Some checks failed
wasm-build.yml / build: host networking (no Docker bridge/NAT on the build host) (push) Failing after 0s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
58 lines
2.7 KiB
YAML
58 lines
2.7 KiB
YAML
services:
|
|
kicad-wasm-builder:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/Dockerfile
|
|
# Build host runs dockerd with bridge:none + iptables:false (PIA killswitch,
|
|
# no Docker NAT). Image-build RUN steps (emsdk download) use the host netns.
|
|
network: host
|
|
args:
|
|
# Single source of truth: scripts/common/versions.sh, exported into the env by the scripts
|
|
# that drive compose (docker/build.sh, docker/shell.sh). No default -> the Dockerfile fails
|
|
# fast if it's unset, so the image can't be built against the wrong toolchain.
|
|
EMSCRIPTEN_VERSION: ${EMSCRIPTEN_VERSION:?source scripts/common/versions.sh before docker compose}
|
|
# Container name is auto-generated with project prefix (set in build.sh)
|
|
|
|
# The compile container shares the host network namespace so it inherits the
|
|
# PIA killswitch directly — the build host's dockerd has no bridge/NAT.
|
|
network_mode: host
|
|
|
|
# Resource limits. Defaults are sized for a dev Mac (Docker Desktop VM).
|
|
# CI overrides via env: the 32-core Hetzner runner sets KICAD_DOCKER_CPUS=$(nproc)
|
|
# and KICAD_DOCKER_MEM=110G — with the 10-CPU default, run 27226030304 compiled
|
|
# everything on 10 of 32 cores while passing -j 32 (3x oversubscribed).
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
cpus: '${KICAD_DOCKER_CPUS:-10}'
|
|
memory: ${KICAD_DOCKER_MEM:-32G}
|
|
|
|
# Emscripten cache on the PERSISTENT build volume: /emsdk lives in the
|
|
# container layer, so every container recreation (any image-context edit
|
|
# rebuilds the image) wiped the ports/sysroot cache and forced re-downloads
|
|
# through a flaky in-container fetcher. On the volume it survives, and the
|
|
# host can pre-seed port tarballs into emcache/ports/.
|
|
environment:
|
|
EM_CACHE: /workspace/build-wasm/emcache
|
|
|
|
volumes:
|
|
# Host source mounted read-only at staging location
|
|
# (rsync'd to /workspace on container start to fix macOS timestamp issues)
|
|
- ..:/workspace-host:ro
|
|
# Synced source in Docker volume (consistent timestamps)
|
|
- workspace-src:/workspace
|
|
# Named volume for build cache (faster than bind mount on macOS)
|
|
- kicad-build-cache:/workspace/build-wasm
|
|
# Output directory for easy access to final WASM files
|
|
- ../output:/workspace/output
|
|
|
|
# Keep the container alive so build.sh can `exec` its stages into it.
|
|
# build.sh STOPS it when the build exits (idle builders keep the Docker
|
|
# Desktop VM ballooned — 32G cap per per-worktree compose project); set
|
|
# KICAD_KEEP_CONTAINER=1 to keep it running afterwards for interactive use.
|
|
stdin_open: true
|
|
tty: true
|
|
|
|
volumes:
|
|
kicad-build-cache:
|
|
workspace-src:
|