mirror of
https://github.com/apache/superset.git
synced 2026-08-04 04:52:32 +00:00
Adds a per-job/step Gantt chart (rendered as a mermaid diagram in the run summary) to the 15 substantive CI workflows -- the 13 setup-backend consumers plus superset-frontend.yml and docker.yml, the other two heaviest CI paths. Skips trivial bot/label/notification workflows that run in seconds and have nothing worth visualizing. For single-job (or single-heavy-job-in-a-linear-chain) workflows, the step is registered first, before checkout, so its post-processing hook -- which is what actually renders the timeline -- captures the full job including other steps' own cleanup. For workflows with multiple independent parallel jobs, added a dedicated `actions-timeline` terminal job (`needs: [...]`, `if: always()`) instead of duplicating the step into each parallel job: the action fetches every job of the whole run from the GitHub API regardless of which job it executes in, so one copy that runs after every sibling job completes produces one authoritative timeline, while N copies dropped into N parallel jobs would each race to render an incomplete gantt before their siblings finish. `expand-composite-actions: true` is set everywhere so setup-backend's internal steps (Python setup, uv install, apt package caching, dependency install) show up as their own bars rather than one opaque blob -- directly useful given the last two PRs' worth of composite-action changes. `actions: read` is added wherever needed to read job/step timing from the Actions API, either to the workflow's top-level `permissions:` (when the job in question has no job-level override) or directly into the relevant job's own `permissions:` block (when one already exists, since a job-level block replaces rather than merges with the workflow-level one).
227 lines
8.1 KiB
YAML
227 lines
8.1 KiB
YAML
name: Build & publish docker images
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- "master"
|
|
- "[0-9].[0-9]*"
|
|
pull_request:
|
|
branches:
|
|
- "master"
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
changes:
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 10
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
outputs:
|
|
python: ${{ steps.check.outputs.python }}
|
|
frontend: ${{ steps.check.outputs.frontend }}
|
|
docker: ${{ steps.check.outputs.docker }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- name: Check for file changes
|
|
id: check
|
|
uses: ./.github/actions/change-detector/
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
setup_matrix:
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 5
|
|
outputs:
|
|
matrix_config: ${{ steps.set_matrix.outputs.matrix_config }}
|
|
steps:
|
|
- id: set_matrix
|
|
run: |
|
|
MATRIX_CONFIG=$(if [ "${{ github.event_name }}" == "pull_request" ]; then echo '["dev", "lean"]'; else echo '["dev", "lean", "websocket", "dockerize", "py311", "py312"]'; fi)
|
|
echo "matrix_config=${MATRIX_CONFIG}" >> $GITHUB_OUTPUT
|
|
echo $GITHUB_OUTPUT
|
|
|
|
docker-build:
|
|
name: docker-build
|
|
needs: [setup_matrix, changes]
|
|
if: >-
|
|
needs.changes.outputs.python == 'true' ||
|
|
needs.changes.outputs.frontend == 'true' ||
|
|
needs.changes.outputs.docker == 'true'
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 60
|
|
strategy:
|
|
matrix:
|
|
build_preset: ${{fromJson(needs.setup_matrix.outputs.matrix_config)}}
|
|
fail-fast: false
|
|
env:
|
|
DOCKERHUB_USER: ${{ secrets.DOCKERHUB_USER }}
|
|
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
IMAGE_TAG: apache/superset:GHA-${{ matrix.build_preset }}-${{ github.run_id }}
|
|
|
|
steps:
|
|
- name: "Checkout ${{ github.ref }} ( ${{ github.sha }} )"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Free up disk space
|
|
shell: bash
|
|
run: |
|
|
# Reclaim large preinstalled toolchains we don't use. The image
|
|
# build, and especially the docker-compose sanity check (which
|
|
# rebuilds from scratch whenever the registry cache image
|
|
# apache/superset-cache is unavailable), can otherwise exhaust the
|
|
# runner's root disk and fail with "no space left on device".
|
|
echo "Disk before cleanup:"; df -h /
|
|
sudo rm -rf \
|
|
/usr/share/dotnet \
|
|
/usr/local/lib/android \
|
|
/opt/ghc \
|
|
/usr/local/.ghcup \
|
|
/opt/hostedtoolcache/CodeQL \
|
|
/usr/local/share/boost || true
|
|
echo "Disk after cleanup:"; df -h /
|
|
|
|
- name: Setup Docker Environment
|
|
uses: ./.github/actions/setup-docker
|
|
with:
|
|
dockerhub-user: ${{ secrets.DOCKERHUB_USER }}
|
|
dockerhub-token: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
build: "true"
|
|
|
|
- name: Setup supersetbot
|
|
uses: ./.github/actions/setup-supersetbot/
|
|
|
|
- name: Build Docker Image
|
|
shell: bash
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
BUILD_PRESET: ${{ matrix.build_preset }}
|
|
run: |
|
|
# Single platform builds in pull_request context to speed things up
|
|
if [ "$GITHUB_EVENT_NAME" = "push" ]; then
|
|
PLATFORM_ARG="--platform linux/arm64 --platform linux/amd64"
|
|
# can only --load images in single-platform builds
|
|
PUSH_OR_LOAD="--push"
|
|
elif [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then
|
|
PLATFORM_ARG="--platform linux/amd64"
|
|
PUSH_OR_LOAD="--load"
|
|
fi
|
|
|
|
# Retry to absorb transient Docker Hub registry errors (base-image
|
|
# pull timeouts, 504/401 on push, ECONNRESET) that otherwise fail
|
|
# the whole job. buildx reuses the buildkit layer cache from the
|
|
# failed attempt, so a retry mostly re-does just the failed push.
|
|
#
|
|
# supersetbot's "dev"/"lean" presets pin their own --build-arg
|
|
# PY_VER, which lands ahead of --extra-flags on the assembled
|
|
# buildx command line; docker/buildx keeps the last value for a
|
|
# repeated --build-arg key, so appending PY_VER here overrides
|
|
# supersetbot's pin and keeps the build on the Dockerfile's own
|
|
# supported Python version.
|
|
for attempt in 1 2 3; do
|
|
if supersetbot docker \
|
|
$PUSH_OR_LOAD \
|
|
--preset "$BUILD_PRESET" \
|
|
--context "$EVENT" \
|
|
--context-ref "$RELEASE" $FORCE_LATEST \
|
|
--extra-flags "--build-arg PY_VER=3.11.14-slim-trixie --build-arg INCLUDE_CHROMIUM=false --tag $IMAGE_TAG" \
|
|
$PLATFORM_ARG; then
|
|
break
|
|
fi
|
|
if [ "$attempt" -eq 3 ]; then
|
|
echo "::error::supersetbot docker build failed after 3 attempts"
|
|
exit 1
|
|
fi
|
|
echo "::warning::Build attempt ${attempt} failed; retrying in 30s..."
|
|
sleep 30
|
|
done
|
|
|
|
# in the context of push (using multi-platform build), we need to pull the image locally
|
|
- name: Docker pull
|
|
if: github.event_name == 'push'
|
|
run: |
|
|
for i in 1 2 3; do
|
|
docker pull $IMAGE_TAG && break
|
|
[ $i -lt 3 ] && sleep 30
|
|
done
|
|
|
|
- name: Print docker stats
|
|
run: |
|
|
echo "SHA: ${{ github.sha }}"
|
|
echo "IMAGE: $IMAGE_TAG"
|
|
docker images $IMAGE_TAG
|
|
docker history $IMAGE_TAG
|
|
|
|
- name: docker-compose sanity check
|
|
if: matrix.build_preset == 'dev'
|
|
shell: bash
|
|
env:
|
|
BUILD_PRESET: ${{ matrix.build_preset }}
|
|
run: |
|
|
export SUPERSET_BUILD_TARGET=$BUILD_PRESET
|
|
# This should reuse the CACHED image built in the previous steps
|
|
docker compose build superset-init --build-arg DEV_MODE=false --build-arg INCLUDE_CHROMIUM=false
|
|
docker compose up superset-init --exit-code-from superset-init
|
|
|
|
docker-compose-image-tag:
|
|
# Run this job only on pushes to master (not for PRs)
|
|
# goal is to check that building the latest image works, not required for all PR pushes
|
|
needs: changes
|
|
if: github.event_name == 'push' && github.ref == 'refs/heads/master' && needs.changes.outputs.docker == 'true'
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: "Checkout ${{ github.ref }} ( ${{ github.sha }} )"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- name: Free up disk space
|
|
shell: bash
|
|
run: |
|
|
# The sanity check rebuilds the image from scratch whenever the
|
|
# registry cache image apache/superset-cache is unavailable, which
|
|
# can exhaust the runner's root disk ("no space left on device").
|
|
echo "Disk before cleanup:"; df -h /
|
|
sudo rm -rf \
|
|
/usr/share/dotnet \
|
|
/usr/local/lib/android \
|
|
/opt/ghc \
|
|
/usr/local/.ghcup \
|
|
/opt/hostedtoolcache/CodeQL \
|
|
/usr/local/share/boost || true
|
|
echo "Disk after cleanup:"; df -h /
|
|
- name: Setup Docker Environment
|
|
uses: ./.github/actions/setup-docker
|
|
with:
|
|
dockerhub-user: ${{ secrets.DOCKERHUB_USER }}
|
|
dockerhub-token: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
build: "false"
|
|
install-docker-compose: "true"
|
|
- name: docker-compose sanity check
|
|
shell: bash
|
|
run: |
|
|
docker compose -f docker-compose-image-tag.yml up superset-init --exit-code-from superset-init
|
|
|
|
actions-timeline:
|
|
needs: [docker-build, docker-compose-image-tag]
|
|
if: always()
|
|
runs-on: ubuntu-26.04
|
|
permissions:
|
|
actions: read
|
|
steps:
|
|
- uses: Kesin11/actions-timeline@7bf79990b7c09f5dfb570ac30b814ca597bd538e # v3.1.1
|
|
with:
|
|
expand-composite-actions: true
|