Skip to content

chore(ci): build the derived sandbox images in their own job - #106653

Merged
trunk-io[bot] merged 2 commits into
chore/sandbox-skills-checkoutfrom
chore/sandbox-derived-images-job
Sep 28, 2026
Merged

trunk-io[bot] merged 2 commits into
chore/sandbox-skills-checkoutfrom
chore/sandbox-derived-images-job

Conversation

@tatoalo

@tatoalo tatoalo commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The check a sandbox agent bump waits on, "Sandbox Base Image Smoke", reports 38 s later than it could at p50 and 201 s later at max, because the base image job also builds the pi, autoresearch and vm images after the smoke (run 36044984574, job "Build and push Tasks Sandbox container image": the second parallel group runs for 25 s after the smoke).

  • The smoke check only needs the base image and its smoke result.
  • A job's outputs are not readable until the whole job ends, so the derived builds sit between the smoke and the check.

Changes

  • The three derived images build in a new job, sandbox_derived_build, that needs the base job. The smoke check now reports as soon as the base job ends.
  • "Sandbox Base Image Pass" needs the new job and fails when it fails, so the required check still covers every image.
  • The new job checks out only the images directory (the derived Dockerfiles copy one file from it) and sets up neither buildx nor QEMU, because it runs no container.

Before:

flowchart LR
    S[build_skills] --> B[sandbox_base_build<br/>base, notebook, streamlit<br/>smoke<br/>pi, autoresearch, vm]
    B --> C{{Sandbox Base Image Smoke}}
    B --> P{{Sandbox Base Image Pass}}
    classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff;
    classDef phYellow fill:#f9bd2b,stroke:#f9bd2b,color:#000;
    class S,B phBlue;
    class C,P phYellow;
Loading

After:

flowchart LR
    S[build_skills] --> B[sandbox_base_build<br/>base, notebook, streamlit<br/>smoke]
    B --> C{{Sandbox Base Image Smoke}}
    B --> D[sandbox_derived_build<br/>pi, autoresearch, vm]
    D --> P{{Sandbox Base Image Pass}}
    B --> P
    classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff;
    classDef phYellow fill:#f9bd2b,stroke:#f9bd2b,color:#000;
    class S,B,D phBlue;
    class C,P phYellow;
Loading

@tatoalo
tatoalo added this pull request to stack #106659 September 25, 2026 12:56
@tatoalo tatoalo added the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@posthog

posthog Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🦔 PostHog Review reviewed this pull request

Nothing worth raising this time. Enjoy the moment:

The dancing man in the red room from Twin Peaks

@github-actions

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Trunk lane — backend Python lane

This PR is assigned to the backend Python lane. It runs backend Python tests and may merge in parallel with PRs in other lanes.

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[High risk] Splits sandbox image builds into a separate CI job.

The PR is not ready to merge because the derived-image job publishes packages from pull-request runs.

Reviews (2) · Last reviewed commit: "chore(ci): build the derived sandbox ima..."

@posthog posthog Bot removed the reviewhog ($$$) Reviews pull requests before humans do label Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 44292374-9e96-4925-b232-d94750fc2b5f

📥 Commits

Reviewing files that changed from the base of the PR and between 230a6ac and 8b5380b.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 4f863db5-d6ab-4d2e-a830-ffafb18074b6

📥 Commits

Reviewing files that changed from the base of the PR and between 911b301 and 08e9377.

📒 Files selected for processing (1)
  • .github/workflows/cd-sandbox-base-image.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The workflow adds sandbox_derived_build after sandbox_base_build. It builds the pi image with the commit-specific base image and removes downloaded artifact references from the autoresearch and VM build contexts. The aggregate check now includes the derived build and fails when its result is neither success nor skipped.

Priority: ⬇️ Low

Merge Risk: 🟡 Moderate · up to 08e93

A master build with deployment disabled can fail while building the derived images. Resolve that workflow condition before merging unless the failure is explicitly accepted.

Architecture Summary

Architecture risk: 🔵 Low · up to 08e93

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: Adds sandbox_derived_build, dependent on changes and sandbox_base_build, with repository, PR-origin, change-detection, dispatch, and label conditions. It checks out only .dockerignore and sandbox image definitions, authenticates to GHCR, and builds the pi image from the commit-specific base image; its context no longer refers to a downloaded artifact.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: The autoresearch image build context no longer refers to a downloaded artifact.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: The VM image build context no longer refers to a downloaded artifact.
  • observed — Modified behavior in .github/workflows/cd-sandbox-base-image.yml: Adds sandbox_derived_build to the aggregate check’s dependencies.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description clearly explains the problem, changes, impact, and CI flow. However, it omits the required “How did you test this code?” section and does not select a release status. It also omits the… Add a “How did you test this code?” section with actual automated or manual verification and limitations. Select exactly one release-status option. Complete or explicitly mark the notification, docs, and agent-context sections as applicable…
Full details: Description check

Explanation

The description clearly explains the problem, changes, impact, and CI flow. However, it omits the required “How did you test this code?” section and does not select a release status. It also omits the template’s agent context and notification/docs sections, if applicable.

Resolution

Add a “How did you test this code?” section with actual automated or manual verification and limitations. Select exactly one release-status option. Complete or explicitly mark the notification, docs, and agent-context sections as applicable or not applicable.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@tatoalo
tatoalo force-pushed the chore/sandbox-derived-images-job branch from 27363fb to 911b301 Compare September 25, 2026 13:36

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 252ae14e-5d46-42f7-bedc-6bf5cc15774b

📥 Commits

Reviewing files that changed from the base of the PR and between 27363fb and 911b301.

📒 Files selected for processing (1)
  • .github/workflows/cd-sandbox-base-image.yml

Included review availability: Your plan provides up to 12 included reviews per hour; 0 remain after this review.

Comment thread .github/workflows/cd-sandbox-base-image.yml
@tatoalo
tatoalo marked this pull request as ready for review September 25, 2026 14:16
@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team September 25, 2026 14:17
Comment thread .github/workflows/cd-sandbox-base-image.yml
@trunk-io

trunk-io Bot commented Sep 28, 2026

Copy link
Copy Markdown

Stacked PR 106658 failed testing in the merge queue. Please investigate the failure and re-submit the stack.

@tatoalo
tatoalo force-pushed the chore/sandbox-derived-images-job branch from 08e9377 to 230a6ac Compare September 28, 2026 08:26
@tatoalo
tatoalo force-pushed the chore/sandbox-derived-images-job branch from 230a6ac to 8b5380b Compare September 28, 2026 08:28
@trunk-io
trunk-io Bot merged commit 0b0de21 into master Sep 28, 2026
222 checks passed
@trunk-io
trunk-io Bot deleted the chore/sandbox-derived-images-job branch September 28, 2026 09:03
@trunk-io

trunk-io Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request was merged into master as part of stacked PR 106658.

@deployment-status-posthog

deployment-status-posthog Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-09-28 09:24 UTC Run
prod-us ✅ Deployed 2026-09-28 09:41 UTC Run
prod-eu ✅ Deployed 2026-09-28 09:42 UTC Run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants