From b9bb9014b2841a7bdb73340d0c033de868abb08d Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 00:40:38 +0900 Subject: [PATCH 1/8] fix(ci): align production build resources with upstream --- .github/workflows/adev-production-deploy.yml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 0323d43281..3436bf0e0d 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -10,7 +10,7 @@ env: jobs: adev-build: - runs-on: ubuntu-latest + runs-on: ubuntu-latest-8core steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: @@ -27,10 +27,6 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | - # Limit resources for CI runners (ubuntu-latest: 7GB RAM, 2 CPUs) - build --local_ram_resources=4096 - build --local_cpu_resources=2 - build --jobs=2 build --discard_analysis_cache build --nokeep_state_after_build - run: pnpm install --frozen-lockfile From 8847ada2877274d2e653ee6564265228e1b59cdd Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 00:43:20 +0900 Subject: [PATCH 2/8] fix(ci): retain standard runner for production build --- .github/workflows/adev-production-deploy.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 3436bf0e0d..2276add0de 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -10,7 +10,7 @@ env: jobs: adev-build: - runs-on: ubuntu-latest-8core + runs-on: ubuntu-latest steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: From c77c9258862341a14c7003f899212dbabca7d296 Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 00:47:04 +0900 Subject: [PATCH 3/8] fix(ci): remove outdated Bazel caps from CI and previews --- .github/workflows/adev-preview-build.yml | 4 ---- .github/workflows/ci.yml | 4 ---- 2 files changed, 8 deletions(-) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index 8f8c2a868c..b8c5b033ac 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -35,10 +35,6 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | - # Limit resources for CI runners (ubuntu-latest: 7GB RAM, 2 CPUs) - build --local_ram_resources=4096 - build --local_cpu_resources=2 - build --jobs=2 build --discard_analysis_cache build --nokeep_state_after_build # Allow network access in sandbox for Algolia API calls during SSR prerendering. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9a01783032..13a1ddd98d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -41,10 +41,6 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | - # Limit resources for CI runners (ubuntu-latest: 7GB RAM, 2 CPUs) - build --local_ram_resources=4096 - build --local_cpu_resources=2 - build --jobs=2 build --discard_analysis_cache build --nokeep_state_after_build # Allow network access in sandbox for Algolia API calls during SSR prerendering. From ef3d3ca97f543d90b4cf7da1656f0e0c5ac388a5 Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 01:03:26 +0900 Subject: [PATCH 4/8] fix(ci): diagnose Bazel termination and align production sandbox --- .github/workflows/adev-preview-build.yml | 15 +++++++++++++++ .github/workflows/adev-production-deploy.yml | 4 ++++ .github/workflows/ci.yml | 15 +++++++++++++++ 3 files changed, 34 insertions(+) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index b8c5b033ac..7ca33cda0f 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -40,11 +40,26 @@ jobs: # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile + - name: Record memory state before build + run: | + if [ -r /sys/fs/cgroup/memory.events ]; then + cp /sys/fs/cgroup/memory.events "$RUNNER_TEMP/memory.events.before" + fi - name: Build run: pnpm run build env: _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 + - name: Report memory state after build + if: always() + run: | + for file in "$RUNNER_TEMP/memory.events.before" /sys/fs/cgroup/memory.events /sys/fs/cgroup/memory.max /sys/fs/cgroup/memory.peak /home/runner/.bazel/server/jvm.out; do + if [ -r "$file" ]; then + echo "::group::$file" + tail -n 200 "$file" + echo '::endgroup::' + fi + done - uses: angular/dev-infra/github-actions/previews/pack-and-upload-artifact@0512a5b9381ccff00c278d7b4b6ee38e5c09654d with: workflow-artifact-name: 'adev-preview' diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 2276add0de..07a901f2d5 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -8,6 +8,8 @@ on: env: BAZEL_REPO_CACHE_PATH: '~/.cache/bazel_repo_cache' +permissions: read-all + jobs: adev-build: runs-on: ubuntu-latest @@ -29,6 +31,8 @@ jobs: bazelrc: | build --discard_analysis_cache build --nokeep_state_after_build + # Allow network access in sandbox for Algolia API calls during SSR prerendering. + build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile - name: Build run: pnpm run build diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 13a1ddd98d..f536cc04c9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -46,11 +46,26 @@ jobs: # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install + - name: Record memory state before build + run: | + if [ -r /sys/fs/cgroup/memory.events ]; then + cp /sys/fs/cgroup/memory.events "$RUNNER_TEMP/memory.events.before" + fi - name: Build run: pnpm run build env: _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 + - name: Report memory state after build + if: always() + run: | + for file in "$RUNNER_TEMP/memory.events.before" /sys/fs/cgroup/memory.events /sys/fs/cgroup/memory.max /sys/fs/cgroup/memory.peak /home/runner/.bazel/server/jvm.out; do + if [ -r "$file" ]; then + echo "::group::$file" + tail -n 200 "$file" + echo '::endgroup::' + fi + done # build-windows: # runs-on: windows-latest # steps: From 701b5ca2816b27756cc629f9bc4d2773d4a7f32c Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 01:23:23 +0900 Subject: [PATCH 5/8] fix(ci): record build memory during execution --- .github/workflows/adev-preview-build.yml | 16 ++++++++++++++-- .github/workflows/adev-production-deploy.yml | 2 +- 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index 7ca33cda0f..2a1472d91b 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -24,7 +24,7 @@ jobs: with: submodules: true - name: setup pnpm - uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # 4.1.0 + uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version-file: '.node-version' @@ -46,7 +46,19 @@ jobs: cp /sys/fs/cgroup/memory.events "$RUNNER_TEMP/memory.events.before" fi - name: Build - run: pnpm run build + run: | + if [ -r /sys/fs/cgroup/memory.current ]; then + ( + while true; do + printf 'cgroup memory.current=%s memory.peak=%s ' "$(cat /sys/fs/cgroup/memory.current)" "$(cat /sys/fs/cgroup/memory.peak)" + awk '/^oom / || /^oom_kill / {printf "%s=%s ", $1, $2} END {print ""}' /sys/fs/cgroup/memory.events + sleep 5 + done + ) & + monitor_pid=$! + trap 'kill "$monitor_pid" 2>/dev/null || true' EXIT + fi + pnpm run build env: _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 07a901f2d5..5f9f38df13 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -18,7 +18,7 @@ jobs: with: submodules: true - name: setup pnpm - uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # 4.1.0 + uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version-file: '.node-version' From 58d52c09e4fca404b33ad6c2012fcc447c777b87 Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 01:40:27 +0900 Subject: [PATCH 6/8] fix(ci): reduce Bazel build memory without fixed caps --- .github/workflows/adev-preview-build.yml | 37 ++++++-------------- .github/workflows/adev-production-deploy.yml | 1 + .github/workflows/ci.yml | 16 +-------- 3 files changed, 13 insertions(+), 41 deletions(-) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index 2a1472d91b..c37a2d3a15 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -37,41 +37,26 @@ jobs: bazelrc: | build --discard_analysis_cache build --nokeep_state_after_build + build --notrack_incremental_state # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile - - name: Record memory state before build - run: | - if [ -r /sys/fs/cgroup/memory.events ]; then - cp /sys/fs/cgroup/memory.events "$RUNNER_TEMP/memory.events.before" - fi - name: Build run: | - if [ -r /sys/fs/cgroup/memory.current ]; then - ( - while true; do - printf 'cgroup memory.current=%s memory.peak=%s ' "$(cat /sys/fs/cgroup/memory.current)" "$(cat /sys/fs/cgroup/memory.peak)" - awk '/^oom / || /^oom_kill / {printf "%s=%s ", $1, $2} END {print ""}' /sys/fs/cgroup/memory.events - sleep 5 - done - ) & - monitor_pid=$! - trap 'kill "$monitor_pid" 2>/dev/null || true' EXIT - fi + ( + while true; do + printf 'memory monitor: ' + awk '/^(MemTotal|MemAvailable|SwapTotal|SwapFree):/ {printf "%s=%s%s ", $1, $2, $3}' /proc/meminfo + awk '$1 == "oom_kill" {print "oom_kill=" $2}' /proc/vmstat + sleep 5 + done + ) & + monitor_pid=$! + trap 'kill "$monitor_pid" 2>/dev/null || true' EXIT pnpm run build env: _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 - - name: Report memory state after build - if: always() - run: | - for file in "$RUNNER_TEMP/memory.events.before" /sys/fs/cgroup/memory.events /sys/fs/cgroup/memory.max /sys/fs/cgroup/memory.peak /home/runner/.bazel/server/jvm.out; do - if [ -r "$file" ]; then - echo "::group::$file" - tail -n 200 "$file" - echo '::endgroup::' - fi - done - uses: angular/dev-infra/github-actions/previews/pack-and-upload-artifact@0512a5b9381ccff00c278d7b4b6ee38e5c09654d with: workflow-artifact-name: 'adev-preview' diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 5f9f38df13..fd36a10547 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -31,6 +31,7 @@ jobs: bazelrc: | build --discard_analysis_cache build --nokeep_state_after_build + build --notrack_incremental_state # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f536cc04c9..10bab68490 