Skip to content

test(cache): authenticate remote cache e2e uploads with a GitHub Actions stand-in - #809

Draft
wan9chi wants to merge 1 commit into
remote-cache-e2e-blobsfrom
remote-cache-e2e-oidc
Draft

wan9chi wants to merge 1 commit into
remote-cache-e2e-blobsfrom
remote-cache-e2e-oidc

Conversation

@wan9chi

@wan9chi wan9chi commented Oct 5, 2026

Copy link
Copy Markdown
Member

Motivation

The public cache service from #718 only accepts uploads with a GitHub Actions OIDC token. The token has to come from a push to the registered repository's main branch, and its audience has to be the endpoint. The file backend accepted any upload, so the e2e cases never sent a token and never exercised the client's OIDC support from #798.

Changes

  • GitHub Actions stand-in. The backend process stands in for GitHub's token service. remote-cache-server run --github-actions runs a command as if in a job with id-token: write: it sets ACTIONS_ID_TOKEN_REQUEST_URL, and ACTIONS_ID_TOKEN_REQUEST_TOKEN defaults to main-push. The request token picks the workflow run the token is for: main-push or pull-request.
  • Write policy. Like the service, the file backend checks each store's token: its RS256 signature against the stand-in's key, its time bounds, its audience, and its claims. It answers other stores as the service does, with 401 Invalid credentials or 403 Write not permitted.
  • Uploading steps run with --github-actions. The only snapshot changes are those command lines.

Stacked on #808.

🤖 Generated with Claude Code

…ons stand-in

The public cache service only accepts uploads with a GitHub Actions
OIDC token for a push to the registered repository's main branch, whose
audience is the endpoint. The test backend accepted any upload, so the
e2e cases never sent a token and never exercised the client's OIDC
support.

The backend process now stands in for GitHub's token service, and
`remote-cache-server run --github-actions` runs a command as if in a
GitHub Actions job with `id-token: write`. The request token picks the
workflow run that the token is for, a push to `main` by default. Like
the service, the backend checks the token's signature, time bounds,
audience, and claims, and answers other stores with `401 Invalid
credentials` or `403 Write not permitted`.

Every step that uploads now runs with `--github-actions`. The only
snapshot changes are those command lines.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

fspy benchmark

linux

dynamic/launch             change  -0.65%  [ -8.50% ..  +7.91%]  overhead  +284.28%
dynamic/access             change  +0.57%  [-11.59% .. +21.95%]  overhead   +13.91%
dynamic/access-relative    change  +1.00%  [-14.46% .. +25.79%]  overhead   +60.74%
dynamic/access-contended   change  -4.33%  [-14.83% ..  +3.21%]  overhead   +14.77%
static/launch              change  +1.03%  [ -6.16% ..  +9.38%]  overhead  +708.53%
static/access              change  +2.37%  [-10.14% .. +22.53%]  overhead  +849.35%
static/access-relative     change  -0.28%  [ -7.25% ..  +6.05%]  overhead +1160.96%
static/access-contended    change  +0.33%  [ -5.66% ..  +7.14%]  overhead +2785.90%

macos

dynamic/launch             change  -0.35%  [ -4.25% ..  +3.86%]  overhead  +224.38%
dynamic/access             change  +0.65%  [ -8.21% .. +132.04%]  overhead    +4.42%
dynamic/access-relative    change  +2.99%  [ -4.16% .. +82.87%]  overhead  +262.41%
dynamic/access-contended   change  +0.69%  [-11.88% .. +73.02%]  overhead   +11.07%

windows

dynamic/launch             change  -0.19%  [ -6.55% .. +10.39%]  overhead   +23.70%
dynamic/access             change  +0.55%  [ -2.87% ..  +6.63%]  overhead    +1.43%
dynamic/access-relative    change  +0.18%  [ -4.16% ..  +6.60%]  overhead    +1.43%
dynamic/access-contended   change  -0.10%  [-15.83% ..  +9.12%]  overhead    -7.15%

@wan9chi
wan9chi added this pull request to stack #812 October 5, 2026 05:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant