From 2f18567d2494a3dddbec62ab414bd5784d2be3f8 Mon Sep 17 00:00:00 2001 From: Hennadii Stepanov <32963518+hebasto@users.noreply.github.com> Date: Mon, 2 Feb 2026 11:17:18 +0000 Subject: [PATCH] ci: Rotate Docker cache keys every 4 weeks This forces a periodic clean build to ensure we do not rely on stale cache layers indefinitely. --- .github/actions/run-in-docker-action/action.yml | 3 +-- .github/workflows/ci.yml | 12 ++++++++++-- 2 files changed, 11 insertions(+), 4 deletions(-) diff --git a/.github/actions/run-in-docker-action/action.yml b/.github/actions/run-in-docker-action/action.yml index 5d46ca1b..0884d3a4 100644 --- a/.github/actions/run-in-docker-action/action.yml +++ b/.github/actions/run-in-docker-action/action.yml @@ -6,8 +6,7 @@ inputs: required: true scope: description: 'A cached image scope' - required: false - default: ${{ runner.arch }} + required: true command: description: 'A command to run in a container' required: true diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 59d22514..3e74f3d0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -48,6 +48,8 @@ jobs: docker_cache: name: "Build ${{ matrix.arch }} Docker image" runs-on: ${{ matrix.runner }} + outputs: + cache_scope: ${{ steps.cache_timestamp.outputs.period }} strategy: fail-fast: false @@ -59,6 +61,10 @@ jobs: runner: ubuntu-24.04-arm steps: + - name: Get cache validity period + id: cache_timestamp + run: echo "period=$(($(date +%V) / 4))" >> "$GITHUB_OUTPUT" + - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: @@ -70,8 +76,8 @@ jobs: uses: docker/build-push-action@v6 with: file: ./ci/linux-debian.Dockerfile - cache-from: type=gha,scope=${{ runner.arch }} - cache-to: type=gha,scope=${{ runner.arch }},mode=min + cache-from: type=gha,scope=${{ runner.arch }}-${{ steps.cache_timestamp.outputs.period }} + cache-to: type=gha,scope=${{ runner.arch }}-${{ steps.cache_timestamp.outputs.period }},mode=min x86_64-debian: name: "x86_64: Linux (Debian stable)" @@ -117,6 +123,7 @@ jobs: uses: ./.github/actions/run-in-docker-action with: dockerfile: ./ci/linux-debian.Dockerfile + scope: ${{ runner.arch }}-${{ needs.docker_cache.outputs.cache_scope }} command: ./ci/ci.sh - &PRINT_LOGS @@ -636,6 +643,7 @@ jobs: uses: ./.github/actions/run-in-docker-action with: dockerfile: ./ci/linux-debian.Dockerfile + scope: ${{ runner.arch }}-${{ needs.docker_cache.outputs.cache_scope }} command: | g++ -Werror include/*.h clang -Werror -x c++-header include/*.h