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -43,29 +43,15 @@ jobs: bazelrc: | build --discard_analysis_cache build --nokeep_state_after_build + build --notrack_incremental_state # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install - - name: Record memory state before build - run: | - if [ -r /sys/fs/cgroup/memory.events ]; then - cp /sys/fs/cgroup/memory.events "$RUNNER_TEMP/memory.events.before" - fi - name: Build run: pnpm run build env: _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 - - name: Report memory state after build - if: always() - run: | - for file in "$RUNNER_TEMP/memory.events.before" /sys/fs/cgroup/memory.events /sys/fs/cgroup/memory.max /sys/fs/cgroup/memory.peak /home/runner/.bazel/server/jvm.out; do - if [ -r "$file" ]; then - echo "::group::$file" - tail -n 200 "$file" - echo '::endgroup::' - fi - done # build-windows: # runs-on: windows-latest # steps: From a6b9cdd6f03ff1472935912f4ab6eb368421977a Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 01:51:25 +0900 Subject: [PATCH 7/8] fix(ci): set Bazel server heap on hosted runners --- .github/workflows/adev-preview-build.yml | 3 ++- .github/workflows/adev-production-deploy.yml | 2 +- .github/workflows/ci.yml | 2 +- 3 files changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index c37a2d3a15..b5623d7846 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -35,6 +35,7 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | + startup --host_jvm_args=-Xmx2g build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state @@ -48,6 +49,7 @@ jobs: printf 'memory monitor: ' awk '/^(MemTotal|MemAvailable|SwapTotal|SwapFree):/ {printf "%s=%s%s ", $1, $2, $3}' /proc/meminfo awk '$1 == "oom_kill" {print "oom_kill=" $2}' /proc/vmstat + ps -eo pid,comm,rss --sort=-rss | sed -n '1,6p' sleep 5 done ) & @@ -55,7 +57,6 @@ jobs: trap 'kill "$monitor_pid" 2>/dev/null || true' EXIT pnpm run build env: - _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 - uses: angular/dev-infra/github-actions/previews/pack-and-upload-artifact@0512a5b9381ccff00c278d7b4b6ee38e5c09654d with: diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index fd36a10547..8f1fc848b5 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -29,6 +29,7 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | + startup --host_jvm_args=-Xmx2g build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state @@ -38,7 +39,6 @@ jobs: - name: Build run: pnpm run build env: - _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 - name: Deploy to Firebase Hosting uses: FirebaseExtended/action-hosting-deploy@0cbcac4740c2bfb00d632f0b863b57713124eb5a # v0.9.0 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 10bab68490..77e26985d9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -41,6 +41,7 @@ jobs: disk-cache: ${{ github.workflow }} repository-cache: true bazelrc: | + startup --host_jvm_args=-Xmx2g build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state @@ -50,7 +51,6 @@ jobs: - name: Build run: pnpm run build env: - _JAVA_OPTIONS: -Xms512m -Xmx2g NODE_OPTIONS: --max-old-space-size=4096 # build-windows: # runs-on: windows-latest From ebcade3ac24cde23e0d7c1876a7df392f8a24eed Mon Sep 17 00:00:00 2001 From: Suguru Inatomi Date: Sat, 10 Oct 2026 02:07:03 +0900 Subject: [PATCH 8/8] fix(ci): limit persistent Bazel workers on hosted runners --- .github/workflows/adev-preview-build.yml | 1 + .github/workflows/adev-production-deploy.yml | 1 + .github/workflows/ci.yml | 1 + 3 files changed, 3 insertions(+) diff --git a/.github/workflows/adev-preview-build.yml b/.github/workflows/adev-preview-build.yml index b5623d7846..1ec008d20d 100644 --- a/.github/workflows/adev-preview-build.yml +++ b/.github/workflows/adev-preview-build.yml @@ -39,6 +39,7 @@ jobs: build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state + build --worker_max_instances=1 # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile diff --git a/.github/workflows/adev-production-deploy.yml b/.github/workflows/adev-production-deploy.yml index 8f1fc848b5..1f3e5d4d11 100644 --- a/.github/workflows/adev-production-deploy.yml +++ b/.github/workflows/adev-production-deploy.yml @@ -33,6 +33,7 @@ jobs: build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state + build --worker_max_instances=1 # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install --frozen-lockfile diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 77e26985d9..e828cc57cc 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -45,6 +45,7 @@ jobs: build --discard_analysis_cache build --nokeep_state_after_build build --notrack_incremental_state + build --worker_max_instances=1 # Allow network access in sandbox for Algolia API calls during SSR prerendering. build --sandbox_default_allow_network - run: pnpm install