Fix the build cache of the container image workflows - #421
Merged
Merged
Conversation
The cache was written to <suffix>-<base-tag> but read from <suffix>-<cache-key> (the branch name by default), so it was never reused. Write it per cache key (sanitized branch name), and read it from the base tag, the cache key, and the default branch.
Member
Author
Test results in kitconcept.intranetI tested this branch in kitconcept.intranet on a test branch (
The remaining time is the acceptance tests (~8–10 min). Builds after a dependency change will be partly cached, depending on how the Dockerfiles order their layers. |
ericof
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
container-image-build.ymlandcontainer-image-push.ymlnever reuse their registry build cache:<image-cache-suffix>-<base-tag>, for examplebuildcache-sha-45c6735.<image-cache-suffix>-<cache-key>, wherecache-keydefaults togithub.ref_name, for examplebuildcache-main.Nothing ever writes
buildcache-<branch>, so every build starts cold. The log of a kitconcept.intranet run shows it:As a result,
container-image-pushrebuilds from scratch too, although the docs say it reuses the cache written bycontainer-image-build. In kitconcept.intranet the frontend image takes ~6.5 minutes in both. Also, every commit pushes a newbuildcache-sha-*image to the registry that is never read.Fix
In both workflows, a new step computes the cache references:
<image-cache-suffix>-<cache-key>, with the key normalized to a valid image tag (feature/x→feature-x).<image-cache-suffix>-<base-tag>, so callers that passcache-key: <base-tag>keep working as before;<image-cache-suffix>-<cache-key>, the latest build of the branch, including thecontainer-image-buildjob of the same run, socontainer-image-pushreuses it;<image-cache-suffix>-<default branch>, as a fallback for the first build of a new branch.Missing cache images are only logged by buildx, they don't fail the build. Inputs are passed through
env, not interpolated into the script.The registry gets one cache image per branch instead of one per commit.
The reference docs and a news entry are updated.
container-image-build-push.ymlhas no registry cache, so it's unchanged.Test plan
main,feature/plate-53,cache-key == base-tag, and an empty default branch, produces the expected referencesactionlintandzizmorreport no new findings (the existing ones are unchanged)buildcache-<branch>and the image builds are faster