paperclip/.github/workflows
Dotta 8430bd897f
ci: reuse trusted cache for Daytona images (#12862)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The full-stack runner campaign checks local and Daytona runner
behavior.
> - A Daytona image content miss starts a cold multi-stage Docker build.
> - Stable dependency and agent CLI layers take most of the image build
time.
> - Development targets must not write shared cache state.
> - This pull request adds a registry cache with a default-branch write
gate.
> - It also puts volatile source inputs after stable install layers.
> - The benefit is a shorter Daytona image build without weaker secret
isolation.

## Linked Issues or Issue Description

**What existing behavior does this improve?**

This improves the Daytona runner image stage in the full-stack E2E
workflow.

**Subsystem affected**

The GitHub Actions runner E2E workflow and its Daytona Docker image are
affected.

**Current behavior**

Each new Daytona image content ID starts with an empty BuildKit cache. A
runner source change also invalidates dependency and agent CLI install
layers because volatile inputs occur before those layers.

**Proposed behavior**

All authorized campaigns can read one GHCR BuildKit cache. Only a
campaign whose target ref is the repository default branch can update
that cache. The Dockerfile installs dependencies and agent CLIs before
it consumes volatile runner source or revision metadata.

**Reason and benefit**

The paid runner matrix spends several minutes building the image before
any selected cell can start. Cache reuse removes repeated stable setup
work and makes focused Daytona iterations faster.

**Breaking changes**

None. The immutable content tag, digest inspection, Cosign signature,
image labels, pinned base images, and provider credential boundary stay
unchanged.

## What Changed

- Read a registry-backed BuildKit cache for Daytona image content
misses.
- Export the cache only when the resolved target ref is the default
branch.
- Keep provider credentials outside the image build and cache.
- Install provider-pack dependencies before runner source is copied.
- Keep expensive agent CLI installs before source revision metadata.
- Add workflow and Docker layer-order contract checks.

## Verification

- `prettier --write .github/workflows/runner-full-stack-e2e.yml
tests/runner-e2e/daytona-image.test.ts
tests/runner-e2e/workflow-security.test.ts`
- `actionlint .github/workflows/runner-full-stack-e2e.yml`
- `git diff --check`
- I did not run a test suite or Docker image build locally. The
requested iteration policy reserves those checks for GitHub Actions.

## Risks

Low risk. BuildKit can use a cache record only when its content key
matches the build instruction and input. Development targets have
read-only cache access. The cache contains public source and build
outputs, but it does not receive provider credentials or the GitHub
token as Docker build inputs.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex with GPT-5, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-09-05 06:31:27 -05:00
..
agent-runtime-images.yml build(deps): bump actions/checkout from 6 to 7 (#8461) 2026-06-23 10:13:39 -07:00
commitperclip-review.yml fix(build): enforce Node 24 across Paperclip (#11792) 2026-08-21 10:17:52 -07:00
docker.yml ci: harden paid runner browser and lock repair (#12829) 2026-09-04 08:58:44 -05:00
e2e.yml test(runner): add full-stack acceptance and eval gates (#12700) 2026-09-02 08:55:08 -05:00
pr-trusted.yml ci: keep the Docker build context complete and guard it on every PR (#12855) 2026-09-04 15:35:10 -07:00
pr.yml ci: activate the Docker context integrity gate for PRs (#12860) 2026-09-04 17:22:15 -07:00
refresh-lockfile.yml ci: harden paid runner browser and lock repair (#12829) 2026-09-04 08:58:44 -05:00
release-smoke.yml Follow the current onboarding arc in the release smoke (#12423) 2026-08-28 07:21:08 -07:00
release-verify.yml test(runner): add full-stack acceptance and eval gates (#12700) 2026-09-02 08:55:08 -05:00
release.yml fix(onboarding): restore browser launch and gate canaries (#12667) 2026-09-01 10:10:30 -05:00
runner-chaos-evals.yml test(runner): add full-stack acceptance and eval gates (#12700) 2026-09-02 08:55:08 -05:00
runner-full-stack-e2e.yml ci: reuse trusted cache for Daytona images (#12862) 2026-09-05 06:31:27 -05:00
runner-live-evals.yml test(runner): add full-stack acceptance and eval gates (#12700) 2026-09-02 08:55:08 -05:00
storybook-visual.yml build(deps): bump actions/setup-node from 6 to 7 (#9884) 2026-07-21 12:04:06 -05:00