A rebuild replaces an object in place: a package whose build failed was published as its CRAN source, and the rebuilt binary takes exactly the same URL. Two things then hide the result from clients. The slot's index still advertises the old MD5 and, for anything served from source, no Built stamp, because weekly-rebuild-missing never re-indexed. And the pull zone caches tarballs for ~370 days, while purge_cdn_cache.sh only purges the five index files, so the edge keeps serving the source tarball for up to a year with nothing about it looking wrong. Observed after rebuilding AATtools 0.0.3: the pipeline reported a successful upload while the edge still served the CRAN source, etag ea8127... and no Meta/. - re-index the slot at the end of a rebuild, flat and per-minor, detecting the codename from the image rather than adding OS_ID to 18 matrix rows - add scripts/purge_cdn_zone.sh and call it afterwards. One zone purge covers every replaced object and all three hostnames, which share pull zone 3857050; purging per URL would be ~13.5k rate-limited calls per arch where one missed call leaves a silently stale package - purge on failure too, since a rebuild that died part-way still replaced objects and those are exactly the ones a stale edge keeps hiding
207 lines
8.3 KiB
YAML
207 lines
8.3 KiB
YAML
# Consolidated weekly-rebuild-missing pipeline (all platforms, both arches).
|
|
# One matrix row per OS/arch replaces the former per-platform files.
|
|
# Routing is preserved 1:1:
|
|
# - cron: each existing `weekly-rebuild-missing-<os>-<arch>` cron fires only
|
|
# its matching matrix row (via the per-row `cron:` name filter).
|
|
# - manual: `weekly_rebuild_missing` dropdown, default "all" (matches the
|
|
# previous bare manual trigger that ran every os/arch); pick a
|
|
# single <os>-<arch> to run just one.
|
|
# Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64).
|
|
variables:
|
|
# Gates this pipeline. A manual pipeline creation instantiates every file in
|
|
# .crow/, and a declared default is applied even when the run never passed
|
|
# this variable, so the default must be a value that matches no matrix row.
|
|
weekly_rebuild_missing:
|
|
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
|
|
options:
|
|
- none
|
|
- all
|
|
- alpine-322-amd64
|
|
- alpine-322-arm64
|
|
- alpine-323-amd64
|
|
- alpine-323-arm64
|
|
- alpine-324-amd64
|
|
- alpine-324-arm64
|
|
- redhat-8-amd64
|
|
- redhat-8-arm64
|
|
- redhat-9-amd64
|
|
- redhat-9-arm64
|
|
- redhat-10-amd64
|
|
- redhat-10-arm64
|
|
- ubuntu-2204-amd64
|
|
- ubuntu-2204-arm64
|
|
- ubuntu-2404-amd64
|
|
- ubuntu-2404-arm64
|
|
- ubuntu-2604-amd64
|
|
- ubuntu-2604-arm64
|
|
default: none
|
|
|
|
when:
|
|
- event: cron
|
|
cron: weekly-rebuild-missing-${OS}-${ARCH}
|
|
- event: manual
|
|
evaluate: 'weekly_rebuild_missing == "all" || weekly_rebuild_missing == "${OS}-${ARCH}"'
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- OS: alpine-322
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.22
|
|
- OS: alpine-322
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.22
|
|
- OS: alpine-323
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.23
|
|
- OS: alpine-323
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.23
|
|
- OS: alpine-324
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-324
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: redhat-8
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-8
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-9
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-9
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-10
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: redhat-10
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: ubuntu-2204
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2204
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2404
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2404
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2604
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:resolute
|
|
- OS: ubuntu-2604
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:resolute
|
|
|
|
steps:
|
|
- name: 'Rebuild missing binaries'
|
|
image: reg.devxy.io/rpkgs/build-env-${IMG}
|
|
pull: true
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
RED_HAT_DEV_PW:
|
|
