10671884d2
The packer-built almalinux9-gobuilder image is being retired. Switch test and pre-commit steps to artifactapi docker-internal/gobuilder 0.1.2-alma9, which trusts the estate CA and ships go-cache-plugin baked in on PATH. - Point test/pre-commit steps at the new image - Drop the curl/sha256sum bootstrap for go-cache-plugin; set GOCACHEPROG directly as a static env var since the binary is always present now - Best-effort S3 cache behaviour is unchanged: verified go build/test still succeed with unreachable/invalid S3 credentials, since the plugin itself degrades to cache misses at runtime
35 lines
1.2 KiB
YAML
35 lines
1.2 KiB
YAML
when:
|
|
- event: pull_request
|
|
|
|
steps:
|
|
- name: pre-commit
|
|
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
|
|
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
|
|
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
|
|
commands:
|
|
- uvx pre-commit run --all-files
|
|
environment:
|
|
# golib lives on Gitea; skip the public proxy/sum db.
|
|
GOPRIVATE: git.unkin.net
|
|
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
|
|
GOCACHE_S3_BUCKET: gocache
|
|
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
|
|
GOCACHE_S3_REGION: us-east-1
|
|
GOCACHE_S3_ENDPOINT_URL: "https://s3.ceph.unkin.net"
|
|
GOCACHE_S3_PATH_STYLE: "true"
|
|
GOCACHE_KEY_PREFIX: ci-artifactapi
|
|
AWS_ACCESS_KEY_ID:
|
|
from_secret: GOCACHE_AWS_ACCESS_KEY_ID
|
|
AWS_SECRET_ACCESS_KEY:
|
|
from_secret: GOCACHE_AWS_SECRET_ACCESS_KEY
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: default
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: 1
|
|
limits:
|
|
memory: 2Gi
|
|
cpu: 2
|