Problem
Two CI jobs went red this week on network transients while fetching Go bits, each on a change that does not touch the code under test, each green on rerun:
On this strict-base rebase line a red job costs a rerun and, once a merge lands ahead, a rebuilt pull request, so one failed download is paid more than once.
Proposed solution
Make the Go downloads independent of one network round: cache the toolchain and the module cache (actions/setup-go with cache: true keyed on go.sum, or actions/cache over GOMODCACHE/GOCACHE), and run go mod download with a bounded retry before the build and the manifest generation. A fork-infrastructure change (workflow files only), squashed per FORK.md.
Acceptance criteria
build (golang-adk) and manifests-check take their toolchain and modules from the cache on a warm run (visible in the job log).
- A single failed download no longer fails the job: the step retries, or the cache serves it.
- No change to the code under test.
Written by an agent.
Problem
Two CI jobs went red this week on network transients while fetching Go bits, each on a change that does not touch the code under test, each green on rerun:
build (golang-adk)of run https://github.com/giantswarm/kagent-upstream/actions/runs/38010441645 (the CI of feat(session): the Session's actor with its workspace directory #345, 2026-10-10): TLS handshake timeout againstsum.golang.orgduring the go1.27.2 toolchain download.manifests-checkon docs(fork): carried files for the sync's App push and Renovate off #342: the "Generate controller manifests" step failed readinggoogle.golang.org/protobuf@v1.36.7fromproxy.golang.org.On this strict-base rebase line a red job costs a rerun and, once a merge lands ahead, a rebuilt pull request, so one failed download is paid more than once.
Proposed solution
Make the Go downloads independent of one network round: cache the toolchain and the module cache (
actions/setup-gowithcache: truekeyed ongo.sum, oractions/cacheoverGOMODCACHE/GOCACHE), and rungo mod downloadwith a bounded retry before the build and the manifest generation. A fork-infrastructure change (workflow files only), squashed perFORK.md.Acceptance criteria
build (golang-adk)andmanifests-checktake their toolchain and modules from the cache on a warm run (visible in the job log).Written by an agent.