From 5d9783b85e757a68b19da1862e689ba9555e7aa2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Emir=20Beganovi=C4=87?= Date: Thu, 8 Oct 2026 20:57:21 +0200 Subject: [PATCH] Publish pulls the tested builder image instead of building it on every run (#850) A builder droplet starts with no images, so publish.yml built omarchy-pkg-builder from the Dockerfile each time: about 100 s of pacstrap, keyring setup and toolchain install, to run gpg, repo-add, bsdtar and rclone for about 14 s. builder-images.yml already publishes the tested image for the current build inputs to ghcr.io/omacom/omarchy-pkg-builder under bin/builder-image key. Pull that, check its org.omarchy.builder.key label, and tag it as the local name the rest of the step uses. Build as before when no image carries the key, which is what a merge that changes build/ sees until the refresh it triggered has finished. Co-authored-by: Ryan Hughes --- .github/workflows/publish.yml | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index ab69575..0dde694 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -280,8 +280,26 @@ jobs: cat publish-record.json exit 0 fi - docker image inspect omarchy-pkg-builder:latest-x86_64-edge >/dev/null 2>&1 \ - || docker buildx build --load -t omarchy-pkg-builder:latest-x86_64-edge --build-arg MIRROR=edge build + # A builder droplet starts with no images, so building this one here + # cost every publish about 100 s (and 20 s more to start a container + # from it) for the 14 s of signing and upload it is needed for. + # builder-images.yml already publishes the tested image for exactly + # these build inputs under their key; pull that. Build only when no + # image carries the key: a merge that changed build/ publishes + # before the refresh it triggered has finished. + builder=omarchy-pkg-builder:latest-x86_64-edge + if ! docker image inspect "$builder" >/dev/null 2>&1; then + key=$(bin/builder-image key --arch x86_64 --mirror edge) + published="ghcr.io/omacom/omarchy-pkg-builder:$key" + if docker pull --quiet "$published" && + [[ $(docker image inspect "$published" --format '{{index .Config.Labels "org.omarchy.builder.key"}}') == "$key" ]]; then + docker tag "$published" "$builder" + echo "==> Builder image: pulled $published" + else + echo "==> Builder image: none published for $key, building it" + docker buildx build --load -t "$builder" --build-arg MIRROR=edge build + fi + fi # Group the merge's files by the (channel, architecture) slot each # belongs to. A package's files live under build-output/edge/