mirror of
https://github.com/yeasy/docker_practice.git
synced 2026-08-10 08:27:25 +00:00
A wedged Chrome/mdPress step held a harness runner for 27 minutes yesterday
(normal run: ~4 min) and ignored `gh run cancel`; it only stopped because that
job happened to carry timeout-minutes: 30. An audit found 66 of the 101 jobs
across the cluster had no timeout at all — the same hang there would have held
a runner for GitHub's 6-hour default.
Values come from measured run history, not guesses. Across ~120 successful
runs the slowest workflow tops out at 10 min (Update Preview Publications),
CI at 6.5, Update Preview PDF at 4.8:
30 min — jobs that run Chrome/mdPress/pandoc (3x the observed max, and the
value harness already used)
15 min — release, publish, deploy, check-link, chaincode-tests
10 min — dependabot auto-merge
Every value has at least 6x headroom over its job's observed maximum, so this
should never turn a slow-but-working run into a failure.
Verified: all 72 workflow files still parse, and all 101 jobs now carry an
integer timeout in range.
113 lines
4.1 KiB
Go
113 lines
4.1 KiB
Go
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- master
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
permissions: {}
|
|
|
|
jobs:
|
|
build:
|
|
permissions:
|
|
contents: read
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install locked Node dependencies
|
|
env:
|
|
PUPPETEER_SKIP_DOWNLOAD: "true"
|
|
run: npm ci
|
|
|
|
- name: Install canonical-example validators
|
|
env:
|
|
KUBECONFORM_VERSION: "0.8.0"
|
|
KUBECONFORM_SHA256: "9bc2bffbf71f261128533edaf912153948b7ff238f9a531ae6d34466ec287883"
|
|
ACTIONLINT_VERSION: "1.7.12"
|
|
ACTIONLINT_SHA256: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8"
|
|
run: |
|
|
mkdir -p "$RUNNER_TEMP/bin"
|
|
kube_archive="$RUNNER_TEMP/kubeconform.tar.gz"
|
|
curl -fsSL --retry 3 \
|
|
"https://github.com/yannh/kubeconform/releases/download/v${KUBECONFORM_VERSION}/kubeconform-linux-amd64.tar.gz" \
|
|
-o "$kube_archive"
|
|
echo "${KUBECONFORM_SHA256} $kube_archive" | sha256sum -c -
|
|
tar xzf "$kube_archive" -C "$RUNNER_TEMP/bin" kubeconform
|
|
|
|
actionlint_archive="$RUNNER_TEMP/actionlint.tar.gz"
|
|
curl -fsSL --retry 3 \
|
|
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" \
|
|
-o "$actionlint_archive"
|
|
echo "${ACTIONLINT_SHA256} $actionlint_archive" | sha256sum -c -
|
|
tar xzf "$actionlint_archive" -C "$RUNNER_TEMP/bin" actionlint
|
|
echo "$RUNNER_TEMP/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Check project rules, metadata, and canonical examples
|
|
run: |
|
|
python3 check_project_rules.py
|
|
npm test
|
|
python3 tools/test_examples.py --require-tools
|
|
|
|
- name: Install Chromium
|
|
uses: browser-actions/setup-chrome@2e1d749697dd1612b833dba4a722266286fbefcd # v2.1.2
|
|
with:
|
|
chrome-version: stable
|
|
|
|
- name: Install CJK fonts and PDF inspection tools
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y fonts-noto-cjk fonts-noto-cjk-extra poppler-utils
|
|
|
|
- name: Install mdPress 0.7.10
|
|
env:
|
|
MDPRESS_VERSION: "0.7.10"
|
|
MDPRESS_SHA256: "17e53e455996940bbbce64c69c43b3fb543f1501e03b74cf0434074efebd2db4"
|
|
run: |
|
|
archive="$RUNNER_TEMP/mdpress_${MDPRESS_VERSION}_linux_amd64.tar.gz"
|
|
curl -fsSL --retry 3 \
|
|
"https://github.com/yeasy/mdPress/releases/download/v${MDPRESS_VERSION}/mdpress_${MDPRESS_VERSION}_linux_amd64.tar.gz" \
|
|
-o "$archive"
|
|
echo "${MDPRESS_SHA256} $archive" | sha256sum -c -
|
|
tar xzf "$archive" -C "$RUNNER_TEMP" mdpress
|
|
mkdir -p "$RUNNER_TEMP/bin"
|
|
install -m 0755 "$RUNNER_TEMP/mdpress" "$RUNNER_TEMP/bin/mdpress"
|
|
echo "$RUNNER_TEMP/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Prepare PDF sources
|
|
run: python3 tools/prepare_pdf_sources.py --book-dir . --out "$RUNNER_TEMP/docker_practice-pdf-src"
|
|
|
|
- name: Build PDF
|
|
working-directory: ${{ runner.temp }}/docker_practice-pdf-src
|
|
run: |
|
|
mkdir -p "$GITHUB_WORKSPACE/dist"
|
|
mdpress build --format pdf --output "$GITHUB_WORKSPACE/dist/docker_practice.pdf"
|
|
|
|
- name: Build site
|
|
run: npm run build
|
|
|
|
- name: Verify build artifacts
|
|
run: |
|
|
title=$(python3 -c 'import json; print(json.load(open("book.json", encoding="utf-8"))["title"])')
|
|
python3 tools/verify_artifacts.py \
|
|
--title "$title" \
|
|
--pdf dist/docker_practice.pdf \
|
|
--site _site \
|
|
--checksums dist/SHA256SUMS
|
|
(cd dist && sha256sum -c SHA256SUMS)
|
|
|
|
- name: Upload verified PDF
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: docker_practice-pdf
|
|
path: |
|
|
dist/docker_practice.pdf
|
|
dist/SHA256SUMS
|
|
if-no-files-found: error
|