ci: tighten credential and build-cache hygiene - #346
Conversation
- persist-credentials: false on the pdp-tester checkout, like the permit-opa ones - .dockerignore: exclude nested .git directories from the build context - export only the final image's layers to the GHA cache (mode=min) in tests.yml and release.yml Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🔍 Vulnerabilities of
|
| digest | sha256:29e30d69bb483319cb54f5aef771016653f95aa487263b8fd79b1f88edd3667f |
| vulnerabilities | |
| platform | linux/amd64 |
| size | 140 MB |
| packages | 247 |
📦 Base Image oisupport/staging-amd64:026d26881d2e1ebad06e4f309b0fc5f03c0471c5230d325d7b571be802586ee6
| also known as |
|
| digest | sha256:f282f385cfce21b0a644094330930704424a48d59afe8f08052e0f8e0b7a35c6 |
| vulnerabilities |
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
|
zeevmoney
left a comment
There was a problem hiding this comment.
Approved — no CRITICAL or HIGH issues found.
Non-blocking:
- MEDIUM
.github/workflows/release.yml:73— "Little is lost" leaves outrust_chef(~4 min per build); notes at 86-93, 112-119 and Dockerfile:104-105/165 go stale - MEDIUM
.github/workflows/tests.yml:117— withno-cache-filters: main, themode=minexport is never read back - LOW
.github/workflows/tests.yml:116— comment omits thepdpbinary the final image takes from the Rust stages - LOW
.github/workflows/tests.yml:167— the token-bearing pdp-tester checkout is on a mutable tag
Details are in the inline comments on each line.
…R-16640) Review follow-ups on #346: - mode=min exported only `main`'s layers, which no-cache-filters: main never reads back. Drop cache-to from the image builds and cache rust_chef (no COPY/ADD, ~4 min cold) by itself in scope `rust-chef`, read by the image builds in tests.yml and release.yml. - The arm64 opa_build step no longer reads the default scope. - Fix the comments that described mode=max behavior, and the final-image wording (/opa and /app/pdp). - Pin the pdp-tester checkout to the same checkout SHA as the other token-bearing checkouts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Follow-up to #345: general CI hygiene.
persist-credentials: false, and pinned to the sameactions/checkoutSHA (v6.0.3) as the other token-bearing checkouts. Nothing after the clone uses git, and pdp-tester has no git-sourced dependencies..dockerignore: also exclude nested.gitdirectories (**/.git), not just the root one.rust_chefis cached, in its ownrust-chefscope, by a dedicatedCache the rust_chef stagestep intests.yml.rust_chefreads nothing from the build context: base image,apk add,cargo installandrustuponly. The Dockerfile now says it must stay free ofCOPY/ADD.tests.ymlandrelease.ymlread that scope and export nothing. Every layer of the final image comes frommain, whichno-cache-filters: mainnever serves from cache, so exporting it only filled the cache.opa_buildstep no longer reads the cache.mode=maxbehavior are updated.Cost: about 2 seconds per build, for
opa_build's pre-COPYlayers (the go floor check) no longer coming from the cache.rust_chef(about 4 minutes when cold) stays cached. Therust_planner/rust_builderstages already re-ran on almost every build.Tracked internally as PER-16640.
🤖 Generated with Claude Code