ci: unpack the lint cache off the RAM disk; PRs into develop start no workflow

Static Checks / lint (x64-4 lane): every cache hit since the job moved to
this lane ran out of space. The 2.47 GB archive plus the tree it unpacks to
does not fit the 16Gi RAM-backed workspace, so each hit fell back to a
1.5-4 h cold install (16 of 16 runs cold since #10303). The Restore step
now moves the archive onto the disk-backed package-cache volume (the
parent of YARN_CACHE_FOLDER) before extracting, so only the tree lives in
RAM. Where YARN_CACHE_FOLDER is unset, or the move fails, it extracts in
place exactly as before. Two report-only df lines (after the restore and
at the top of Summarize) record workspace headroom and can never fail a
step.

Triggers: apply the owner decision of 2026-09-21 (already on draft #10254,
same text) directly to develop. A pull request INTO develop no longer
starts static-checks, typos (cspell), snyk-analysis (trigger removed,
restore lines kept in a comment), or build, secrets-analysis and the
external-uptime-monitor self-test (branches-ignore: develop, so PRs into
stage/master still run them). Every push trigger is unchanged, so all of
them still run when code lands on develop. develop has no required status
checks, so no PR is blocked by the missing runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Ruslan Konviser
2026-09-27 15:11:58 +02:00
co-authored by Claude Opus 5.5
parent eac7136562
commit 40826df61b
6 changed files with 58 additions and 11 deletions
+5
View File
@@ -32,6 +32,11 @@ name: Build
on:
pull_request:
# Off by owner decision (2026-09-21): a pull request INTO develop does not start this workflow. The cost
# belonged to every commit on the branch being merged, and the run belongs to the merge - the push
# trigger below runs it when code lands on develop. PRs aimed at other branches still run it.
branches-ignore:
- develop
push:
branches:
- develop
@@ -60,6 +60,12 @@ on:
# This trigger is also the only way to exercise the workflow pre-merge: `workflow_dispatch`
# is not available until the file exists on the default branch.
pull_request:
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts this self-test. Here it
# proves the YAML parses and the probes work before the change is merged, and develop is the branch the
# merge itself is about - so the rehearsal stays for PRs aimed at other branches, and the scheduled and
# manual runs below are untouched.
branches-ignore:
- develop
paths:
- '.github/workflows/external-uptime-monitor.yml'
+5
View File
@@ -5,6 +5,11 @@ on:
branches:
- develop
pull_request:
# Off by owner decision (2026-09-21): a pull request INTO develop does not start this workflow. The cost
# belonged to every commit on the branch being merged, and the run belongs to the merge - the push
# trigger above runs it when code lands on develop. PRs aimed at other branches still run it.
branches-ignore:
- develop
concurrency:
# Same shape as `build.yml`, for the same reason and with the same trade-off written out there:
+7 -4
View File
@@ -4,10 +4,13 @@ on:
push:
branches:
- develop
pull_request:
# The branches below must be a subset of the branches above
branches:
- develop
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts a run: the cost
# belonged to every commit on the branch being merged, and the run belongs to the merge. The push
# trigger above runs the whole workflow when code lands on develop. To restore the PR trigger,
# replace this comment with:
# pull_request:
# branches:
# - develop
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
+28 -4
View File
@@ -18,9 +18,13 @@ on:
push:
branches:
- develop
pull_request:
branches:
- develop
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts a run: the cost
# belonged to every commit on the branch being merged, and the run belongs to the merge. The push
# trigger above runs the whole workflow when code lands on develop. To restore the PR trigger,
# replace this comment with:
# pull_request:
# branches:
# - develop
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
@@ -116,7 +120,24 @@ jobs:
- name: Restore node_modules
shell: bash
run: .github/scripts/restore-node-modules.sh
# On the x64-4 lane the workspace is a 16Gi RAM disk, and the archive restored above (2.47 GB)
# plus the tree it unpacks to (about 15 GB of RAM-disk pages) does not fit: every cache hit on this
# lane ran out of space and fell back to a 2 h install (e.g. runs 36067622802, 36262033210).
# Moving the archive onto the disk-backed package-cache volume first (a different file system, so
# `mv` copies it and then frees the RAM pages) leaves only the tree in RAM. Deleting it after tar
# opens it would not help: an open file keeps its pages until it is closed. Skipped where
# YARN_CACHE_FOLDER is unset (GitHub-hosted runners); a failed move extracts in place, as before.
run: |
dest="${YARN_CACHE_FOLDER:+${YARN_CACHE_FOLDER%/*}}"
if [ -n "$dest" ] && [ -f "$NODE_MODULES_ARCHIVE" ] && mkdir -p "$dest" \
&& mv -fT "$NODE_MODULES_ARCHIVE" "$dest/$NODE_MODULES_ARCHIVE"; then
export NODE_MODULES_ARCHIVE="$dest/$NODE_MODULES_ARCHIVE"
echo "archive moved to $NODE_MODULES_ARCHIVE"
fi
.github/scripts/restore-node-modules.sh
# Workspace headroom after the restore (size, used, free, in bytes), so a growing tree shows up
# here before it runs out again. A report line only: `|| true` keeps it from failing the step.
echo "workspace after restore: $(df -B1 --output=size,used,avail . | tail -1)" || true
# NON-BLOCKING, on purpose. See the header. `--nxBail=false` so one failing project still
# lets every other project report; without it the first failure hides the rest.
@@ -131,6 +152,9 @@ jobs:
if: always()
shell: bash
run: |
# Workspace headroom after ESLint (size, used, free, in bytes), including whatever the lint run
# wrote. A report line only, so it can never fail this step.
echo "workspace after lint: $(df -B1 --output=size,used,avail . | tail -1)" || true
{
echo "## ESLint"
echo
+7 -3
View File
@@ -3,9 +3,13 @@ on:
push:
branches:
- develop
pull_request:
branches:
- develop
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts a run: the cost
# belonged to every commit on the branch being merged, and the run belongs to the merge. The push
# trigger above runs the whole workflow when code lands on develop. To restore the PR trigger,
# replace this comment with:
# pull_request:
# branches:
# - develop
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}