Skip to content

Give each Rust CI job its own cache and save caches only from main - #1259

Open
dhruv8sh wants to merge 2 commits into
mainfrom
chore/ci-per-job-rust-cache
Open

dhruv8sh wants to merge 2 commits into
mainfrom
chore/ci-per-job-rust-cache

Conversation

@dhruv8sh

@dhruv8sh dhruv8sh commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Give each Rust CI job its own rust-cache key. Today every job shares cargo-${{ runner.os }}, and a job with an exact key match never saves. The first job to save (cloudflare or parity) owns the cache, and the axum, fastly, spin and clippy jobs rebuild 150–1,000 dependency crates on every run even though they report a full hit.
  • Save Rust caches only from main. PR-scoped caches can't be reused by other PRs and were pushing the repo past its 10 GB limit (12.6 GB, ~10.8 GB of it from PRs), evicting main's caches.
  • Remove the runner image's preinstalled stable toolchain before setup. rust-cache hashes every installed toolchain into its key, so each runner-image update was changing the key.

Changes

File Change
.github/workflows/test.yml Per-job keys (cargo-fastly, cargo-axum, cargo-cloudflare, cargo-spin, cargo-parity; cargo-cli unchanged), cache-save-if on main only, and a step that uninstalls the image's stable toolchain
.github/workflows/format.yml Same for the clippy job (cargo-clippy)
.github/actions/setup-integration-test-env/action.yml Restores cargo-axum, which builds the same axum debug and Fastly release WASM artifacts. Same save and toolchain changes.

Closes

Closes #1258

Test plan

  • cargo test-fastly && cargo test-axum
  • cargo clippy-fastly && cargo clippy-axum
  • cargo fmt --all -- --check
  • JS tests: cd crates/trusted-server-js/lib && npx vitest run (ran with NODE_OPTIONS=--no-experimental-webstorage because local Node is 26, not the pinned 24.12.0)
  • JS format: cd crates/trusted-server-js/lib && npm run format
  • Docs format: cd docs && npm run format
  • WASM build: cargo build --package trusted-server-adapter-fastly --release --target wasm32-wasip1
  • Manual testing via fastly compute serve
  • Other: local act benchmark of main's test.yml vs this branch, running the cloudflare, fastly and axum jobs sequentially (one cold main-push run, then two warm PR runs per variant)
Job (warm PR run) Deps rebuilt, before → after Job time, before → after
axum 749 → 0 242 s → 145 s (−40%)
fastly cargo test 664 → 0 645 s → 585 s (−9%)
cloudflare 0 → 0 73 s → 73 s

What the benchmark confirmed:

  • PR runs skip saving.
  • main runs save one cache per job.
  • The key no longer includes the image's stable toolchain.

Not covered locally:

  • The axum job stopped at the CLI browser tests because the image has no Chrome, so its release-WASM step (~1,000 dependency rebuilds in CI) wasn't measured.
  • Not run: the spin, clippy, parity and CLI jobs, macOS, and the integration-test workflow.

After merge, check these:

  • gh cache list shows Rust caches only for refs/heads/main, under 10 GB.
  • PR runs' axum and fastly jobs show ~0 dependency Compiling lines.

The first PR runs after merge build cold until main has saved the new keys.

Checklist

  • Changes follow AGENTS.md conventions
  • No unwrap() in production code — use expect("should ...")
  • Uses tracing macros (not println!)
  • New code has tests (CI configuration only. Verified with the act benchmark above.)
  • No secrets or credentials committed

All Rust jobs shared one rust-cache key, so the fastest job saved it and every slower job restored a cache built for a different target, logged "Cache up-to-date", and rebuilt its dependencies on every run.

Use a per-job shared key, restrict saves to main so PR-scoped caches stop evicting main's, and uninstall the runner image's preinstalled stable toolchain so image rollouts no longer rotate the cache key. Integration tests restore the axum job's cache, which builds the same artifacts.

Closes #1258

Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
@dhruv8sh dhruv8sh self-assigned this Oct 7, 2026

@ChristianPavilonis ChristianPavilonis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review summary

Reviewed b9235ca43d6e7dd1cd484eb5a69daeb3eae671db against 7a0ecb4cbfa39af3d83f7e1ed2733d7eabdc4cb1. No actionable issues introduced by this PR were found.

Inspected all three changed files, every affected job, all four integration-action consumers, and the resolved setup/cache action implementations.

Safety proof

  • CI logs show all 12 affected job executions removing stable, installing pinned Rust 1.95.0, and completing successfully. Coverage includes native Linux/macOS, both WASM targets, Clippy, parity, and integration tests.
  • Logs from runs 37701852034, 37701851968, and 37701851955 confirm separate OS/job cache namespaces, matching Axum/integration keys, and save-if: false forwarded in every affected PR execution. No Rust cache saves occurred.

Validation and remaining uncertainty

  • All 22 PR checks pass. The CI merge tree is identical to the reviewed head tree.
  • Diff whitespace checks and actionlint without ShellCheck pass. Actionlint with ShellCheck reports 12 unchanged SC2086 diagnostics, confirmed against the base revision. All new removal scripts pass ShellCheck.
  • In-memory assertions pass for all setup definitions, key uniqueness, intentional integration sharing, Rust pins, shell syntax, the absent-rustup branch, and CI log observations.
  • Existing reviews, inline comments, issue comments, and review threads were empty.
  • Main-branch cache saving, subsequent warm restores, and the claimed storage/performance improvements remain unverified on GitHub after merge.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Give each Rust CI job its own cache and save caches only from main

3 participants