ci(verdaccio): route the Cypress and Currents e2e installs through the internal npm cache

These were the last two dependency-installing workflows still resolving packages
straight from the public npm registry. Both are covered now, using the same
placement discipline as build.yml.

The step goes AFTER the yarn cache restore and BEFORE `yarn bootstrap`, because
the action rewrites yarn.lock's resolved URLs (the load-bearing half - yarn v1
fetches the URL recorded in the lockfile and ignores the registry setting) while
hashFiles() in a cache key evaluates at step runtime. Configuring the registry
first would move the key and bifurcate the cache namespace by VIP reachability.

No save-key pinning was required. build.yml needs it because it uses the split
actions/cache/restore + actions/cache/save pair, whose save step re-derives
hashFiles() at save time. Both files here use the COMBINED actions/cache, which
records its primary key with core.saveState during the restore - before the
rewrite - and whose post-job save reads that recorded key back, so the entry is
written under exactly the key the next run's restore computes.

Scope, and what was deliberately left alone:

- test_currents.yml `e2e-tests` and test_cypress.yml `e2e-tests` get the step.
  Both resolve to the self-hosted ARC pool via vars.RUNNER_LINUX_X64_8
  (= ever-k8s-linux-x64-8), the only place the VIP answers. The action probes
  the VIP and falls back to the public registry, so the `|| 'ubuntu-latest'`
  fallback runner degrades to today's behaviour rather than hanging on a LAN IP.
- test_currents.yml `prepare` installs nothing - it only emits a build UUID.
- test_cypress.yml `e2e-tests-setup` overrides its install with
  `install-command: node -p 'os.cpus()'`, so it resolves no packages from any
  npm registry. Adding the step there would buy nothing and would rewrite
  yarn.lock ahead of cypress-io/github-action's own lockfile-keyed cache,
  splitting it in two.

`expect-vip` is derived from the runner variable rather than the
contains(matrix.os, ...) idiom the app workflows use: these jobs' only matrix
key is `containers`, so that expression would collapse to false and silently
disable the in-network VIP retry and its warning.

Additive only - no workflow, job or step was removed or reordered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Ruslan Konviser
2026-08-22 21:50:01 +02:00
co-authored by Claude Opus 5
parent 046f69c685
commit a6ab2fc9e3
2 changed files with 59 additions and 0 deletions
+27
View File
@@ -87,6 +87,33 @@ jobs:
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-yarn-
# Route the installs below through the internal Verdaccio cache. This job resolves to the
# self-hosted ARC pool (vars.RUNNER_LINUX_X64_8), which is the only place the VIP is
# reachable; the action PROBES it and falls back to the public npm registry otherwise, so the
# `|| 'ubuntu-latest'` fallback runner degrades to today's behaviour instead of hanging.
#
# Placed AFTER the yarn cache restore on purpose: the action rewrites yarn.lock's resolved
# URLs (that rewrite is the load-bearing half — yarn v1 fetches the URL recorded in the
# lockfile and ignores the registry setting), and hashFiles() in a cache key evaluates at step
# runtime. Configuring the registry before the restore would move the key and bifurcate the
# cache namespace by VIP reachability. Same ordering as build.yml.
#
# No save-key pinning is needed here, unlike build.yml: that file uses a split
# cache/restore + cache/save pair, whose save step re-derives hashFiles() at save time. This
# is the COMBINED actions/cache action — it captures its primary key during the restore, i.e.
# before the rewrite, and its post-job save reuses that captured key, so the entry is written
# under exactly the key the next run's restore computes.
- name: Configure Registry
uses: ever-co/ever-gauzy/.github/actions/configure-registry@aa4ee19926fabcf820aa1294385a76aec6bdb548
with:
verdaccio-registry: ${{ vars.VERDACCIO_REGISTRY }}
verdaccio-token: ${{ secrets.VERDACCIO_TOKEN }}
force-public: ${{ vars.VERDACCIO_FORCE_PUBLIC }}
# NOT contains(matrix.os, ...) as the app workflows use: this job's only matrix key is
# `containers`, so that expression collapses to false and would silently disable the
# in-network VIP retry and its warning. Derive it from the runner variable this job uses.
expect-vip: ${{ vars.RUNNER_LINUX_X64_8 != '' }}
# - name: Increase file limit
# run: echo fs.inotify.max_user_watches=524288 | sudo tee -a /etc/sysctl.conf && sudo sysctl -p
+32
View File
@@ -83,6 +83,38 @@ jobs:
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-yarn-
# Route the installs below through the internal Verdaccio cache. This job resolves to the
# self-hosted ARC pool (vars.RUNNER_LINUX_X64_8), which is the only place the VIP is
# reachable; the action PROBES it and falls back to the public npm registry otherwise, so the
# `|| 'ubuntu-latest'` fallback runner degrades to today's behaviour instead of hanging.
#
# Placed AFTER the yarn cache restore on purpose: the action rewrites yarn.lock's resolved
# URLs (that rewrite is the load-bearing half — yarn v1 fetches the URL recorded in the
# lockfile and ignores the registry setting), and hashFiles() in a cache key evaluates at step
# runtime. Configuring the registry before the restore would move the key and bifurcate the
# cache namespace by VIP reachability. Same ordering as build.yml.
#
# No save-key pinning is needed here, unlike build.yml: that file uses a split
# cache/restore + cache/save pair, whose save step re-derives hashFiles() at save time. This
# is the COMBINED actions/cache action — it captures its primary key during the restore, i.e.
# before the rewrite, and its post-job save reuses that captured key, so the entry is written
# under exactly the key the next run's restore computes.
#
# Deliberately NOT added to the `e2e-tests-setup` job above: its cypress-io/github-action step
# overrides the install with `install-command: node -p 'os.cpus()'`, so that job resolves no
# packages from any npm registry. Adding the step there would buy nothing and would rewrite
# yarn.lock ahead of that action's own internal lockfile-keyed cache, splitting it in two.
- name: Configure Registry
uses: ever-co/ever-gauzy/.github/actions/configure-registry@aa4ee19926fabcf820aa1294385a76aec6bdb548
with:
verdaccio-registry: ${{ vars.VERDACCIO_REGISTRY }}
verdaccio-token: ${{ secrets.VERDACCIO_TOKEN }}
force-public: ${{ vars.VERDACCIO_FORCE_PUBLIC }}
# NOT contains(matrix.os, ...) as the app workflows use: this job's only matrix key is
# `containers`, so that expression collapses to false and would silently disable the
# in-network VIP retry and its warning. Derive it from the runner variable this job uses.
expect-vip: ${{ vars.RUNNER_LINUX_X64_8 != '' }}
# - name: Increase file limit
# run: echo fs.inotify.max_user_watches=524288 | sudo tee -a /etc/sysctl.conf && sudo sysctl -p