🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

💾 Downloads 🕛 kürzlich 2 Min Lesezeit
0

trunk/3df983ce80ed6a6d81579f3964e5d53787483bed: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)

↗ Quelle (GitHub · github.com)
🗣️ Stimme:
🐙
$ git clone https://github.com/pytorch/pytorch.git

Two related changes to docker-builds.yml:




  1. Migrate the full .ci/docker/** image matrix to OSDC ARC runners.

    The orchestrator runs on a small mt-l-x86iavx512-2-4 runner inside

    ghcr.io/actions/actions-runner:latest; the actual build is

    offloaded to the cluster's remote BuildKit pools. BuildKit is a

    remote builder, so a single x86 orchestrator can drive both amd64

    and arm64 builds -- only the buildkit_addr differs per matrix row.


    Auth model:



    • ECR: reuses pytorch/pytorch/.github/actions/ecr-login@main,

      which falls through to OIDC on OSDC pods (no EC2 instance profile,

      no IRSA on the arc-runner ServiceAccount). We pass

      aws-role-to-assume: arn:aws:iam::308535385114:role/arc; a

      companion change in pytorch-gha-infra grants that role the ECR

      write actions on the pytorch/ci-image repository.

    • GHCR: unchanged (GHCR_PAT under the docker-build environment,

      gated on push events).


    Dropped:



    • pytorch/test-infra/.github/actions/calculate-docker-image and

      pull-docker-image: the tag is just git rev-parse HEAD:.ci/docker,

      computed inline.

    • chown-workspace, the legacy ecr-login composite step, and the

      nick-fields/retry wrapper for the GHCR push -- docker buildx imagetools create is a one-shot server-side cross-registry copy.


    .ci/docker/build.sh learns one knob, REMOTE_BUILDKIT. When set,

    it swaps --load -t <tmp> for --push (remote builders cannot load

    into a non-existent local daemon) and skips the post-build

    drun-based sanity checks. The EC2 / local-daemon path is unchanged.


    .github/actionlint.yaml learns the new mt-l-x86iavx512-2-4

    self-hosted runner label.




  2. Add a ciflow/docker tag trigger, mirroring how trunk.yml uses

    ciflow/trunk/*. Pushing a ciflow/docker/<sha> tag to any commit

    force-builds the matrix on that commit -- useful for testing

    Dockerfile edits without an open PR, or for re-running a build that

    failed transiently. The existing paths: filter on push: is

    removed because GitHub AND-combines tags with paths, which would

    silently block ciflow pushes on commits that didn't already touch

    .ci/docker. PR-side path filtering is preserved.




Authored by Claude.

Pull Request resolved: , https://github.com/malfet

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten trunk/3df983ce80ed6a6d81579f3964e5d53787483bed: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)

Thematisch verwandte Begriffe: trunk3df983ce80ed6a6d81579f3964e5d53787483bed, Migrate, dockerbuilds, workflow · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...