Move CI runners off the workstation onto a build server #103
Labels
No labels
amd
avatars
bug
builder
crash
epic
feature
from-viewer
gl-removal
known-limitation
monitoring
parity
perf
platform
rendering
rt
ui
upstream
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
backspace119/Slipstream#103
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Both release jobs (Linux tarball, Windows zip) run on the
cachyoshost runner, which is the dev workstation. Move them to a server.What currently ties CI to this machine
.forgejo/workflows/release.yml:CI_ROOT=/home/bryan/ci/badalchestorm,CI_ROOT_WIN=/home/bryan/ci/badalchestorm-win, andCACHE_SRCpointing at a dev worktree (.claude/worktrees/agent-…) for.venv,.build-variables,.autobuild-installables*. Replace with runner-local cache dirs.glibc_compat.hsymver pins,fix_isa_note.py,make glibc-check(glibc <= 2.38, x86-64-v2). A different server distro changes the compiler and sysroot, so re-verifyglibc-check/isa-checkoutput, or pin a container image that matches.make_vulkan_lib.sh),~/.xwin(MSVC CRT + Windows SDK viaxwin --accept-license splat; the license must be accepted for the server too),~/.cache/wincross/crt(fromfetch_vcredist.py).build-variablesclone.RELEASE_TOKEN(repo read/write). Uploads use the LAN API (192.168.96.20:3000) because Cloudflare caps bodies at 100 MB, so the server must reach Forgejo on the LAN.Plan
builder; jobsruns-on: builderwithcontainer:. Makes the toolchain reproducible and the machine disposable.varsinstead of/home/bryan/...; dropCACHE_SRC.ci-*dry run on the new runner, compareglibc-check/isa-checkoutput and a Wine smoke of the Windows zip against the current builds, then retire thecachyoslabel from the workstation.Sizing notes
The workstation has 48 cores (Linux build ~minutes). A smaller server works, but expect 30–60 min cold builds; persistent build dirs keep tagged releases incremental.
Done: CI now runs on applejack. It's a dedicated LXC (CT 125 on rainbowcrash) in the DMZ at
192.168.96.24: Ubuntu 24.04, 16 cores, 32 GB RAM, 200 GB disk.Setup
192.168.96.1, search domaindmz.internal, apt forced to IPv4 (the DMZ has no IPv6 route). It reaches Forgejo over VLAN 96 only; there are no inbound ports.cc/c++, CMake 4.4 from Kitware. The stock 3.28 can't find thelib-prefixed Windows 3p libraries.clang-cl,lld-link,llvm-{rc,mt,lib,dlltool}linked into/usr/local/bin.~ci/.xwinand~ci/.cache/wincross/crt, so both machines use the identical SDK.forgejo-runnerv13.2.0 as the system serviceforgejo-runner.service(User=ci), registered as applejack with label builder, capacity 1.runs-on: builder. Persistent trees are/srv/ci/slipstreamand/srv/ci/slipstream-win, and each keeps its own venv, build-variables and 3p cache. Nothing refers to a developer machine any more.ci-applejack-2passed both jobs.cachyosrunner registration can be deleted in the Forgejo UI.Privacy fix (the PII leak)
/home/<user>/ci/..., from__FILE__in LL and Boost macros.a5f2ee564fadds-ffile-prefix-map=<repo>=.(GCC and clang-cl) and/pdbaltpath:%_PDB%(Windows)./home/runner/work/3p-*), and the Windows exe references onlyslipstream-bin.pdb.Portability
GLIBC_2.38,GLIBCXX_3.4.32.One follow-up remains: extend
make glibc-checkto fail on GLIBCXX above a chosen floor, so a toolchain change can't raise it silently again.Tested and shipped in v0.12.0-beta.3.