Skip to content

ops: nightly prune of docker build cache older than a week - #309

Merged
ralyodio merged 1 commit into
masterfrom
ops/nightly-builder-prune
Sep 25, 2026
Merged

ralyodio merged 1 commit into
masterfrom
ops/nightly-builder-prune

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Build cache is the biggest non-database consumer on a box that builds its own images, and dev2 does: deploy-app.sh builds here so NEXT_PUBLIC_* never leave the box, and the other properties on dev2 build here too.

In one day that cache went 0 → 38 GB, was pruned by hand, and was back to 11.5 GB within hours — twice firing a disk alarm that had nothing to do with the databases.

Why age-filtered, not a bare prune

until=168h discards only cache older than a week, so nothing a current or recent build would reuse is touched and rebuild speed is preserved. A bare prune -f would slow the next build of every property on the box; the problem is accumulation over time, not the working set.

Agreed first, not imposed

This is shared infrastructure and the nichedb session is the heavier build user, so a policy that could slow their rebuilds wasn't mine to decide alone. They asked for it explicitly — "a week of cache is plenty for rebuild speed and I'd rather the alarm never fires on cache again."

Verified on dev2

The exact command reclaims 0 B today, because nothing is yet a week old, and leaves the 11.5 GB working cache intact. That's the behaviour that matters — it proves the filter protects current builds rather than nuking them.

Build cache is the biggest non-database consumer on a box that builds its own
images, and this one does: deploy-app.sh builds here so NEXT_PUBLIC_* never
leave the box, and the other properties on dev2 build here too. In one day
that cache went 0 -> 38 GB, was pruned by hand, and was back to 11.5 GB within
hours — twice firing a disk alarm that had nothing to do with the databases.

until=168h is the conservative part. Only cache older than a week is
discarded, so nothing a current or recent build would reuse is touched and
rebuild speed is preserved. A bare `prune -f` would slow the next build of
every property on the box, which is why this is age-filtered rather than
total.

Agreed with the nichedb session first, since they are the heavier build user
on shared infrastructure and a policy that slows their rebuilds is not mine to
impose.

Verified on dev2: the exact command reclaims 0B today, because nothing is yet
a week old, and leaves the 11.5 GB working cache intact — which is the
behaviour that matters.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

49 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 32 | LOW: 15

Severity Rule Location
HIGH tls-verification-disabled lib/onion.ts:48
HIGH secret-generic-credential lib/sp/platforms/facebook.ts:32
MEDIUM js-unescaped-html-sink app/(app)/dashboard/admin/email-broadcast/EmailBroadcastForm.tsx:125
MEDIUM js-unescaped-html-sink app/(app)/dashboard/projects/[id]/autoblog/articles/[articleId]/page.tsx:214
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:67
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:97
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:104
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:110
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:186
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:190
MEDIUM js-unescaped-html-sink app/c/[project]/[slug]/page.tsx:77
MEDIUM js-unescaped-html-sink app/c/[project]/page.tsx:57
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:228
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:285
MEDIUM js-unescaped-html-sink app/layout.tsx:129
MEDIUM js-open-redirect app/login/form.tsx:39
MEDIUM js-unescaped-html-sink app/r/[token]/page.tsx:176
MEDIUM js-open-redirect app/signup/form.tsx:43
MEDIUM js-open-redirect components/billing/buy-credits-modal.tsx:98
MEDIUM js-unescaped-html-sink components/json-ld.tsx:8
MEDIUM js-unescaped-html-sink components/report/markdown-view.tsx:15
MEDIUM js-unescaped-html-sink lib/careers/page-templates.ts:198
MEDIUM js-dynamic-code-execution lib/crawl-limits.ts:67
MEDIUM redos-nested-quantifier lib/emailMarkdown.ts:41
MEDIUM redos-nested-quantifier lib/emailMarkdown.ts:324
MEDIUM redos-nested-quantifier lib/lx/articleGen.ts:99
MEDIUM redos-nested-quantifier lib/tracker/agent-gate.ts:61
MEDIUM sh-predictable-temp-path ops/selfhost/server/setup-supabase.sh:201
MEDIUM sh-remote-script-execution prober/deploy/provision.sh:30
MEDIUM sql-template-interpolation scripts/detect-slot-themes.ts:31
MEDIUM sql-template-interpolation scripts/purge-constructed-keywords.ts:163
MEDIUM sql-template-interpolation scripts/purge-offniche-keywords.ts:124
MEDIUM js-dynamic-code-execution scripts/test-crawl-limits.mjs:14
MEDIUM js-dynamic-code-execution scripts/test-crawl-limits.mjs:24
LOW secret-generic-credential app/(marketing)/docs/autoblog-webhook/page.tsx:145
LOW secret-generic-credential lib/sp/platforms/linkedin.ts:25
LOW js-dynamic-code-execution tests/careers-page-templates.test.ts:21
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:19
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:69
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:51
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:52
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:20
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:24
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:25
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:26
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:31
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:35
LOW secret-generic-credential tests/contract/posthog-integration.test.ts:13
LOW secret-generic-credential tests/lead-campaign.test.ts:16

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 3020cd1 into master Sep 25, 2026
10 checks passed
@ralyodio
ralyodio deleted the ops/nightly-builder-prune branch September 25, 2026 02:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant