From 1a9c601c2b5f44bf5a07537e038e7708668fb8eb Mon Sep 17 00:00:00 2001 From: Jack O'Sullivan Date: Mon, 24 Aug 2026 22:55:44 +0100 Subject: [PATCH] ci/cache: Collect garbage before pushes Run retention cleanup before uploading build results so inode exhaustion cannot prevent CI from reaching its only garbage-collection step. --- .gitea/workflows/ci.yaml | 4 ++++ ci/push-to-cache.sh | 14 ++++++++++++-- docs/deployment.md | 4 +++- 3 files changed, 19 insertions(+), 3 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index d61dd91..169b9e8 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -37,6 +37,10 @@ jobs: env: HARMONIA_SSH_KEY: ${{ secrets.HARMONIA_SSH_KEY }} run: | + # Make room before pushing so a full cache cannot prevent the GC at + # the end of a successful run from ever being reached. + ci/push-to-cache.sh --gc + nix eval --json --apply "builtins.attrNames" .#ci.x86_64-linux | jq -cr '.[]' | while read job; do echo "::group::Build $job" nix build --no-link .#ci.x86_64-linux."$job" diff --git a/ci/push-to-cache.sh b/ci/push-to-cache.sh index be53f94..30a1fa5 100755 --- a/ci/push-to-cache.sh +++ b/ci/push-to-cache.sh @@ -10,6 +10,11 @@ remote_cmd() { ssh -i "$SSH_KEY" "$SSH_HOST" env HOME=/run/harmonia NIX_REMOTE="$REMOTE_STORE" "$@" } +collect_garbage() { + echo "Collecting garbage..." + remote_cmd nix-collect-garbage --delete-older-than 60d +} + umask_old=$(umask) umask 0066 echo "$HARMONIA_SSH_KEY" | base64 -d > "$SSH_KEY" @@ -17,6 +22,12 @@ umask $umask_old mkdir -p ~/.ssh cp ci/known_hosts ~/.ssh/ + +if [ "${1-}" = "--gc" ]; then + collect_garbage + exit +fi + path="$1" echo "Pushing $path to cache..." @@ -26,6 +37,5 @@ if [ -n "$UPDATE_PROFILE" ]; then echo "Updating profile..." remote_cmd nix-env -p "$REMOTE_STORE"/nix/var/nix/profiles/nixfiles --set "$path" - echo "Collecting garbage..." - remote_cmd nix-collect-garbage --delete-older-than 60d + collect_garbage fi diff --git a/docs/deployment.md b/docs/deployment.md index 719fd16..040dde0 100644 --- a/docs/deployment.md +++ b/docs/deployment.md @@ -222,7 +222,9 @@ On pushes to `master`, this installs Determinate Nix on the runner (via Harmonia substituter as the boxes), runs `nix flake check --no-build`, then builds every attribute of `.#ci.x86_64-linux`: systems as `system-`, homes as `home-` (with `@` changed to `-at-`), packages as `package-`, and the development `shell`. Each result is pushed to the -Harmonia cache with [`ci/push-to-cache.sh`](../ci/push-to-cache.sh). +Harmonia cache with [`ci/push-to-cache.sh`](../ci/push-to-cache.sh). Before the first push, the +workflow collects cache paths older than its retention period so a full cache cannot prevent +collection from being reached. It then builds `.#ciDrv.x86_64-linux`, a `linkFarm` of all CI attributes, and pushes it with `UPDATE_PROFILE=1`. That updates the `nixfiles` profile on the cache box and collects old paths