zozo123 commented on PR #74173:
URL: https://github.com/apache/airflow/pull/74173#issuecomment-6087766006

   @shahar1 ready for another look. Your round-2 points are addressed at 
`2fe6e1219d`:
   
   - The dependency layer is split out into draft #74466. It drops the `|| 
echo` and the Bash-semantics tests.
   - The artifact is now `ci-image-snapshot-v1-…`, and a test checks that 
upload and restore use the same name.
   - New: the snapshot is kept for 1 day instead of 2. Only its own run reads 
it, and a re-run after it expires restores the 2-day stash instead. That halves 
the storage the snapshot adds.
   
   @potiuk @jscheffl, shahar1 asked for your call on the CI budget before this 
merges. These figures are per built CI image (Python/platform) per PR run, from 
run [37804108397](https://github.com/apache/airflow/actions/runs/37804108397):
   
   - **Cost:** about 115 s of extra serial time in the builder, and one more 
2.53 GB artifact (now kept 1 day) next to the existing 2.36 GB stash.
   - **Saving:** each of the 79 consumer jobs unpacks the snapshot in 38 s 
instead of running `docker image load` for 103–109 s. That is about 85–90 
runner-minutes per AMD run. The download is the same size either way, and its 
time varies from run to run (45–211 s medians), so turnaround is unchanged.
   
   Is that tradeoff acceptable?
   
   CodeQL also reports one `actions/cache-poisoning/poisonable-step` alert on 
the snapshot step. It is a false positive: the step only runs on `pull_request` 
and writes no cache. The analysis and a reproduction are 
[here](https://github.com/apache/airflow/pull/74173#discussion_r4225221915). 
Someone with Security-tab access would need to dismiss it.
   
   ---
   Drafted-by: Claude Code (Opus 5.5) (no human review before posting)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to