perf(ci): persist the Go build cache across container builds (#5033)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Amir Raminfar
2026-09-06 07:21:21 -07:00
committed by GitHub
co-authored by Claude Opus 5
parent 0adb8bd45c
commit cbd1084e71
2 changed files with 44 additions and 0 deletions
+7
View File
@@ -6,3 +6,10 @@ dist
.git
e2e
docs
# Restored into the workspace by the Go cache restore/injection steps in
# dev.yml. Without these the build context would carry a few hundred MB of
# module and compiler cache on every build.
go-build-cache
go-mod-cache
scratch
+37
View File
@@ -23,6 +23,7 @@ jobs:
if: ${{ !github.event.repository.fork && !github.event.pull_request.head.repo.fork && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == 'amir20/dozzle') }}
steps:
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Login to DockerHub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
@@ -60,6 +61,42 @@ jobs:
run: |
echo "${{ secrets.TTL_KEY }}" > shared_key.pem
echo "${{ secrets.TTL_CERT }}" > shared_cert.pem
# BuildKit cache mounts live in the builder's local state and cache-to:gha
# does not export them. Every run got a fresh builder, so /go/pkg/mod and
# /root/.cache/go-build started empty and the whole dependency tree was
# recompiled from scratch for both platforms, ~135s of a 3m30s build. Note
# `go mod download` looks CACHED in the log while leaving its mount empty,
# so the modules were re-fetched inside `go build` too.
#
# Both mounts default to id=<target>, so the amd64 and arm64 builds share
# one copy and a single injection reaches both. That is safe for Go (GOCACHE
# keys entries by GOOS/GOARCH, the module cache is just source) and would
# not be for apt/apk, which is why those need id=...-${TARGETARCH}.
- name: Restore Go caches
id: go-cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
go-build-cache
go-mod-cache
# Keyed on go.sum with no run-unique suffix so a hit skips the save.
# Dependencies are the expensive part and they only move when go.sum
# does; recompiling dozzle's own packages each run costs a few seconds.
# A per-SHA key would instead upload the whole cache on every build.
key: go-docker-${{ hashFiles('go.sum') }}
restore-keys: go-docker-
- name: Inject Go caches into the builder
uses: reproducible-containers/buildkit-cache-dance@5422eac04292c961a382e0f584ea0f03ad9da723 # v3.4.0
with:
builder: ${{ steps.buildx.outputs.name }}
cache-map: |
{
"go-build-cache": "/root/.cache/go-build",
"go-mod-cache": "/go/pkg/mod"
}
# On a hit the mounts would be written back unchanged, so skip the
# extraction post-step that tars them back out of the builder.
skip-extraction: ${{ steps.go-cache.outputs.cache-hit == 'true' }}
- name: Build and push
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with: