group run) that touches ghci/base or ghci/compiler still overwrote the shared, unsuffixed buildcache-<tag>-<arch> registry tag on every build — the same tag main and every other PR reads from. An in-progress PR's not-yet-reviewed Dockerfile change could silently become the cache basis for unrelated concurrent PRs (and for main itself, if the PR never merges), forcing a cold rebuild the next time they imported it.

  • Added a tag_suffix input to build-multiarch.yaml (the same -pr-<N>/-mg-<sha> value ghci.yaml's suffix job already computes and threads through BASE_TAG build-args).
  • cache-to now only ever writes this run's own buildcache-<tag><tag_suffix>-<arch> tag, never the plain one, unless tag_suffix is empty (a push to main).
  • cache-from reads both: this run's own suffixed tag first, then the plain tag as a fallback — so a PR's first build still benefits from whatever main last cached, and a missing cache-from source is a soft error buildx logs and skips, not a build failure.
  • This creates a new ephemeral tag shape (buildcache-<tag>-pr-<N>-<arch>, buildcache-<tag>-mg-<sha>-<arch>) that needs the same lifecycle as the real -pr-<N>/-mg-<sha> image tags, so cleanup-ghcr-packages.yaml's existing PR-close and merge_group-ephemeral patterns were extended to also match an optional trailing arch.

Test plan

  • node --check on the extracted actions/github-script bodies (syntax only)
  • python3 -c "import yaml; yaml.safe_load(...)" on all three changed workflow files
  • Next PR run should show base/compiler importing cache from the plain tag on first push, and from its own -pr-<N> tag on a second push
  • On PR close, delete-pr-images should also remove that PR's buildcache-*-pr-<N>-<arch> tags

🤖 Generated with Claude Code

https://claude.ai/code/session_01U1ni5gYuf7PVCbLikoveMK


Generated by Claude Code

mahf708
mahf708 previously approved these changes Sep 22, 2026
Base automatically changed from claude/wizardly-sagan-gfrig1 to main September 25, 2026 15:14
@bartgol
bartgol dismissed mahf708’s stale review September 25, 2026 15:14

The base branch was changed.

Even with the previous commit's fix, a non-fork PR (or merge_group
run) that touches ghci/base or ghci/compiler still overwrote the
shared, unsuffixed buildcache-<tag>-<arch> registry tag on every
build. That tag is what main and every other PR read from, so an
in-progress PR's not-yet-reviewed Dockerfile change could silently
become the cache basis for unrelated concurrent PRs (and for main
itself, if the PR never merges) -- forcing them into a cold rebuild
the next time they imported it.

Add a tag_suffix input to build-multiarch.yaml (the same -pr-<N> /
-mg-<sha> value ghci.yaml already computes in its `suffix` job and
threads through BASE_TAG build-args) and use it to separate reads from
writes:

- cache-to only ever writes buildcache-<tag><tag_suffix>-<arch>, this
  run's own cache scope. It never touches the plain
  buildcache-<tag>-<arch> tag unless tag_suffix is empty, i.e. a push
  to main.
- cache-from reads both: this run's own suffixed tag first (empty
  until a later push to the same PR/merge_group run has written it),
  then the plain tag as a fallback, so a PR's first build still
  benefits from whatever main last cached. A cache-from source that
  doesn't exist yet is a soft error buildx logs and skips, not a
  build failure.

This creates a new kind of registry tag -- buildcache-<tag>-pr-<N>-
<arch> and buildcache-<tag>-mg-<sha>-<arch> -- that needs the same
lifecycle as the real -pr-<N>/-mg-<sha> image tags, or it would leak
forever now that live buildcache tags are otherwise never swept by
age. Extend cleanup-ghcr-packages.yaml's existing tag patterns
(delete-pr-images' PR-close sweep, and cleanup-untagged's
merge_group-ephemeral age sweep) to also match an optional trailing
arch, so these new tags are cleaned up exactly like their non-cache
counterparts already are.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U1ni5gYuf7PVCbLikoveMK
@bartgol
bartgol force-pushed the claude/cache-suffix-isolation branch from 24a016e to f09cd8c Compare September 25, 2026 15:19
@bartgol
bartgol requested a review from mahf708 September 25, 2026 15:20
@bartgol
bartgol enabled auto-merge September 25, 2026 15:21
@bartgol
bartgol added this pull request to the merge queue Sep 25, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Sep 25, 2026
@mahf708
mahf708 enabled auto-merge September 25, 2026 21:56
@mahf708
mahf708 added this pull request to the merge queue Sep 25, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 25, 2026
@bartgol
bartgol enabled auto-merge September 25, 2026 22:33
@bartgol
bartgol added this pull request to the merge queue Sep 25, 2026
Merged via the queue into main with commit 1d2ec13 Sep 26, 2026
33 checks passed
@bartgol
bartgol deleted the claude/cache-suffix-isolation branch September 26, 2026 02:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ghci github ci

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants