Skip to content

route-git-token remaps and App minting, sccache write and archive, cargo-install prebuilt releases - #85

Merged
gronke merged 4 commits into
mainfrom
feat/remaps-archive-prebuilt
Sep 26, 2026
Merged

gronke merged 4 commits into
mainfrom
feat/remaps-archive-prebuilt

Conversation

@gronke

@gronke gronke commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Changes

  • sccache: write: "false" reads without storing, through the backend's own read/write mode, and "true" asks for READ_WRITE on GCS, which sccache defaults to read-only; a named archive carries the local disk cache as one GitHub Actions cache entry per job where no backend is configured, keyed by archive, namespace, toolchain, CARGO_* environment and lockfile and saved once per key; an unreachable endpoint is named in a warning.
  • sccache: one backend detection by the rules of the pinned 0.17.0 serves the namespace, the mode and the archive decision; a cache in sccache's configuration file and a multi-level chain count as backends that namespace and write: "false" refuse, and the started server has to report the detected backend as its cache location; the pinned download moves into _lib/install-release.sh.
  • Breaking: sccache loses mode: gha (one cache entry and one network round trip per object, with the Actions runtime token exported into the job), and a leftover SCCACHE_GHA_ENABLED or SCCACHE_GHA_VERSION fails the step, so the next cut is 3.0.0.
  • route-git-token: remaps fetch a dependency pinned at a URL outside the routed namespace from a repository on the host, and app-client-id with app-private-key mint the GitHub App token in place.
  • cargo-install: url with sha256 pins installs a prebuilt release through the same installer, checked against its version before it reaches the cache; host mode skips an exact version that later steps would run and puts the tools on PATH, and docker mode runs nothing from the cache on the runner.
  • Docs: one complete compiler-cache job in the README, and the compile cache for each execution model in docs/self-hosted.md.

@gronke
gronke force-pushed the feat/remaps-archive-prebuilt branch 2 times, most recently from eea5f1a to a20c4fb Compare September 26, 2026 07:54
…he cache without a backend, mode gha goes

One detection by the pinned release's rules serves the namespace, the read/write mode and the archive decision, and the started server has to report the backend it names.
The gha backend, one cache entry and one round trip per object with the runtime token exported into the job, gives way to one GitHub Actions cache entry per archive and namespace, saved once per toolchain, CARGO_* environment and lockfile; the pinned download moves into _lib/install-release.sh.
A remap fetches a dependency pinned outside the routed namespace from a repository on the host, which consumers used to append as GIT_CONFIG_* entries by hand; the app-* inputs replace the separate create-github-app-token step.
… version present

A release archive verified against its sha256 pin and its version replaces the compile in both modes, through the installer sccache uses; host mode checks the binary later steps will run and puts the cache's bin/ on PATH, while docker mode runs nothing from the cache, which sealed steps can write, on the runner.
@gronke
gronke force-pushed the feat/remaps-archive-prebuilt branch from a20c4fb to 4d64f1c Compare September 26, 2026 11:54
@gronke
gronke merged commit 6bd8a1c into main Sep 26, 2026
43 checks passed
@gronke
gronke deleted the feat/remaps-archive-prebuilt branch September 26, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant