Skip to content

Run Linux CI jobs on Depot runners - #1362

Merged
Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
ci/depot-linux-runners
Oct 9, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
ci/depot-linux-runners

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Merge-queue jobs wait for Linux runners in the org's shared GitHub-hosted pool, behind every PR run. In merge_group run 37971851954, clippy waited 7.7 min to start (18:14:08 → 18:21:50Z), while its Windows and macOS jobs started within seconds. About 200 runs were queued repo-wide at the time.

SocketDev already runs Depot runners in firewall, envrypt (public) and depscan. Depot runners don't count against GitHub's concurrency pool.

Change

  • Every Linux runs-on in ci.yml and the *-compatibility.yml workflows now maps to depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4. These are 4 vCPU, the size of GitHub's public-repo ubuntu-latest.
  • Matrix values stay ubuntu-latest / ubuntu-22.04. Job names, cache keys, artifact names and scripts/ (which read matrix.os) are unchanged; only runs-on is mapped.
  • Kill switch: setting the repo variable DISABLE_DEPOT_RUNNERS=true falls back to GitHub-hosted runners with no commit. It's the same switch depscan uses.
  • Some workflows stay GitHub-hosted:
    • release, publish-*: npm provenance and trusted publishing need GitHub-hosted runners.
    • bench: timings should keep their baseline.
    • merge-queue-*, pin-check, installer-drift, vlt-serve-watchdog: small jobs, some holding write tokens.

Verification

  • This PR's own CI is the access test. If the Depot GitHub app doesn't have access to this repo, the Linux jobs here stay queued, and an org admin needs to add socket-patch to Depot's repository list.
  • actionlint shows the same 164 findings as main, all pre-existing optional-matrix-field warnings.
  • python3 -m unittest discover -s scripts/tests: 297 OK (1 skip).

Conflicts with #1355 are only in runs-on: lines, so whichever lands second needs a mechanical rebase.

🤖 Generated with Claude Code


Note

Low Risk
Workflow-only runner selection with an explicit fallback variable; no product code or secrets handling changes in the diff.

Overview
Routes Linux GitHub Actions jobs in ci.yml and the ecosystem *-compatibility.yml workflows onto Depot runners (depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4) instead of the org’s shared GitHub-hosted pool, so merge-queue and heavy PR CI are less likely to sit behind runner concurrency.

Matrix labels stay ubuntu-latest / ubuntu-22.04; only runs-on is rewritten (macOS/Windows unchanged). ci.yml documents the rationale and adds DISABLE_DEPOT_RUNNERS=true as a repo variable kill switch to fall back to GitHub-hosted Linux runners without a code change.

Reviewed by Cursor Bugbot for commit 6fcaf8e. Configure here.

Merge-queue jobs wait for runners in the org's shared GitHub-hosted Linux
pool, behind every PR run: in one merge_group run `clippy` waited 7.7 min
to start while its Windows and macOS jobs started at once. Depot's runners
don't count against that pool.

Every Linux `runs-on` in ci.yml and the compatibility workflows now maps
to depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4 (4 vCPU, the size of
GitHub's public-repo ubuntu-latest). Matrix values are unchanged, so job
names, cache keys and scripts are unchanged too. Setting the repository
variable DISABLE_DEPOT_RUNNERS=true falls back to GitHub-hosted runners,
the same switch depscan uses.

Release, publish, bench and the merge-queue helper workflows stay
GitHub-hosted: npm provenance needs GitHub-hosted runners, bench timings
should keep their baseline, and the helpers hold write tokens.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Measured: this PR's full CI run on Depot (37974343578) went 18:35:30 → 18:56:52Z, 21.4 min, all 98 checks green. Linux jobs started within seconds. Over the same window, the six merge_group runs on GitHub-hosted Linux (created 18:14) were at 84/194 jobs after 43 min, with ~16 Linux jobs each still waiting for a runner.

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 9, 2026
# Conflicts:
#	.github/workflows/vlt-compatibility.yml
@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
@mikolalysenko
Mikola Lysenko (mikolalysenko) removed this pull request from the merge queue due to a manual request Oct 9, 2026
@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 9, 2026
Applies #1362's runs-on mapping to this branch's ci.yml and compatibility
workflows: Linux jobs map to depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4
unless the repository variable DISABLE_DEPOT_RUNNERS=true. The two PRs
touch the same workflow files, so carrying the mapping here lets them
land back to back without a conflict eviction.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merged via the queue into main with commit ae422fd Oct 9, 2026
459 of 566 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the ci/depot-linux-runners branch October 9, 2026 20:53
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 9, 2026
Main now runs PR, merge_group and push CI in the lean scope (#1375) on
Depot runners (#1362), and already carries this PR's Gradle Windows
change. Every conflicted workflow and test file takes main's version.
Only the pieces that still save minutes on that structure are re-applied.

Kept:
- Merge-queue verdict reuse on push to main. clippy runs
  scripts/ci-reuse-merge-group.py (actions: read), which looks for a
  successful merge_group run of ci.yml for the identical SHA from a
  gh-readonly-queue/main/ branch of this repository. When it finds one, the
  push run still compiles to refresh the main-only caches (cargo test
  --no-run in test, coverage under the llvm-cov env and
  cargo-old-toolchains; the e2e builders and node-addon build as before)
  but skips test steps and the test-only jobs the queue already ran: e2e,
  e2e-extended, e2e-windows, e2e-macos, the cargo-vex and yarn lean jobs and
  docker-base. Jobs the queue never runs (test-release, e2e-full,
  yarn-berry-full, cargo-vex-matrix-full) keep running, so the Linux e2e
  bundle still uploads. API errors, timeouts, bad payloads, missing
  evidence and direct pushes all fall back to the full run. hosted-e2e is
  left running on every push, as main's LEAN SCOPE note requires.
- Coverage summary from the existing LCOV export
  (scripts/ci-lcov-summary.py) instead of a second `cargo llvm-cov
  report --summary-only` pass over the instrumented objects. coverage is
  the critical-path job.
- Runtime-balanced Windows test shards (scripts/ci-test-shard.py with
  scripts/ci-test-durations.json) and the slimmer sbt warm-up for
  coverage-docker's blocking slice (Dockerfile.sbt SBT_WARM_TOOLS). Both
  only affect full-scope runs now.

Dropped:
- e2e row packing (ci-e2e-groups.py, ci-e2e-run.py, grouped e2e jobs,
  e2e-gradle-mid) and their tests: main split e2e into lean `e2e` and
  full-only `e2e-extended` instead.
- The Gradle compat changes (already on main via #1375).
- The ci-ok `!cancelled()` condition and the node-addon OS matrix: they
  don't apply cleanly to main's design and aren't needed for the savings
  above.
- The per-workflow Depot runs-on edits, which main landed in #1362.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-perf CI / merge-queue performance finding (profiler routine)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants