Skip to content

ci(appsec): tolerate Go module cache miss instead of hard-failing#5065

Merged
darccio merged 1 commit into
mainfrom
ci/appsec-graceful-cache-miss
Jul 24, 2026
Merged

ci(appsec): tolerate Go module cache miss instead of hard-failing#5065
darccio merged 1 commit into
mainfrom
ci/appsec-graceful-cache-miss

Conversation

@kakkoyun

Copy link
Copy Markdown
Member

What does this PR do?

The three Restore Go modules cache steps in appsec.yml (the macos, disabled, and golang-linux-container jobs) set fail-on-cache-miss: true. When the GitHub Actions cache service times out during restore, that turns a transient miss into a hard job failure instead of falling back to a rebuild.

Example: run 30056911582linux/arm64 golang:1.26-trixie failed on an actions/cache download timeout plus fail-on-cache-miss.

This sets fail-on-cache-miss: false on those three restore steps.

Why it's safe

These jobs manage caching themselves (actions/setup-go with cache: false) and point GOMODCACHE at the restored path with no -mod=readonly. On a miss, Go re-fetches the modules pinned by go.sum — same versions, just a slower run. The go-mod-caching job already relies on this cold path.

Motivation

Removes a class of infra-only CI failures (cache-service timeouts) seen in the CI report for commit 7e9bb86f. CI-only; no code or go.mod changes. Verified with actionlint.

The three "Restore Go modules cache" steps (macos, disabled, golang-linux-container jobs) set fail-on-cache-miss: true. When the GitHub Actions cache service times out during restore, that turns a transient miss into a hard job failure instead of falling back to a rebuild (e.g. run 30056911582, linux/arm64 golang:1.26-trixie).

Set fail-on-cache-miss: false on the three restore steps. These jobs manage caching themselves (setup-go cache: false) and point GOMODCACHE at the restored path with no -mod=readonly, so on a miss Go re-fetches the modules pinned by go.sum -- same versions, slower run. The go-mod-caching job already relies on this cold path.
@datadog-datadog-prod-us1-2

datadog-datadog-prod-us1-2 Bot commented Jul 24, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 62.74% (+11.32%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 08b51d3 | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Jul 24, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-07-24 11:19:25

Comparing candidate commit 08b51d3 in PR branch ci/appsec-graceful-cache-miss with baseline commit 345341d in branch main.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 326 metrics, 0 unstable metrics, 1 flaky benchmarks without significant changes.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Known flaky benchmarks

These benchmarks are marked as flaky and will not trigger a failure. Modify FLAKY_BENCHMARKS_REGEX to control which benchmarks are marked as flaky.

Known flaky benchmarks without significant changes:

  • scenario:BenchmarkOTLPTraceWriterFlush

@kakkoyun
kakkoyun marked this pull request as ready for review July 24, 2026 11:34
@kakkoyun
kakkoyun requested a review from a team as a code owner July 24, 2026 11:34
@darccio
darccio merged commit fa297ea into main Jul 24, 2026
206 of 207 checks passed
@darccio
darccio deleted the ci/appsec-graceful-cache-miss branch July 24, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants