Add measured Depot base-image caching - #16
Conversation
|
Warning Review limit reached
Next review available in: 56 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe staging workflow selects a pinned upstream or validated Depot pull-through Actions Runner image. The Dockerfile consumes the selected image through a build argument. Documentation defines the contract, operations, benchmarking, and audit rules. Tests validate workflow behavior. ChangesRunner base image selection
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant GitHub Actions
participant Depot Registry
participant Docker Build
GitHub Actions->>GitHub Actions: Validate trusted workflow and registry settings
GitHub Actions->>Depot Registry: Authenticate with OIDC pull token
Depot Registry-->>GitHub Actions: Enable pull-through image access
GitHub Actions->>Docker Build: Pass ACTIONS_RUNNER_BASE_IMAGE
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
tests/workflow-matrix.test.sh (1)
329-335: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winAssert the exact authentication contract.
The current checks pass if the login condition changes to
false. They also pass if a future edit sends the pull token on the command line. Require the exactcache_selected == 'true'condition and--password-stdinlogin form.Proposed test assertions
grep -Fq "depot pull-token --project \"\$DEPOT_PROJECT_ID\"" \ "$base_image_login_step" -grep -Fq 'steps.base_image.outputs.cache_selected' "$base_image_login_step" +grep -Fq "if: steps.base_image.outputs.cache_selected == 'true'" \ + "$base_image_login_step" +grep -Fq \ + 'docker login "$DEPOT_REGISTRY_HOST" --username x-token --password-stdin' \ + "$base_image_login_step"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@tests/workflow-matrix.test.sh` around lines 329 - 335, Strengthen the assertions in workflow-matrix.test.sh for the base_image_login_step: require the exact cache_selected == 'true' condition and the depot pull-token command, and assert that authentication uses the --password-stdin login form. Keep rejecting secrets, DEPOT_TOKEN, and REGISTRY_PULL_TOKEN references, while ensuring command-line token passing cannot satisfy the test.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@tests/workflow-matrix.test.sh`:
- Around line 329-335: Strengthen the assertions in workflow-matrix.test.sh for
the base_image_login_step: require the exact cache_selected == 'true' condition
and the depot pull-token command, and assert that authentication uses the
--password-stdin login form. Keep rejecting secrets, DEPOT_TOKEN, and
REGISTRY_PULL_TOKEN references, while ensuring command-line token passing cannot
satisfy the test.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 5307684f-d56a-4f64-9671-a0c5661e28f2
📒 Files selected for processing (7)
.github/workflows/stage-image-family.ymlDockerfileREADME.mddocs/AUDIT.mddocs/CI_BENCHMARKS.mddocs/OPERATIONS.mdtests/workflow-matrix.test.sh
What changed
Why
The Actions runner base is the only public container base in this repository. Pull-through caching may reduce cold pulls and registry throttling, but must remain disabled until fresh-runner measurements show at least 20% and 10 seconds of median improvement with identical digests.
Validation
The optional local Docker frontend check could not connect to the local Docker endpoint (
failed to build: EOF).Summary by CodeRabbit
New Features
Documentation
Tests