summaryrefslogtreecommitdiffstats
path: root/image-builder/crontab.example
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-22 11:10:35 +0200
committerDanilo M. <danix@danix.xyz>2026-09-22 11:10:35 +0200
commit48882edb25df1dabb6197edda8ffb092c32731fd (patch)
treedde7f70fe28595030eaaa187bb155f03c7c02108 /image-builder/crontab.example
parent88b55ee4d2920f1bfbf9fe75bfe3ceec6cb9ba9b (diff)
downloadsbo-dockerbuild-8fb161933119d0dbeafa575f47e09c267e076469.tar.gz
sbo-dockerbuild-8fb161933119d0dbeafa575f47e09c267e076469.zip
release 1.1.2v1.1.2
Also records the host config the chain depends on. The schedule and the storage layout existed only on the VM, so a rebuilt host would have lost both, and the README's inline copy of the schedule had already drifted from what actually runs. crontab.example is byte-identical to the deployed crontab; fstab.example carries the two-disk layout and the dockerd mount-namespace trap that makes moving the registry store non-obvious. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'image-builder/crontab.example')
-rw-r--r--image-builder/crontab.example68
1 files changed, 68 insertions, 0 deletions
diff --git a/image-builder/crontab.example b/image-builder/crontab.example
new file mode 100644
index 0000000..174ace0
--- /dev/null
+++ b/image-builder/crontab.example
@@ -0,0 +1,68 @@
+# sbo-testbuild image chain, root's crontab on the docker host.
+#
+# Copyright (C) 2026 Danilo M. <danix@danix.xyz>
+# GPLv2 only; see LICENSE.
+#
+# Reference copy of what the VM actually runs. Nothing reads this file: install
+# it with `crontab -` (or paste into `crontab -e`) and keep the two in step.
+# It is recorded here because the schedule is as much a part of the build
+# system as the scripts, and it used to live only on the VM, where a rebuilt
+# host would have lost it.
+#
+# Timings are not arbitrary. The chain is gated stage to stage, so each stage
+# must finish before the next starts, and every reclaim must land outside a
+# build window or it strips the working set mid-export.
+#
+# 02:50 reclaim dangling images, then build cache to a 5G floor
+# 03:00 -current bootstrap -> full -> testbuild
+# 05:00 15.0 bootstrap -> full -> testbuild
+# 07:00 reclaim dangling images (catches both variants)
+# 08:00 registry blob GC, Sundays only
+#
+# Repos sync at 01:00/02:00, so the chain starts after that and the images are
+# ready by 09:00.
+
+# ---------------------------------------------------------------------------
+# Pre-build reclaim
+# ---------------------------------------------------------------------------
+# Exporting the -current full image needs roughly its own size (~33G) in
+# transient space on top of what is already resident. An afternoon cache prune
+# with a 20G floor left the volume short by 03:20, and build-full-image.sh
+# failed ten nights running (2026-09-13 to 09-22) with "no space left on
+# device", always in the same export phase. build-sbo-testbuild.sh then saw an
+# unchanged parent and skipped silently, so the -current tags sat six days
+# stale while 15.0 rebuilt fine.
+#
+# Reclaiming just before the build, not hours after it, is what makes the
+# headroom exist when it is needed. Images first (debris from a previous
+# failure), then the cache down to a 5G floor.
+50 2 * * * docker image prune -f >> /var/log/sbo-testbuild.log 2>&1
+55 2 * * * docker builder prune -f --reserved-space 5g >> /var/log/sbo-testbuild.log 2>&1
+
+# ---------------------------------------------------------------------------
+# Build chain
+# ---------------------------------------------------------------------------
+# No --force: each script self-gates (bootstrap=ChangeLog hash, full=base
+# digest, testbuild=full digest + .txz hash), so an unchanged night is a cheap
+# no-op that exits in seconds.
+#
+# -current (moves daily):
+0 3 * * * /opt/sbo-testbuild/image-builder/bootstrap.sh --version current >> /var/log/sbo-testbuild.log 2>&1
+20 3 * * * /opt/sbo-testbuild/image-builder/build-full-image.sh --version current >> /var/log/sbo-testbuild.log 2>&1
+30 4 * * * /opt/sbo-testbuild/image-builder/build-sbo-testbuild.sh --version current >> /var/log/sbo-testbuild.log 2>&1
+# 15.0 (frozen stable; rebuilds only on a real repo update):
+0 5 * * * /opt/sbo-testbuild/image-builder/bootstrap.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1
+20 5 * * * /opt/sbo-testbuild/image-builder/build-full-image.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1
+30 6 * * * /opt/sbo-testbuild/image-builder/build-sbo-testbuild.sh --version 15.0 >> /var/log/sbo-testbuild.log 2>&1
+
+# ---------------------------------------------------------------------------
+# Post-build cleanup
+# ---------------------------------------------------------------------------
+# Since 1.1.2 each build prunes its own superseded image right after pushing,
+# so this is a backstop for anything those missed (a failed run, a manual
+# build). Cheap when there is nothing to do.
+0 7 * * * docker image prune -f >> /var/log/sbo-testbuild.log 2>&1
+# The registry never reclaims on its own: every push adds blobs and nothing
+# removes them, so its store grows until the disk fills. Weekly is enough.
+# registry-gc.sh has its own safety gates; see the script.
+0 8 * * 0 /opt/sbo-testbuild/image-builder/registry-gc.sh >> /var/log/sbo-testbuild.log 2>&1