| 1 | name: Cache janitor |
| 2 | |
| 3 | # The Actions cache held 11,099,951,127 bytes across 2,896 entries, past the |
| 4 | # repo's 10 GiB cap, so GitHub evicted live main entries first. A cache is |
| 5 | # readable only from its own ref and the default branch: once a PR closes or |
| 6 | # a release finishes, its refs/pull/N or refs/tags/vX entries are dead weight. |
| 7 | # This deletes them. Branch caches (main included) are never touched; see |
| 8 | # scripts/release/prune-actions-caches.sh. |
| 9 | on: |
| 10 | # pull_request_target so fork PRs get a token that can delete caches. It |
| 11 | # never checks out or runs PR code: the checkout below is the base branch. |
| 12 | pull_request_target: |
| 13 | types: [closed] |
| 14 | workflow_run: |
| 15 | workflows: [Release] |
| 16 | types: [completed] |
| 17 | schedule: |
| 18 | - cron: '17 4 * * *' |
| 19 | workflow_dispatch: |
| 20 | inputs: |
| 21 | dry_run: |
| 22 | description: List what the sweep would delete without deleting it |
| 23 | required: false |
| 24 | default: true |
| 25 | type: boolean |
| 26 | |
| 27 | permissions: |
| 28 | contents: read |
| 29 | |
| 30 | concurrency: |
| 31 | group: cache-janitor-${{ github.event_name }}-${{ github.event.pull_request.number || github.event.workflow_run.id || 'sweep' }} |
| 32 | cancel-in-progress: false |
| 33 | |
| 34 | jobs: |
| 35 | prune: |
| 36 | name: Prune dead caches |
| 37 | if: github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push') |
| 38 | timeout-minutes: 15 |
| 39 | runs-on: ubuntu-latest |
| 40 | permissions: |
| 41 | contents: read |
| 42 | actions: write |
| 43 | # Read PR state for the sweep. |
| 44 | pull-requests: read |
| 45 | steps: |
| 46 | - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 |
| 47 | with: |
| 48 | # Base-branch script only. Never the PR head. |
| 49 | ref: ${{ github.event.repository.default_branch }} |
| 50 | persist-credentials: false |
| 51 | - name: Prune |
| 52 | shell: bash |
| 53 | env: |
| 54 | GH_TOKEN: ${{ github.token }} |
| 55 | GH_REPO: ${{ github.repository }} |
| 56 | EVENT_NAME: ${{ github.event_name }} |
| 57 | PR_NUMBER: ${{ github.event.pull_request.number }} |
| 58 | RUN_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} |
| 59 | DRY_RUN: ${{ inputs.dry_run }} |
| 60 | run: | |
| 61 | set -euo pipefail |
| 62 | script=scripts/release/prune-actions-caches.sh |
| 63 | case "${EVENT_NAME}" in |
| 64 | pull_request_target) |
| 65 | "${script}" --ref "refs/pull/${PR_NUMBER}/merge" --ref "refs/pull/${PR_NUMBER}/head" |
| 66 | ;; |
| 67 | workflow_run) |
| 68 | # A tag-push Release run reports the tag as head_branch. The |
| 69 | # script refuses anything that is not a refs/tags/<tag> ref. |
| 70 | "${script}" --ref "refs/tags/${RUN_HEAD_BRANCH}" |
| 71 | ;; |
| 72 | workflow_dispatch) |
| 73 | if [[ "${DRY_RUN}" == "true" ]]; then |
| 74 | "${script}" --dry-run --sweep |
| 75 | else |
| 76 | "${script}" --sweep |
| 77 | fi |
| 78 | ;; |
| 79 | *) |
| 80 | "${script}" --sweep |
| 81 | ;; |
| 82 | esac |
| 83 |