Files
Stephan Renatus 7d26c3f6f2 ci: serialize benchmarks workflow to avoid racing writes to benchmarks branch
Quick successive merges to main were spinning up overlapping Benchmarks
workflow runs. Each run publishes results by cloning the benchmarks
branch, running the (long) benchmark suite, and force-pushing merged
results back. Overlapping runs race: gobenchdata's force-push means
the run that finishes last silently clobbers data another run already
published, and the notebook job's plain push fails outright when two
runs finish close together.

Add a concurrency group so runs queue instead of overlapping, so every
push to main gets a data point instead of some being silently dropped
or failing to push.


Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-08-21 14:35:02 +02:00

173 lines
5.5 KiB
YAML

name: Benchmarks
on:
workflow_dispatch: {}
push:
branches: [main]
concurrency:
group: benchmarks
cancel-in-progress: false
permissions:
contents: read
jobs:
# Check what types of changes this PR contains
check-changes:
name: Check what files changed
runs-on: ubuntu-24.04
outputs:
go: ${{ steps.changes.outputs.go }}
bench: ${{ steps.changes.outputs.bench }}
steps:
- name: Check out code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Download OPA
uses: open-policy-agent/setup-opa@b2b258e089860efaadaaf71bf6e3aecb4a3eeff1 # v2.4.0
with:
version: edge
- name: Check for file changes
id: changes
env:
BEFORE_SHA: ${{ github.event.before }}
CURRENT_SHA: ${{ github.event.after }}
run: |
set -e
# Default to running all checks
echo "go=true" >> $GITHUB_OUTPUT
echo "Comparing $BEFORE_SHA with $CURRENT_SHA"
git diff --name-only "$BEFORE_SHA" "$CURRENT_SHA" \
| jq -R '{filename: .}' | jq -s '.' > changed_files.json
if [ ! -s changed_files.json ] || [ "$(cat changed_files.json)" = "[]" ]; then
echo "Warning: No changed files found"
exit 0
fi
echo "Changed files:"
jq -r '.[].filename' changed_files.json
opa eval \
--data build/policy/pr-check/pr_check.rego \
--input changed_files.json \
--format pretty \
'data.policy["pr-check"]' > opa_result.json
go_result=$(jq -r '.changes.go // false' opa_result.json)
bench_result=$(jq -c '.changes.bench // []' opa_result.json)
echo "go=${go_result}" >> $GITHUB_OUTPUT
echo "bench=${bench_result}" >> $GITHUB_OUTPUT
echo "Final outputs:"
echo " go=${go_result}"
echo " bench=${bench_result}"
benchmarks:
permissions:
contents: write # we'll push to the `benchmarks` branch
name: Benchmarks
needs: check-changes
if: ${{ needs.check-changes.outputs.go == 'true' }}
uses: ./.github/workflows/run-benchmarks.yaml
with:
publish: true
publish_branch: benchmarks
regression-check:
permissions:
contents: read
pull-requests: write
name: Check for regressions
runs-on: ubuntu-24.04
needs: [check-changes]
if: ${{ needs.check-changes.outputs.bench != '' && needs.check-changes.outputs.bench != '[]' }}
steps:
- name: Check out code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
- name: Fetch base commit
env:
BEFORE_SHA: ${{ github.event.before }}
run: git fetch --depth=1 origin "$BEFORE_SHA"
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: .go-version
- name: Install tools
run: cd build/tools && go install tool
- name: Run benchmarks and comment on PR
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
COMMIT_SHA: ${{ github.sha }}
BEFORE_SHA: ${{ github.event.before }}
AFTER_SHA: ${{ github.event.after }}
BENCH_PKGS: ${{ needs.check-changes.outputs.bench }}
run: go run ./build/bench-comment
notebook:
permissions:
contents: write # we'll push to the `benchmarks` branch
name: update notebook
runs-on: ubuntu-24.04
needs: [check-changes, benchmarks] # force sequential commits for notebook and benchmark results
if: ${{ needs.check-changes.outputs.go == 'true' }}
steps:
- uses: open-policy-agent/setup-opa@b2b258e089860efaadaaf71bf6e3aecb4a3eeff1 # v2.4.0
- name: Check out code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: benchmarks
persist-credentials: true
- name: Setup Java
uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0
with:
distribution: 'temurin'
java-version: '21'
- name: Setup Clojure
uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
with:
install: true
cache: true
mise_toml: |
[tools]
clojure = "1.12.5.1638"
- name: Cache Clojure dependencies
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.m2/repository
~/.gitlibs
key: clj-${{ hashFiles('clay/deps.edn') }}
restore-keys: clj-
- name: Clean previous output
run: rm -rf docs/*.html
- name: update notebook
run: |
clojure -J-Xss32m -M -m opa-bench.generate
working-directory: clay/
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: commit if changed
working-directory: docs/
run: |
if ! git diff-index --quiet HEAD -- .; then
git config --local user.email "${GITHUB_ACTOR}@users.noreply.github.com"
git config --local user.name "${GITHUB_ACTOR}"
git add -f .
git diff --staged --name-only
git commit -m "benchmarks: update notebook for ${GITHUB_SHA}"
git push origin benchmarks
else
echo "no changes, no commit"
fi