Stop building the web image's frontend under QEMU - #24
Merged
Merged
Conversation
The Web Build & Push job for 633f641 on main was cancelled at GitHub's six-hour limit. Dockerfile.web built its builder stage once per target platform, so the arm64 leg ran `pnpm install` and `pnpm build` under QEMU. Node crashed there with SIGILL ("qemu: uncaught target signal 4") 40 seconds into the install; the step never exited, and the job sat idle until GitHub killed it. dist/ is static files, identical for every architecture. The builder stage now runs on $BUILDPLATFORM, so it is built once, natively, and only the COPY-only nginx stage is produced per architecture: nothing executes under emulation. Emulated, `pnpm build` alone took 260s against 23s natively. The job also gets a 20-minute timeout, so a hang fails in minutes instead of holding a runner for six hours. release.yml builds each architecture on its own native runner, where $BUILDPLATFORM already equals the target, so release images are built exactly as before. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The
mainpush that merged #23 shows a red ✗: Web Build & Push was cancelled at GitHub's six-hour job limit, so no web image was pushed for 633f641. This PR removes the cause, and caps the job so a hang can't hold a runner that long again.Why it hung
Dockerfile.web's builder stage ran once per target platform, so the arm64 leg ranpnpm installandpnpm buildunder QEMU. In run 34862152349, Node crashed 40 seconds into the arm64 install:The step never exited: the log is silent from 15:32 until the cancellation at 21:31 (UTC). The amd64 leg of the same build had finished in under a minute.
It is not something #23's code does. The crash came mid-download, before any package's own code could run, and the same emulated install succeeded on #22's push.
The fix
$BUILDPLATFORM.dist/is static files, identical for every architecture, so it is now built once, natively, and copied into each architecture's nginx image. The nginx stage only copies files, so nothing executes under emulation. It is faster too: on Clear 127 lint findings and gate lint in CI #22's push, emulatedpnpm buildtook 260s against 23s natively.timeout-minutes: 20on the job. A healthy run takes minutes.[Unreleased], following the 1.0.1 entry for the release workflow's move to native runners.release.ymlbuilds each architecture on its own native runner, where$BUILDPLATFORMalready equals the target, so release images are built exactly as before.make docker-builduses plaindocker build, which gets$BUILDPLATFORMfrom BuildKit.Verification
This job only runs on pushes to
main, so this PR's own CI cannot exercise it. I built the image locally for both platforms —docker buildx build --platform linux/amd64,linux/arm64with adocker-containerbuilder, the kind CI uses, on an arm64 Mac — and exported both images:pnpm buildran exactly once, on the build platform, and both platforms' nginx stages copied its output.index.html, theirdist/trees are identical, and each image's nginx binary is its own architecture (x86-64 and aarch64).The real proof is the next
mainpush, which I will watch.Left as it is
The Set up QEMU step stays. Nothing in the build needs it any more, but only a
mainrun can show the job works without it, so this PR changes one thing at a time.🤖 Generated with Claude Code