Some checks failed
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
ci/crow/cron/process-updates/9 Pipeline was canceled
ci/crow/cron/process-updates/4 Pipeline was successful
ci/crow/manual/build-all-versions-install-deps/2 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was canceled
ci/crow/cron/process-updates/8 Pipeline failed
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was canceled
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline failed
ci/crow/manual/build-all-versions-install-deps/1 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline failed
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/manual/build-all-versions/2 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/manual/build-all-versions/3 Pipeline failed
ci/crow/manual/build-all-versions/1 Pipeline failed
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/manual/build-all-versions/6 Pipeline failed
ci/crow/manual/build-all-versions/5 Pipeline was canceled
ci/crow/manual/build-all-versions/8 Pipeline was canceled
ci/crow/cron/process-updates/12 Pipeline was canceled
ci/crow/manual/build-all-versions/7 Pipeline was canceled
ci/crow/cron/process-updates/6 Pipeline failed
ci/crow/cron/process-updates/2 Pipeline failed
ci/crow/manual/build-all-versions/4 Pipeline was canceled
## Problem
The arm64 `build-all` pipeline fills the macmini (gaia) host disk despite an 8h prune.
Root cause is not images or job volumes: it is the persistent dep-cache volume, specifically `pkgcache/R/pkgcache/_metadata`, which grew to ~165 GB.
`{pkgcache}` mints a new content hash for the "patched" binaries repo on every PACKAGES change, so each per-package build writes a fresh ~70 MB `pkgs-<hash>.rds` (+ `patched-<hash>/`) that is never evicted (2407 snapshots observed).
When the disk hits 100% OrbStack stops and the on-host prune can no longer connect to the daemon, so it never self-heals.
## Change (Workstream A of the disk-fill fix)
- Add `trim_pkgcache_metadata()` to `local/r-minor-helpers.R`: keeps the newest `keep` (default 20) `patched-*`/`pkgs-*.rds` entries under `_metadata`, deleting only entries older than `min_age_secs` (default 600s) so it never races the up-to-4 concurrent split-jobs sharing the volume.
Preserves `pkg/` downloads and the stable CRAN/BioC/INLA repo dirs.
No-op when `R_PKG_CACHE_DIR` is empty (amd64) or `_metadata` is absent (first run).
- Call it every 25 packages inside the build loop in `local/build-all.R`.
- Add a defensive start-of-run cleanup of `_metadata/patched-*` + `pkgs-*.rds` to the two workflows that mount the persistent volume (`build-all-versions.yaml`, `build-all-versions-install-deps.yaml`).
Only these paths are touched; `process-updates.yaml`/`weekly-rebuild-missing.yaml` (no persistent volume) are unchanged.
Follow-ups (separate workstreams): on-host self-healing prune watcher + OrbStack disk cap (ansible), and Prometheus/Grafana alerting (k8s-talos).
Upstream: bincraft patched-repo hash churn is the true source fix.
New unit tests (6) for the helper; full suite 24/24 green.
Reviewed-on: #110
189 lines
7.3 KiB
YAML
189 lines
7.3 KiB
YAML
### Manual full rebuild of all CRAN binaries for one OS/arch.
|
|
# Set the variables below in the manual-run form (or via --var on the CLI).
|
|
# `target_arch` routes the matrix; OS/OS_VERSION/R_VERSION select the platform
|
|
# image and cache volume. Placement is via the group label (rpkgs-amd64/rpkgs-arm64).
|
|
# Skip list lives in local/excluded-packages.json (read by local/build-all.R).
|
|
variables:
|
|
target_arch:
|
|
description: 'Architecture to build.'
|
|
options:
|
|
- amd64
|
|
- arm64
|
|
default: amd64
|
|
OS:
|
|
description: "Base OS image name."
|
|
options:
|
|
- alpine
|
|
- redhat
|
|
- ubuntu
|
|
default: alpine
|
|
OS_VERSION:
|
|
description: "OS image tag. Must match OS (alpine: 3.24; redhat: 8/9/10; ubuntu: jammy/noble)."
|
|
options:
|
|
- "3.22"
|
|
- "3.23"
|
|
- "3.24"
|
|
- "8"
|
|
- "9"
|
|
- "10"
|
|
- "jammy"
|
|
- "noble"
|
|
- "resolute"
|
|
default: "3.24"
|
|
R_VERSION:
|
|
description: 'Primary R version under /opt/R.'
|
|
options:
|
|
- 4.5.3
|
|
- 4.4.3
|
|
default: 4.5.3
|
|
|
|
when:
|
|
- event: manual
|
|
evaluate: 'target_arch == "${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
platform: linux/${ARCH}
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- ARCH: amd64
|
|
R_PKG_CACHE_DIR: ''
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 1
|
|
- ARCH: amd64
|
|
R_PKG_CACHE_DIR: ''
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 2
|
|
- ARCH: amd64
|
|
R_PKG_CACHE_DIR: ''
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 3
|
|
- ARCH: amd64
|
|
R_PKG_CACHE_DIR: ''
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 4
|
|
- ARCH: arm64
|
|
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 1
|
|
- ARCH: arm64
|
|
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 2
|
|
- ARCH: arm64
|
|
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 3
|
|
- ARCH: arm64
|
|
R_PKG_CACHE_DIR: /mnt/cache/pkgcache
|
|
SPLIT_INTO: 4
|
|
SPLIT_INDEX: 4
|
|
|
|
depends_on:
|
|
- build-all-versions-install-deps
|
|
|
|
steps:
|
|
- name: 'Build binaries'
|
|
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
|
|
pull: true
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
RED_HAT_DEV_PW:
|
|
from_secret: RED_HAT_DEV_PW
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
PGPASS:
|
|
from_secret: PGPASS
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GITHUB_PAT:
|
|
from_secret: GITHUB_PAT
|
|
# normal env vars
|
|
GIT_USER: pat-s
|
|
# set the location of the 'pkgcache' cache dir which persists the R package dependencies needed to install the packages themselves
|
|
R_PKG_CACHE_DIR: ${R_PKG_CACHE_DIR}
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
CCACHE_DIR: /mnt/cache/ccache
|
|
NCPUS: 2
|
|
volumes:
|
|
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
|
|
commands:
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
# Clear churny pkgcache metadata left by a prior crashed run (the "patched"
|
|
# repo mints a new hash per PACKAGES change -> unbounded pkgs-*.rds/patched-*).
|
|
# Keep pkg/ downloads and the stable CRAN/BioC/INLA repo dirs. Within-run
|
|
# growth is bounded separately by trim_pkgcache_metadata() in build-all.R.
|
|
- rm -rf /mnt/cache/pkgcache/R/pkgcache/_metadata/patched-* /mnt/cache/pkgcache/R/pkgcache/_metadata/pkgs-*.rds || true
|
|
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
|
|
# The primary pass must not rely on build-all-versions-install-deps having
|
|
# run on *this* agent: depends_on only orders the steps, but the cache
|
|
# volume is per-agent, so a job landing on an agent where install-deps did
|
|
# not run would otherwise use a stale bincraft (which resolves `platform`
|
|
# to a zero-length value and breaks every metadata query and the sysdeps
|
|
# install). Pin bincraft here, exactly like the R-minor pass below.
|
|
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run); XVFB_ARGS=""; if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi
|
|
- $XVFB $XVFB_ARGS -n $SPLIT_INDEX -- /opt/R/$R_VERSION/bin/Rscript local/build-all.R $SPLIT_INTO $SPLIT_INDEX $NCPUS 2>&1
|
|
- |
|
|
PRIMARY_MINOR=$(echo "$R_VERSION" | cut -d. -f1-2)
|
|
for RBIN in /opt/R/[0-9]*/bin/R; do
|
|
RV=$(basename "$(dirname "$(dirname "$RBIN")")")
|
|
RMINOR=$(echo "$RV" | cut -d. -f1-2)
|
|
[ "$RMINOR" = "$PRIMARY_MINOR" ] && continue
|
|
echo "=== R-minor-sensitive pass under R $RV ==="
|
|
LIB="/mnt/cache/R-pkgs-$RMINOR"
|
|
mkdir -p "$LIB"
|
|
R_LIBS_USER="$LIB" "$(dirname "$RBIN")/Rscript" local/install-bincraft.R || true
|
|
R_LIBS_USER="$LIB" $XVFB $XVFB_ARGS -n $SPLIT_INDEX -- "$(dirname "$RBIN")/Rscript" local/build-all.R --sensitive-only $SPLIT_INTO $SPLIT_INDEX $NCPUS 2>&1 || true
|
|
done
|
|
# archive missed packages; first arg is the codename (e.g. "alpine324"),
|
|
# derived via bincraft like the upload step, not paste(OS, OS_VERSION).
|
|
- /opt/R/$R_VERSION/bin/R -q -e "bincraft::process_unarchived_pkgs(bincraft::set_codename(NULL), Sys.getenv('ARCH'), s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'), workers = $NCPUS)"
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 5Gi
|
|
cpu: 1000m
|
|
limits:
|
|
memory: 20Gi
|
|
cpu: 2000m
|
|
- name: 'Upload package indexes'
|
|
image: 'reg.devxy.io/rpkgs/build-env-${OS}:${OS_VERSION}'
|
|
pull: true
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
volumes:
|
|
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
|
|
commands:
|
|
- |
|
|
CODENAME=$(/opt/R/$R_VERSION/bin/Rscript -e "cat(bincraft::set_codename(NULL))")
|
|
/opt/R/$R_VERSION/bin/R -q -e "bincraft::upload_package_index(codename = '$CODENAME', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'))"
|
|
for RBIN in /opt/R/[0-9]*/bin/R; do
|
|
RMINOR=$(basename "$(dirname "$(dirname "$RBIN")")" | cut -d. -f1-2)
|
|
/opt/R/$R_VERSION/bin/R -q -e "bincraft::upload_package_index(codename = '$CODENAME', r_minor = '$RMINOR', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'))" || true
|
|
done
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 5Gi
|
|
cpu: 1000m
|
|
limits:
|
|
memory: 20Gi
|
|
cpu: 2000m
|