Skip to content

Commit b1eef1c

Browse files
committed
fix(ci): retry Nix builds before executing apps once
Signed-off-by: Evan Lezar <elezar@nvidia.com>
1 parent 4f1095d commit b1eef1c

7 files changed

Lines changed: 37 additions & 6 deletions

File tree

‎.agents/skills/watch-github-actions/SKILL.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -128,7 +128,9 @@ gh run list --json databaseId,status,headBranch,url --jq '.[] | {id: .databaseId
128128
`setup-nix` retries development-shell preparation once when `prepare-shell`
129129
is enabled. Inspect both attempts in the job log; `setup-rust` assumes the
130130
shell has already been prepared. Cargo, lint, and test commands are not retried.
131-
Skipped dependent E2E suites indicate blocked coverage.
131+
Direct Nix builds and app dependency preparation also retry once; apps run
132+
once after preparation succeeds. Skipped dependent E2E suites indicate blocked
133+
coverage.
132134

133135
For `Trivy Changes`, inspect the `Resolve PR baseline` step for the base and head
134136
SHAs. PR runs compare the tested merge commit with its

‎.github/actions/check-protobuf-compatibility/action.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,4 +19,7 @@ runs:
1919
env:
2020
CHECK_REF: ${{ inputs.ref }}
2121
run: |
22+
# Retry dependency preparation, then run the compatibility check once.
23+
nix build --no-link --no-write-lock-file .#check-protobuf-compatibility ||
24+
nix build --no-link --no-write-lock-file .#check-protobuf-compatibility
2225
nix run .#check-protobuf-compatibility --no-write-lock-file -- "$CHECK_REF"

‎.github/workflows/build-vm-driver.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,9 @@ jobs:
8282
path: vm-init
8383

8484
- name: Build VM runtime
85-
run: nix build .#vm-runtime
85+
run: |
86+
# HTTP 416 is not retried by Nix; restart the build once on failure.
87+
nix build .#vm-runtime || nix build .#vm-runtime
8688
8789
- name: Assemble compressed VM runtime
8890
run: |

‎.github/workflows/integration-runner.yml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,4 +85,7 @@ jobs:
8585
ENVIRONMENT: ${{ matrix.environment }}
8686
INSTALLER: ${{ matrix.installer }}
8787
TESTSUITE: ${{ matrix.testsuite }}
88-
run: nix run .#tmachine -- test "${ENVIRONMENT}" "${INSTALLER}" "${TESTSUITE}"
88+
run: |
89+
# Retry dependency preparation, then execute the test suite once.
90+
nix build --no-link .#tmachine || nix build --no-link .#tmachine
91+
nix run .#tmachine -- test "${ENVIRONMENT}" "${INSTALLER}" "${TESTSUITE}"

‎.github/workflows/prepare-integration-inputs.yml‎

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -152,13 +152,22 @@ jobs:
152152
docker save --output artifacts/images/openshell-supervisor-tmachine.tar openshell/supervisor:tmachine
153153
154154
- name: Build test archives
155-
run: nix run .#build-artifacts-test-archives
155+
run: |
156+
# Retry dependency preparation, then generate artifacts once.
157+
nix build --no-link .#build-artifacts-test-archives || nix build --no-link .#build-artifacts-test-archives
158+
nix run .#build-artifacts-test-archives
156159
157160
- name: Build test workload images
158-
run: nix run .#build-artifacts-test-images
161+
run: |
162+
# Retry dependency preparation, then generate artifacts once.
163+
nix build --no-link .#build-artifacts-test-images || nix build --no-link .#build-artifacts-test-images
164+
nix run .#build-artifacts-test-images
159165
160166
- name: Package Helm chart
161-
run: nix run .#build-artifacts-helm
167+
run: |
168+
# Retry dependency preparation, then generate artifacts once.
169+
nix build --no-link .#build-artifacts-helm || nix build --no-link .#build-artifacts-helm
170+
nix run .#build-artifacts-helm
162171
163172
- name: Upload integration inputs
164173
id: upload-integration-inputs

‎CI.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -525,3 +525,10 @@ then resume at EOF and receive HTTP 416. A fresh invocation restarts the
525525
operation. Both attempts appear in the job log; a second failure fails the
526526
step. Any preparation failure is retried once, including deterministic errors.
527527
Cargo, lint, and test commands are not retried.
528+
529+
Direct `nix build` commands retry once. Before each `nix run`, CI builds the
530+
app's package with `nix build --no-link`, retrying preparation once, then runs
531+
the app once. The artifact and protobuf-check apps expose matching package
532+
outputs for this preparation. Runtime failures from tests, artifact generation,
533+
and compatibility checks are not retried. Downloads initiated inside an app
534+
are outside this preparation retry.

‎flake.nix‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,11 @@
182182
};
183183

184184
packages = {
185+
# Expose app derivations so CI can prepare them before executing once.
186+
check-protobuf-compatibility = checkProtobufCompatibility;
187+
build-artifacts-test-archives = artifacts.testArchives;
188+
build-artifacts-test-images = artifacts.testImages;
189+
build-artifacts-helm = artifacts.helm;
185190
vm-runtime = vmRuntime;
186191
tmachine = testMachines.package;
187192
tmachine-config = testMachines.config;

0 commit comments

Comments
 (0)