Skip to content

Run CI on Ubicloud runners, and add a cargo audit job - #5

Merged
pathscale merged 1 commit into
masterfrom
ci/ubicloud-runners
Jul 28, 2026
Merged

pathscale merged 1 commit into
masterfrom
ci/ubicloud-runners

Conversation

@pathscale

Copy link
Copy Markdown
Owner

CI across ~/code runs on Ubicloud; this repo was still on ubuntu-latest and billing GitHub Actions minutes.

  • runs-on: ubicloud-standard-2 for the check job. Sized rather than copied: the heavier repos use -8, but this crate's whole job finishes in ~40s and Ubicloud bills by vCPU-minute, so a bigger runner costs more for no wall-clock gain. WorkTable uses -2 on the same reasoning.
  • New cargo audit job via rustsec/audit-check@v2, matching honey_id-types as the closest analogue (another published library). Now that this crate is on crates.io, an advisory against tokio or serde reaches every consumer and nothing else in CI would catch it.
  • Swatinem/rust-cache@v2 kept: it works on Ubicloud and is the Rust-aware option. ubicloud/cache@v4 is the drop-in for raw path caching, which is what api.support.cafe uses for apt and target dirs, but this crate has nothing that needs it.
  • AGENTS.md records the rule, including the part that bites on new repos: Ubicloud has to be enabled per repository or workflows queue forever rather than failing fast.

This PR is its own test. If the checks run at all, the runners are wired up; if they queue, Ubicloud is not enabled for this repo yet.

CI across ~/code runs on Ubicloud; `ubuntu-latest` here was billing GitHub
Actions minutes instead. Switched to `ubicloud-standard-2`.

Sized deliberately rather than copied: the heavier repos use `-8`, but this
crate's whole check job finishes in about 40 seconds, and Ubicloud bills by
vCPU-minute, so a larger runner would cost more for no wall-clock gain. WorkTable
uses `-2` for the same reason.

Added a `cargo audit` job, matching honey_id-types, the closest analogue as
another published library. Worth having now that this crate is on crates.io: an
advisory against tokio or serde reaches every consumer and nothing else in CI
would notice. It runs on `-2` since it is a lookup, not a build.

Recorded the runner rule in AGENTS.md so it survives the next person reaching
for `ubuntu-latest` out of habit, including the part that bites on new repos:
Ubicloud has to be enabled per repository or workflows queue forever.
@pathscale
pathscale merged commit 4ae680b into master Jul 28, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant