Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 35s
CI / tests-integration (push) Successful in 2m5s
CI / tests-unit (push) Successful in 2m30s
CI / tests-ui (push) Successful in 3m3s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 44s
The host runs with vm.overcommit_memory=0 and no swap, so a process that
grows past free memory makes the kernel OOM-kill across the whole machine
-- the Turbopack build (commit 3d828a61) could take out the database,
nginx or the live release.
Add scripts/with-memory-cap.sh: it moves a command into its own systemd
scope with MemoryMax, so only that cgroup gets OOM-killed (verified: a
Turbopack build died at its 6GB cap, host untouched). Build/analyze/dev/
test*/typecheck now run under explicit caps; ulimit -v is only an explicit
opt-in because it bounds virtual address space per process and 10g/20g both
break V8-based builds. Docker and GitLab builds run in their own isolated
containers with a read-only cgroupfs and opt out explicitly (webpack +
--max-old-space-size stay their bound).
Measured: webpack build peaks ~6.5GB RSS, so 10GB leaves headroom within
the 23.5GB host.
41 lines
701 B
YAML
41 lines
701 B
YAML
image: node:26
|
|
|
|
# Runner containers have no systemd, so scripts/with-memory-cap.sh cannot
|
|
# enforce an RSS cap there and correctly refuses to run unbounded. These
|
|
# builds are already isolated inside their own runner container (not the
|
|
# host) and use the webpack builder; opt out explicitly on purpose.
|
|
variables:
|
|
CMS_MEMORY_CAP_BACKEND: "none"
|
|
|
|
stages:
|
|
- test
|
|
- build
|
|
|
|
cache:
|
|
paths:
|
|
- node_modules/
|
|
|
|
before_script:
|
|
- corepack enable
|
|
- pnpm install --frozen-lockfile
|
|
|
|
lint:
|
|
stage: test
|
|
script:
|
|
- pnpm run lint
|
|
|
|
typecheck:
|
|
stage: test
|
|
script:
|
|
- pnpm run typecheck
|
|
|
|
test:
|
|
stage: test
|
|
script:
|
|
- pnpm run test
|
|
|
|
build:
|
|
stage: build
|
|
script:
|
|
- pnpm run build
|