Repository navigation
route-git-token remaps and App minting, sccache write and archive, cargo-install prebuilt releases - #85
Merged
Conversation
gronke
force-pushed
the
feat/remaps-archive-prebuilt
branch
2 times, most recently
from
September 26, 2026 07:54
eea5f1a to
a20c4fb
Compare
…he cache without a backend, mode gha goes One detection by the pinned release's rules serves the namespace, the read/write mode and the archive decision, and the started server has to report the backend it names. The gha backend, one cache entry and one round trip per object with the runtime token exported into the job, gives way to one GitHub Actions cache entry per archive and namespace, saved once per toolchain, CARGO_* environment and lockfile; the pinned download moves into _lib/install-release.sh.
A remap fetches a dependency pinned outside the routed namespace from a repository on the host, which consumers used to append as GIT_CONFIG_* entries by hand; the app-* inputs replace the separate create-github-app-token step.
… version present A release archive verified against its sha256 pin and its version replaces the compile in both modes, through the installer sccache uses; host mode checks the binary later steps will run and puts the cache's bin/ on PATH, while docker mode runs nothing from the cache, which sealed steps can write, on the runner.
gronke
force-pushed
the
feat/remaps-archive-prebuilt
branch
from
September 26, 2026 11:54
a20c4fb to
4d64f1c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
sccache:write: "false"reads without storing, through the backend's own read/write mode, and"true"asks forREAD_WRITEon GCS, which sccache defaults to read-only; a namedarchivecarries the local disk cache as one GitHub Actions cache entry per job where no backend is configured, keyed by archive, namespace, toolchain,CARGO_*environment and lockfile and saved once per key; an unreachable endpoint is named in a warning.sccache: one backend detection by the rules of the pinned 0.17.0 serves the namespace, the mode and the archive decision; a cache in sccache's configuration file and a multi-level chain count as backends thatnamespaceandwrite: "false"refuse, and the started server has to report the detected backend as its cache location; the pinned download moves into_lib/install-release.sh.sccachelosesmode: gha(one cache entry and one network round trip per object, with the Actions runtime token exported into the job), and a leftoverSCCACHE_GHA_ENABLEDorSCCACHE_GHA_VERSIONfails the step, so the next cut is 3.0.0.route-git-token:remapsfetch a dependency pinned at a URL outside the routed namespace from a repository on the host, andapp-client-idwithapp-private-keymint the GitHub App token in place.cargo-install:urlwith sha256 pins installs a prebuilt release through the same installer, checked against its version before it reaches the cache; host mode skips an exact version that later steps would run and puts the tools onPATH, and docker mode runs nothing from the cache on the runner.docs/self-hosted.md.