ci: fetch vault from artifactapi instead of dnf install #99

Merged
benvin merged 2 commits from benvin/ci-vault-install-speedup into master 2026-07-25 09:47:35 +10:00
Owner

Why

CI installs vault by shelling out to dnf install vault -y. That reads
metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads
the 169MB vendored vault RPM from the unkin repo on every plan/apply run
(~39s per job measured in almalinux9-opentofu:20260606).

Change

  • Replace dnf install vault -y with a pinned curl of the upstream vault zip
    from the artifactapi hashicorp-releases remote proxy, extracted with the
    image's python3 (python3 -m zipfile) to /usr/local/bin/vault.
  • Pin the version via a new VAULT_VERSION env var (1.20.0); bump the var to
    upgrade.

Speedup

Measured in git.unkin.net/unkin/almalinux9-opentofu:20260606:

approach time
dnf install vault -y (current) ~39s
dnf --disablerepo='*' --enablerepo=unkin (still pulls 169MB RPM) ~9s
curl zip from artifactapi + python extract (this PR) ~6.6s

~32s saved per plan/apply job. The zip is cached by artifactapi after first
fetch (warm ~3s).

Caveats

  • Assumes the almalinux9-opentofu image ships curl + python3 (both
    present in :20260606).
  • Relies on the existing artifactapi hashicorp-releases generic remote whose
    patterns already allow vault/.*vault_.*_linux_amd64.zip.
## Why CI installs vault by shelling out to `dnf install vault -y`. That reads metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads the 169MB vendored vault RPM from the `unkin` repo on **every** plan/apply run (~39s per job measured in `almalinux9-opentofu:20260606`). ## Change - Replace `dnf install vault -y` with a pinned `curl` of the upstream vault zip from the artifactapi `hashicorp-releases` remote proxy, extracted with the image's `python3` (`python3 -m zipfile`) to `/usr/local/bin/vault`. - Pin the version via a new `VAULT_VERSION` env var (`1.20.0`); bump the var to upgrade. ## Speedup Measured in `git.unkin.net/unkin/almalinux9-opentofu:20260606`: | approach | time | |---|---| | `dnf install vault -y` (current) | ~39s | | `dnf --disablerepo='*' --enablerepo=unkin` (still pulls 169MB RPM) | ~9s | | curl zip from artifactapi + python extract (this PR) | ~6.6s | ~32s saved per plan/apply job. The zip is cached by artifactapi after first fetch (warm ~3s). ## Caveats - Assumes the `almalinux9-opentofu` image ships `curl` + `python3` (both present in `:20260606`). - Relies on the existing artifactapi `hashicorp-releases` generic remote whose patterns already allow `vault/.*vault_.*_linux_amd64.zip`.
unkinben added 1 commit 2026-07-25 00:28:21 +10:00
ci: fetch vault from artifactapi instead of dnf install
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
1e0f1762d3
CI installed vault by shelling out to `dnf install vault -y`, which reads
metadata for every enabled repo (appstream/baseos/crb/epel/ha) and downloads
the 169MB vendored vault RPM from the unkin repo on every pipeline run
(~39s per plan/apply job).

- Replace the dnf install with a pinned curl of the upstream vault zip from
  the artifactapi hashicorp-releases remote proxy, extracted with python3 to
  /usr/local/bin/vault.
- Pin the version via a VAULT_VERSION env var (1.20.0).
unkinben added 1 commit 2026-07-25 00:32:24 +10:00
Escape VAULT_VERSION for woodpecker YAML substitution ($$ -> shell)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
282730e578
benvin merged commit 31424ea6ff into master 2026-07-25 09:47:35 +10:00
benvin deleted branch benvin/ci-vault-install-speedup 2026-07-25 09:47:35 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#99