from_secret: RED_HAT_DEV_PW
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
PGPASS:
|
|
from_secret: PGPASS
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GITHUB_PAT:
|
|
from_secret: GITHUB_PAT
|
|
FORGEJO_TOKEN:
|
|
from_secret: FORGEJO_TOKEN
|
|
GIT_USER: pat-s
|
|
UVR_CACHE_DIR: /mnt/cache/uvr/cache
|
|
UVR_PACKAGES_DIR: /mnt/cache/uvr/packages
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
R_VERSION: ${R_VERSION}
|
|
CCACHE_DIR: /mnt/cache/ccache
|
|
PLATFORM: ${OS}
|
|
ARCH: ${ARCH}
|
|
NCPUS: 2
|
|
commands:
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- mkdir -p /mnt/cache/uvr/cache /mnt/cache/uvr/packages /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
|
|
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'packageVersion("bincraft")'
|
|
- XVFB=$(command -v xwfb-run 2>/dev/null || command -v xvfb-run); XVFB_ARGS=""; if command -v xwfb-run >/dev/null 2>&1; then dnf install -y -q weston 2>/dev/null; XVFB_ARGS="-c weston"; fi
|
|
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'source("local/fetch-rebuild-packages-from-issue.R")'
|
|
- $XVFB $XVFB_ARGS -- /opt/R/$R_VERSION/bin/R -q -e "sink(stdout(), type = 'message'); options(crayon.enabled = TRUE, Ncpus = $NCPUS, future.globals.onReference = NULL); pkgs <- readLines('/tmp/rebuild_pkgs.txt'); if (length(pkgs) == 0) { cat('Nothing to rebuild\n'); q('no') }; excluded <- jsonlite::fromJSON('local/excluded-packages.json')[['package']]; pkgs <- setdiff(pkgs, excluded); cat(sprintf('Rebuilding %d packages\n', length(pkgs))); n <- length(pkgs); for (i in seq_along(pkgs)) { x <- pkgs[i]; cat(sprintf('[%d/%d] %s\n', i, n, x)); tryCatch(bincraft::build_binary_package(x, tag_limit = 1L, patches = 'local/patches', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'), metadata_db_host = 'r-binaries.devxy.io', metadata_db_name = 'build_metadata', metadata_db_table = 'single_builds', metadata_db_user = 'rpkgs', metadata_db_password = Sys.getenv('PGPASS'), metadata_db_sslmode = 'require', metadata_db_port = 15432, archive = TRUE, upload = TRUE, store_build_metadata = TRUE), error = function(e) cat(sprintf('ERROR building %s - %s\n', x, conditionMessage(e)))) }" 2>&1
|
|
# A rebuild replaces objects in place, so the slot's index still advertises
|
|
# the old MD5 and, for anything that had been served from source, no Built
|
|
# stamp. Re-index here rather than waiting for the next process-updates
|
|
# run, or the rebuilt binaries stay invisible to clients until then.
|
|
# The codename is detected from the image's /etc/os-release.
|
|
- /opt/R/$R_VERSION/bin/R -q -e 'library(bincraft); upload_package_index(s3_endpoint = "https://s3.eu-central-003.backblazeb2.com", s3_region = "eu-central-003", s3_bucket = "devxy-rpkgs-binaries", s3_access_key_id = Sys.getenv("B2_S3_ACCESS_KEY"), s3_secret_access_key = Sys.getenv("B2_S3_SECRET_KEY"))'
|
|
- |
|
|
for RBIN in /opt/R/[0-9]*/bin/R; do
|
|
RMINOR=$(basename "$(dirname "$(dirname "$RBIN")")" | cut -d. -f1-2)
|
|
/opt/R/$R_VERSION/bin/R -q -e "library(bincraft); upload_package_index(r_minor = '$RMINOR', s3_endpoint = 'https://s3.eu-central-003.backblazeb2.com', s3_region = 'eu-central-003', s3_bucket = 'devxy-rpkgs-binaries', s3_access_key_id = Sys.getenv('B2_S3_ACCESS_KEY'), s3_secret_access_key = Sys.getenv('B2_S3_SECRET_KEY'))" || true
|
|
done
|
|
backend_options:
|
|
docker:
|
|
resources:
|
|
requests:
|
|
memory: 5Gi
|
|
cpu: 3000m
|
|
limits:
|
|
memory: 18Gi
|
|
cpu: 3000m
|
|
|
|
- name: Purge CDN cache
|
|
image: reg.devxy.io/docker.io/library/alpine:3.24
|
|
environment:
|
|
OTEL_R_TRACES_EXPORTER: none
|
|
OTEL_R_LOGS_EXPORTER: none
|
|
OTEL_R_METRICS_EXPORTER: none
|
|
BUNNYNET_API_KEY:
|
|
from_secret: BUNNYNET_API_KEY
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
# All hostnames on the zone share this id, so one purge covers
|
|
# cran.devxy.io, cran.allianceswisspass.devxy.io and cran.rpkgs.com.
|
|
BUNNY_PULLZONE: '3857050'
|
|
commands:
|
|
- apk add --no-cache -q bash curl git
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- bash scripts/purge_cdn_zone.sh "$BUNNYNET_API_KEY" "$BUNNY_PULLZONE"
|
|
# A rebuild that died part-way still replaced objects, and those are exactly
|
|
# the ones a stale edge would keep hiding, so purge either way.
|
|
when:
|
|
- status: [success, failure]
|