3 ms·
Not custom copies, but a locked down cache of packages. For Gentoo you can do this by locking the portage tree you use and keeping a copy of the distfiles from
by throwaway9870 5y ago
Not custom copies, but a locked down cache of packages. For Gentoo you can do this by locking the portage tree you use and keeping a copy of the distfiles from the first run, for Python it was a requirements.txt file with a cache of the tar files from PyPi, for go it was including 3rd party code in repo. I don't know what the team did for npm.
It was really nice doing a full image rebuild and knowing the only thing that changed it was you explicitly changed.
- Volundr 5y agoI'm genuinely curious about this. How are you distributing these caches so that if I do a build on my machine it'll produce the exact same image as on yours? If I'm understanding what you mean by "cache" (I'm thinking the node_modules folder for example for NPM) it'd certainly work, but it feels like a logistical nightmare to me.
- mason55 5y agoWe host our own Maven and PyPi. External artifacts get pulled into the cache and devs get all their artifacts form our cache. If an artifact already exists in the cache then we never update it. Super easily honestly, one of those things that we never even think about until someone upstream does something that would have screwed us anyway, like republishing a version number
- throwaway9870 5y agoWe had a VM in a datacenter that hosted everything and was accessed over a VPN. Again, I don't know the specifics of the NPM setup, but for everything else it was HTTP serving static files right off disk. It was a manual process to add new files, but generally they got added in batches so it wasn't too painful. Gentoo has hashes for everything, so at least for OS packages, you could not overwrite anything without breaking the build and noticing.