chore(runner-image): bake Playwright browsers into the ephemeral runner image #349
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#349
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
bitborg-webis adopting Playwright for end-to-end tests and needs browsers on the CI runner. Therunner image currently carries no browser and no browser shared libraries.
A default
playwright installon Debian 13 x64 downloads roughly 503 MB — Chromium 178.6 MB andChrome Headless Shell 117.4 MB from Google's Chrome-for-Testing bucket, Firefox 108.1 MB and WebKit
96.9 MB from the Playwright CDN, plus ffmpeg — and
install-depsthen apt-installs 100-plus sharedlibrary packages. On an M - Medium VM that is roughly 2.5 to 4 minutes added to every job, on an
image that boots cold every time because
min_idleis 0.Bake them instead, using the pattern
scripts/bake-runner-image.shalready uses forRUNNER_VERSION,TOFU_VERSION,NODE_VERSIONandGITLEAKS_VERSION.Scope
PLAYWRIGHT_VERSIONenv pin toscripts/bake-runner-image.sh, next to the existing pins,with the same "single source of truth for the CI pin" comment.
PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright npx --yes playwright@"${PLAYWRIGHT_VERSION}" install --with-depsand export
PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwrightsystem-wide so every job sees it.roles/runner-controller/files/README-runner-image.md,naming the version pin and where it lives.
--replace.Cost
About 1.5 GB of image growth, which at 0.54 SEK per GB-month of Glance storage is roughly
0.8 SEK/month. The 40 GB boot volume is unchanged. Against that: about 2.5 to 4 minutes saved on
every bitborg-web CI job.
Measure during the bake
Whether a larger image lengthens boot-volume creation. The ephemeral VMs boot from a Cinder volume
created from the image on every job and
min_idleis 0, so if the platform does a full copy ratherthan a Ceph clone this shows up as cold-start latency on every job. If it does, that changes the
recommendation and we should reconsider a slimmer bake (headless shell plus WebKit only, roughly
215 MB).
Version coupling, and why the workflow still calls
playwright installPlaywright refuses to run against a browser revision that does not match its package version, so
the baked image is coupled to the
@playwright/testpin in bitborg-web. The workflow thereforekeeps an idempotent
playwright install --with-depsstep: when the revisions match it prints"browsers are already installed" and downloads nothing, and when a Renovate bump outruns the image
it self-heals slowly rather than failing. Add
playwrightto a Renovate group whose descriptionsays to re-bake.
Follow-on
This unblocks the standing TODO in
opentofu/ephemeral-runners.tofuto tighten runner egress from"443 to 0.0.0.0/0" toward Forgejo and the registry only — impossible while every job must reach two
third-party CDNs. It also removes a per-pull-request runtime dependency on two US-operated CDNs,
in the same spirit as pointing
DEFAULT_ACTIONS_URLat data.forgejo.org.Acceptance
/opt/ms-playwrightandPLAYWRIGHT_BROWSERS_PATHset for job shellspnpm exec playwright install --with-depsin a real job completes in about a second