build: compress linux release binaries with upx - #770
Conversation
Add a goreleaser upx step (--best --lzma) scoped to the linux release build ids (devsy-linux, devsy-pro-dev), shrinking the linux/amd64 binary from ~124MB to ~24MB. Local dev builds (devsy-dev, devsy) are left uncompressed so they don't require upx or pay the compression cost. Install upx on the linux leg of the release and pr-ci workflows via the sha-pinned crazy-max/ghaction-upx action (install-only).
✅ Deploy Preview for images-devsy-sh canceled.
|
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for devsydev canceled.
|
The devsy binary is copied into containers and re-exec'd frequently (credentials server, git credential helper per git op, agent setup). --lzma has the slowest decompression, which broke timing-sensitive e2e specs (credentials server startup, secret injection, ssh socket cleanup, workspace status). Use UCL (compress: best) instead: ~10x faster decompression at a smaller size reduction.
Up to standards ✅🟢 Issues
|
Summary
Shrinks the shipped Linux CLI binary from ~124 MB to ~24 MB (~80% smaller) by compressing it with UPX (
--best --lzma), with no feature loss.Changes
.goreleaser.yml— newupxblock (compress: best,lzma: true) scoped togoos: linuxand the release build idsdevsy-linuxanddevsy-pro-dev. Local dev builds (devsy-dev,devsy) are intentionally excluded so they neither require UPX nor pay the compression cost..github/workflows/release.ymland.github/workflows/pr-ci.yml— install UPX on the Linux leg only, via the SHA-pinnedcrazy-max/ghaction-upx@v4.0.0action withinstall-only: true(goreleaser still drives the compression). macOS/Windows artifacts are untouched, so notarization is unaffected.Notes
task cli:build:dev:prolocally now needsupxon PATH (that id is compressed); plaintask cli:build:devdoes not.