Skip to content

Commit 416253f

Browse files
committed
Cache docker build images in ghcr.io to speed up CI
Motivation: Every docker compose build in ci-build.yml, ci-pr.yml, ci-deploy.yml and ci-release.yml rebuilds the CentOS6/CentOS7-aarch64/Debian7/AL2023 images from scratch on each run since GitHub-hosted runners are ephemeral and have no persistent layer cache. ci-build.yml/ci-pr.yml previously worked around this with a type=gha buildx cache scoped per matrix leg; ci-deploy.yml and ci-release.yml had no docker layer caching at all. Modifications: Switch to buildx with a registry cache backend (ghcr.io) so the expensive image layers (devtoolset, OpenSSL built from source, cross-compile toolchains) are reused across runs and across workflows. Cache images are pushed to ghcr.io/netty/netty-tcnative-build-cache, distinct from netty/netty's own ghcr.io/netty/netty-build-cache, so the two repositories' caches can never collide or overwrite each other. Result: Speed up CI builds.
1 parent 6279e1c commit 416253f

8 files changed

Lines changed: 88 additions & 14 deletions

‎.github/workflows/ci-build.yml‎

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,12 +42,26 @@ jobs:
4242
docker-bake-args: "-f docker-compose.al2023.yaml"
4343

4444
name: ${{ matrix.setup }}
45+
permissions:
46+
contents: read
47+
packages: write # to push the docker build cache to ghcr.io
4548
steps:
4649
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4750

4851
- name: Set up Docker Buildx
4952
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
5053

54+
# The docker-compose*.yaml files push/pull their build cache to
55+
# ghcr.io/netty/netty-tcnative-build-cache (distinct from netty/netty's own
56+
# ghcr.io/netty/netty-build-cache, so the two repos' caches never collide).
57+
- name: Log in to GitHub Container Registry
58+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
59+
continue-on-error: true
60+
with:
61+
registry: ghcr.io
62+
username: ${{ github.actor }}
63+
password: ${{ secrets.GITHUB_TOKEN }}
64+
5165
# Cache .m2/repository
5266
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
5367
continue-on-error: true
@@ -67,7 +81,7 @@ jobs:
6781
working-directory: docker
6882
env:
6983
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
70-
run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max"
84+
run: docker buildx bake ${{ matrix.docker-bake-args }} --load
7185

7286
- name: Build project
7387
run: docker compose ${{ matrix.docker-compose-run }} | tee build.output

‎.github/workflows/ci-deploy.yml‎

Lines changed: 24 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,23 +25,40 @@ concurrency:
2525
jobs:
2626
stage-snapshot:
2727
runs-on: ubuntu-latest
28+
permissions:
29+
contents: read
30+
packages: write # to push the docker build cache to ghcr.io
2831
strategy:
2932
matrix:
3033
include:
3134
- setup: centos6-x86_64
32-
docker-compose-build: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml build"
35+
docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml"
3336
docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run stage-snapshot"
3437
- setup: debian7-x86_64
35-
docker-compose-build: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml build"
38+
docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml"
3639
docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run stage-snapshot"
3740
- setup: centos7-aarch64
38-
docker-compose-build: "-f docker/docker-compose.centos-7.yaml build"
41+
docker-bake-args: "-f docker-compose.centos-7.yaml"
3942
docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-stage-snapshot"
4043

4144
name: stage-snapshot-${{ matrix.setup }}
4245
steps:
4346
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4447

48+
- name: Set up Docker Buildx
49+
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
50+
51+
# This workflow's token only has read-all permissions unless the job grants packages:
52+
# write above; ignore-error=true on cache_to in the compose files absorbs any push
53+
# failure. Cache reads (populated by ci-build.yml/ci-pr.yml) still work either way.
54+
- name: Log in to GitHub Container Registry
55+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
56+
continue-on-error: true
57+
with:
58+
registry: ghcr.io
59+
username: ${{ github.actor }}
60+
password: ${{ secrets.GITHUB_TOKEN }}
61+
4562
# Cache .m2/repository
4663
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4764
continue-on-error: true
@@ -55,7 +72,10 @@ jobs:
5572
run: mkdir -p ~/local-staging
5673

5774
- name: Build docker image
58-
run: docker compose ${{ matrix.docker-compose-build }}
75+
working-directory: docker
76+
env:
77+
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
78+
run: docker buildx bake ${{ matrix.docker-bake-args }} --load
5979

6080
- name: Stage snapshots to local staging directory
6181
run: docker compose ${{ matrix.docker-compose-run }}

‎.github/workflows/ci-pr.yml‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,12 +40,25 @@ jobs:
4040
docker-bake-args: "-f docker-compose.al2023.yaml"
4141

4242
name: ${{ matrix.setup }}
43+
permissions:
44+
contents: read
45+
packages: write # to push the docker build cache to ghcr.io; no-op (ignored) for fork PRs
4346
steps:
4447
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4548

4649
- name: Set up Docker Buildx
4750
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
4851

52+
# Only succeeds for same-repo runs; fork PRs get a read-only GITHUB_TOKEN and simply won't
53+
# get cache hits/pushes, which is fine since it only means a slower, non-cached build.
54+
- name: Log in to GitHub Container Registry
55+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
56+
continue-on-error: true
57+
with:
58+
registry: ghcr.io
59+
username: ${{ github.actor }}
60+
password: ${{ secrets.GITHUB_TOKEN }}
61+
4962
# Cache .m2/repository
5063
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
5164
continue-on-error: true
@@ -65,7 +78,7 @@ jobs:
6578
working-directory: docker
6679
env:
6780
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
68-
run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max"
81+
run: docker buildx bake ${{ matrix.docker-bake-args }} --load
6982

7083
- name: Build project
7184
run: docker compose ${{ matrix.docker-compose-run }} | tee build.output

‎.github/workflows/ci-release.yml‎

Lines changed: 19 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -75,17 +75,18 @@ jobs:
7575
needs: prepare-release
7676
permissions:
7777
contents: write
78+
packages: write # to push the docker build cache to ghcr.io
7879
strategy:
7980
matrix:
8081
include:
8182
- setup: centos6-x86_64
82-
docker-compose-build: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml build"
83+
docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml"
8384
docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run stage-release"
8485
- setup: debian7-x86_64
85-
docker-compose-build: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml build"
86+
docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml"
8687
docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run stage-release"
8788
- setup: centos7-aarch64
88-
docker-compose-build: "-f docker/docker-compose.centos-7.yaml build"
89+
docker-bake-args: "-f docker-compose.centos-7.yaml"
8990
docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-stage-release"
9091

9192
name: stage-release-${{ matrix.setup }}
@@ -117,6 +118,17 @@ jobs:
117118
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
118119
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
119120

121+
- name: Set up Docker Buildx
122+
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
123+
124+
- name: Log in to GitHub Container Registry
125+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
126+
continue-on-error: true
127+
with:
128+
registry: ghcr.io
129+
username: ${{ github.actor }}
130+
password: ${{ secrets.GITHUB_TOKEN }}
131+
120132
# Cache .m2/repository
121133
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
122134
continue-on-error: true
@@ -146,12 +158,11 @@ jobs:
146158
working-directory: ./prepare-release-workspace/
147159
run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
148160

149-
# Release builds intentionally use docker compose (not buildx bake) for a clean,
150-
# cache-free build. OPENSSL_VERSION is still extracted above so docker-compose can
151-
# interpolate it as a build arg.
152161
- name: Build docker image
153-
working-directory: ./prepare-release-workspace/
154-
run: docker compose ${{ matrix.docker-compose-build }}
162+
working-directory: ./prepare-release-workspace/docker
163+
env:
164+
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
165+
run: docker buildx bake ${{ matrix.docker-bake-args }} --load
155166

156167
- name: Stage release to local staging directory
157168
working-directory: ./prepare-release-workspace/

‎docker/docker-compose.al2023.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ services:
77
build:
88
context: ../
99
dockerfile: docker/Dockerfile.al2023
10+
cache_from:
11+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:al2023
12+
cache_to:
13+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:al2023,mode=max,ignore-error=true
1014

1115
common: &common
1216
image: netty-tcnative-al2023:x86_64

‎docker/docker-compose.centos-6.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ services:
1010
args:
1111
openssl_version: "${OPENSSL_VERSION:-3.6.1}"
1212
openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}"
13+
cache_from:
14+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:centos6
15+
cache_to:
16+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:centos6,mode=max,ignore-error=true
1317

1418
common: &common
1519
image: netty-tcnative-centos:default

‎docker/docker-compose.centos-7.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,10 @@ services:
1212
apr_version: "1.7.6"
1313
openssl_version: "${OPENSSL_VERSION:-3.6.1}"
1414
openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}"
15+
cache_from:
16+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:cross-aarch64
17+
cache_to:
18+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:cross-aarch64,mode=max,ignore-error=true
1519

1620
cross-compile-aarch64-common: &cross-compile-aarch64-common
1721
image: netty-tcnative-centos:cross_compile_aarch64

‎docker/docker-compose.debian.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ services:
1010
args:
1111
openssl_version: "${OPENSSL_VERSION:-3.6.1}"
1212
openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}"
13+
cache_from:
14+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian7
15+
cache_to:
16+
- type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian7,mode=max,ignore-error=true
1317

1418
common: &common
1519
image: netty-tcnative-debian:default

0 commit comments

Comments
 (0)