chore: persist Docker build cache mounts across CI runs (#32700)

This commit is contained in:
andig 2026-08-10 18:23:26 +02:00 • committed by GitHub
parent 3a0335cdd8
commit 6786ea8b2b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
6 changed files with 67 additions and 2 deletions

45
.github/actions/docker-cache/action.yml vendored Normal file
View file

@ -0,0 +1,45 @@
name: Docker build cache
description: >
Restores the Dockerfile's Go and npm cache mounts and persists them afterwards.
BuildKit cache mounts live in the builder daemon and are not covered by any
cache exporter, so they have to be injected and extracted explicitly. Requires
Buildx to be set up and must run before the build.
inputs:
builder:
description: Buildx builder name
required: true
cache-scope:
description: >
Cache namespace, mirroring build-toolchain. "main" (default) writes the
shared cache. Untrusted callers (e.g. PR builds) should pass a different
value such as "pr": writes stay isolated so they cannot poison the shared
cache, while reads still fall back to it.
default: main
runs:
using: composite
steps:
# Rotates with the dependency set. Source changes keep using the existing
# cache, which still covers the third-party packages dominating the build.
- name: Cache mount contents
id: cache
uses: actions/cache@v6
with:
path: .docker-cache
key: ${{ runner.os }}-docker-mounts-${{ inputs.cache-scope }}-${{ hashFiles('go.sum', 'package-lock.json') }}
restore-keys: |
${{ runner.os }}-docker-mounts-${{ inputs.cache-scope }}-
${{ runner.os }}-docker-mounts-main-
- name: Inject cache mounts
uses: reproducible-containers/buildkit-cache-dance@5422eac04292c961a382e0f584ea0f03ad9da723 # v3.4.0
with:
builder: ${{ inputs.builder }}
cache-map: |
{
".docker-cache/go-build": "/root/.cache/go-build",
".docker-cache/go-mod": "/root/.cache/go-mod",
".docker-cache/npm": "/root/.npm"
}
skip-extraction: ${{ steps.cache.outputs.cache-hit }}

View file

@ -129,8 +129,15 @@ jobs:
password: ${{ secrets.DOCKER_PASS }}
- name: Setup Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4
- name: Restore build cache
uses: ./.github/actions/docker-cache
with:
builder: ${{ steps.buildx.outputs.name }}
cache-scope: pr
- name: Publish
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7
with:

View file

@ -28,8 +28,14 @@ jobs:
password: ${{ secrets.DOCKER_PASS }}
- name: Setup Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4
- name: Restore build cache
uses: ./.github/actions/docker-cache
with:
builder: ${{ steps.buildx.outputs.name }}
- name: Define tags
id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6

View file

@ -60,8 +60,14 @@ jobs:
password: ${{ secrets.DOCKER_PASS }}
- name: Setup Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4
- name: Restore build cache
uses: ./.github/actions/docker-cache
with:
builder: ${{ steps.buildx.outputs.name }}
- name: Meta
id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6