ci: bound CI storage; don't bridge image-build jobs
- deploy/runner/prune.sh + windygit-ci-prune.timer (6h): age-based prune of the CI-only dind (containers, finished-job volumes, images/builder cache >7d) plus a hard 60 GB cap. Only that daemon, over its own TCP socket; never the host's Docker. It was 38 GB and unbounded — the same class of growth that filled Kit 0 on 09-01. - pr_status_bridge: jobs named *docker* are not posted. Job containers have no daemon by design (I-5), so they are red on every commit; a permanent red X teaches everyone to ignore red. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -30,6 +30,7 @@ from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
import urllib.error
|
||||
import urllib.request
|
||||
@@ -60,6 +61,13 @@ STATE = {
|
||||
}
|
||||
MIRROR_TAG = "[GH#"
|
||||
|
||||
# Image-build jobs cannot pass here BY DESIGN: job containers get no Docker
|
||||
# daemon (I-5 — the host socket would hand every workflow root on Veron 1).
|
||||
# Posting them would put a permanent red X on every commit, and a signal that is
|
||||
# always red trains everyone to ignore red. Not posted until a rootless builder
|
||||
# exists; that is a decision, recorded in docs/CUTOVER.md, not a failure.
|
||||
NO_DAEMON_JOB = re.compile(r"docker", re.IGNORECASE)
|
||||
|
||||
|
||||
def _call(base: str, token_header: str, method: str, path: str, body=None):
|
||||
req = urllib.request.Request(
|
||||
@@ -142,7 +150,7 @@ def post_statuses(repo: str, sha: str) -> None:
|
||||
break
|
||||
latest: dict[str, dict] = {}
|
||||
for r in runs:
|
||||
if r["head_sha"] != sha:
|
||||
if r["head_sha"] != sha or NO_DAEMON_JOB.search(r["name"]):
|
||||
continue
|
||||
ctx = f"windy-git/{r['workflow_id'].removesuffix('.yml')}/{r['name']}"
|
||||
if ctx not in latest or r["id"] > latest[ctx]["id"]:
|
||||
|
||||
Reference in New Issue
Block a user