A manual pipeline creation instantiates every file in .crow/, and a declared variable default is applied even when the run never passed that variable. So a gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on any manual run of any pipeline. Triggering a weekly-audit-missing run for one slot started build-all-versions (including its Upload package indexes step) and process-updates across every row. #155 fixed the three pipelines that had no gate at all; these six had a gate whose default was permissive, which left them just as exposed. - add a 'none' option to each gate variable and default to it, so a manual run must name its target explicitly - record why the default must match nothing, next to the default itself Cron triggers are unaffected: they match on the cron name, not the variable.
97 lines
3.4 KiB
YAML
97 lines
3.4 KiB
YAML
# Consolidated install-deps for build-all (both arches in one file).
|
|
# Triggered together with build-all-versions; `target_arch` routes the matrix.
|
|
# Variables are declared so the manual-run form exposes them (crow #1165);
|
|
# they are merged with build-all-versions' identical declarations.
|
|
variables:
|
|
# Gates this pipeline. A manual pipeline creation instantiates every file in
|
|
# .crow/, and a declared default is applied even when the run never passed
|
|
# this variable, so the default must be a value that matches no matrix row.
|
|
target_arch:
|
|
description: 'Architecture to build, or "none" to run nothing.'
|
|
options:
|
|
- none
|
|
- amd64
|
|
- arm64
|
|
default: none
|
|
OS:
|
|
description: 'Base OS image name.'
|
|
options:
|
|
- alpine
|
|
- redhat
|
|
- ubuntu
|
|
default: alpine
|
|
OS_VERSION:
|
|
description: 'OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble).'
|
|
options:
|
|
- '3.24'
|
|
- '8'
|
|
- '9'
|
|
- '10'
|
|
- 'jammy'
|
|
- 'noble'
|
|
default: '3.24'
|
|
R_VERSION:
|
|
description: 'Primary R version under /opt/R.'
|
|
options:
|
|
- 4.5.3
|
|
- 4.4.3
|
|
default: 4.5.3
|
|
|
|
when:
|
|
- event: manual
|
|
evaluate: 'target_arch == "${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
platform: linux/${ARCH}
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- ARCH: amd64
|
|
- ARCH: arm64
|
|
|
|
steps:
|
|
- name: 'Install deps and bincraft'
|
|
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
|
|
pull: true
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GITHUB_PAT:
|
|
from_secret: GITHUB_PAT
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
PGPASS:
|
|
from_secret: PGPASS
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
# Keep uvr's downloads and extracted-package entries on the persistent
|
|
# volume instead of the container-local ~/.uvr default.
|
|
UVR_CACHE_DIR: /mnt/cache/uvr/cache
|
|
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
|
|
CCACHE_DIR: /mnt/cache/ccache
|
|
volumes:
|
|
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
|
|
commands:
|
|
# one-time full wipe to fix corrupted .so files from previous failed builds
|
|
# - rm -rf /mnt/cache/R-pkgs
|
|
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
# Pin the same bincraft version the build steps use, so the precomputed
|
|
# snapshot and the per-agent library stay consistent across the pipeline.
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh RPostgres s3fs data.table future jsonlite
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
|
|
- /opt/R/$R_VERSION/bin/R -q -e "source('local/packages-to-build.R'); saveRDS(pkgs, '/mnt/cache/packages/pkgs_to_build.rds'); saveRDS(pkgs[r_minor_sensitive == TRUE], '/mnt/cache/packages/r_minor_sensitive_pkgs.rds'); sprintf('Precomputed %s package versions (%s r-minor-sensitive)', nrow(pkgs), nrow(pkgs[r_minor_sensitive == TRUE]))"
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 5Gi
|
|
cpu: 1000m
|