diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-22 11:10:35 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-22 11:10:35 +0200 |
| commit | 48882edb25df1dabb6197edda8ffb092c32731fd (patch) | |
| tree | dde7f70fe28595030eaaa187bb155f03c7c02108 /image-builder/crontab.example | |
| parent | 88b55ee4d2920f1bfbf9fe75bfe3ceec6cb9ba9b (diff) | |
| download | sbo-dockerbuild-1.1.2.tar.gz sbo-dockerbuild-1.1.2.zip | |
release 1.1.2v1.1.2
Also records the host config the chain depends on. The schedule and the
storage layout existed only on the VM, so a rebuilt host would have lost
both, and the README's inline copy of the schedule had already drifted
from what actually runs. crontab.example is byte-identical to the
deployed crontab; fstab.example carries the two-disk layout and the
dockerd mount-namespace trap that makes moving the registry store
non-obvious.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'image-builder/crontab.example')
| -rw-r--r-- | image-builder/crontab.example | 68 |
1 files changed, 68 insertions, 0 deletions
diff --git a/image-builder/crontab.example b/image-builder/crontab.example new file mode 100644 index 0000000..174ace0 --- /dev/null +++ b/image-builder/crontab.example @@ -0,0 +1,68 @@ +# sbo-testbuild image chain, root's crontab on the docker host. +# +# Copyright (C) 2026 Danilo M. <danix@danix.xyz> +# GPLv2 only; see LICENSE. +# +# Reference copy of what the VM actually runs. Nothing reads this file: install +# it with `crontab -` (or paste into `crontab -e`) and keep the two in step. +# It is recorded here because the schedule is as much a part of the build +# system as the scripts, and it used to live only on the VM, where a rebuilt +# host would have lost it. +# +# Timings are not arbitrary. The chain is gated stage to stage, so each stage +# must finish before the next starts, and every reclaim must land outside a +# build window or it strips the working set mid-export. +# +# 02:50 reclaim dangling images, then build cache to a 5G floor +# 03:00 -current bootstrap -> full -> testbuild +# 05:00 15.0 bootstrap -> full -> testbuild +# 07:00 reclaim dangling images (catches both variants) +# 08:00 registry blob GC, Sundays only +# +# Repos sync at 01:00/02:00, so the chain starts after that and the images are +# ready by 09:00. + +# --------------------------------------------------------------------------- +# Pre-build reclaim +# --------------------------------------------------------------------------- +# Exporting the -current full image needs roughly its own size (~33G) in +# transient space on top of what is already resident. An afternoon cache prune +# with a 20G floor left the volume short by 03:20, and build-full-image.sh +# failed ten nights running (2026-09-13 to 09-22) with "no space left on +# device", always in the same export phase. build-sbo-testbuild.sh then saw an +# unchanged parent and skipped silently, so the -current tags sat six days +# stale while 15.0 rebuilt fine. +# +# Reclaiming just before the build, not hours after it, is what makes the +# headroom exist when it is needed. Images first (debris from a previous +# failure), then the cache down to a 5G floor. +50 2 * * * docker image prune -f >> /var/log/sbo-testbuild.log 2>&1 +55 2 * * * docker builder prune -f --reserved-space 5g >> /var/log/sbo-testbuild.log 2>&1 + +# --------------------------------------------------------------------------- +# Build chain +# --------------------------------------------------------------------------- +# No --force: each script self-gates (bootstrap=ChangeLog hash, full=base +# digest, testbuild=full digest + .txz hash), so an unchanged night is a cheap +# no-op that exits in seconds. +# +# -current (moves daily): +0 3 * * * /opt/sbo-testbuild/image-builder/bootstrap.sh --version current >> /var/log/sbo-testbuild.log 2>&1 +20 3 * * * /opt/sbo-testbuild/image-builder/build-full-image.sh --version current >> /var/log/sbo-testbuild.log 2>&1 +30 4 * * * /opt/sbo-testbuild/image-builder/build-sbo-testbuild.sh --version current >> /var/log/sbo-testbuild.log 2>&1 +# 15.0 (frozen stable; rebuilds only on a real repo update): +0 5 * * * /opt/sbo-testbuild/image-builder/bootstrap.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1 +20 5 * * * /opt/sbo-testbuild/image-builder/build-full-image.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1 +30 6 * * * /opt/sbo-testbuild/image-builder/build-sbo-testbuild.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1 + +# --------------------------------------------------------------------------- +# Post-build cleanup +# --------------------------------------------------------------------------- +# Since 1.1.2 each build prunes its own superseded image right after pushing, +# so this is a backstop for anything those missed (a failed run, a manual +# build). Cheap when there is nothing to do. +0 7 * * * docker image prune -f >> /var/log/sbo-testbuild.log 2>&1 +# The registry never reclaims on its own: every push adds blobs and nothing +# removes them, so its store grows until the disk fills. Weekly is enough. +# registry-gc.sh has its own safety gates; see the script. +0 8 * * 0 /opt/sbo-testbuild/image-builder/registry-gc.sh >> /var/log/sbo-testbuild.log 2>&1 |
