ci: bound CI storage; don't bridge image-build jobs

- deploy/runner/prune.sh + windygit-ci-prune.timer (6h): age-based prune
  of the CI-only dind (containers, finished-job volumes, images/builder
  cache >7d) plus a hard 60 GB cap. Only that daemon, over its own TCP
  socket; never the host's Docker. It was 38 GB and unbounded — the same
  class of growth that filled Kit 0 on 09-01.
- pr_status_bridge: jobs named *docker* are not posted. Job containers
  have no daemon by design (I-5), so they are red on every commit; a
  permanent red X teaches everyone to ignore red.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 02:47:28 -04:00
parent e4a15869c0
commit 45686283be
6 changed files with 65 additions and 1 deletions

View File

@@ -30,6 +30,7 @@ from __future__ import annotations
import json
import os
import re
import sys
import urllib.error
import urllib.request
@@ -60,6 +61,13 @@ STATE = {
}
MIRROR_TAG = "[GH#"
# Image-build jobs cannot pass here BY DESIGN: job containers get no Docker
# daemon (I-5 — the host socket would hand every workflow root on Veron 1).
# Posting them would put a permanent red X on every commit, and a signal that is
# always red trains everyone to ignore red. Not posted until a rootless builder
# exists; that is a decision, recorded in docs/CUTOVER.md, not a failure.
NO_DAEMON_JOB = re.compile(r"docker", re.IGNORECASE)
def _call(base: str, token_header: str, method: str, path: str, body=None):
req = urllib.request.Request(
@@ -142,7 +150,7 @@ def post_statuses(repo: str, sha: str) -> None:
break
latest: dict[str, dict] = {}
for r in runs:
if r["head_sha"] != sha:
if r["head_sha"] != sha or NO_DAEMON_JOB.search(r["name"]):
continue
ctx = f"windy-git/{r['workflow_id'].removesuffix('.yml')}/{r['name']}"
if ctx not in latest or r["id"] > latest[ctx]["id"]: