|  | il y a 8 ans | |
|---|---|---|
| .. | ||
| README.md | il y a 8 ans | |
| npm-shrinkwrap.canonical.json | il y a 8 ans | |
| requirements.txt | il y a 8 ans | |
| s3_cache.py | il y a 8 ans | |
| sauce_browsers.yml | il y a 8 ans | |
| uncached-npm-install.sh | il y a 8 ans | |
s3_cache.py do?s3_cache.py maintains a cache, stored in an Amazon S3 (Simple Storage Service) bucket, of a given directory whose contents are considered non-critical and are completely & solely determined by (and should be able to be regenerated from) a single given file.
The SHA-256 hash of the single file is used as the key for the cache. The directory is stored as a gzipped tarball.
All the tarballs are stored in S3's Reduced Redundancy Storage (RRS) storage class, since this is cheaper and the data is non-critical.
s3_cache.py itself never deletes cache entries; deletion should either be done manually or using automatic S3 lifecycle rules on the bucket.
Similar to git, s3_cache.py makes the assumption that SHA-256 will effectively never have a collision.
s3_cache.py is used to cache the npm packages that our Grunt tasks depend on and the RubyGems that Jekyll depends on. (Jekyll is needed to compile our docs to HTML so that we can run them thru an HTML5 validator.)
For npm, the node_modules directory is cached based on our npm-shrinkwrap.canonical.json file.
For RubyGems, the gemdir of the current RVM-selected Ruby is cached based on the pseudo_Gemfile.lock file generated by our Travis build script.
pseudo_Gemfile.lock contains the versions of Ruby and Jekyll that we're using (read our .travis.yml for details).
s3_cache.py necessary?s3_cache.py is used to speed up Bootstrap's Travis builds. Installing npm packages and RubyGems used to take up a significant fraction of our total build times. Also, at the time that s3_cache.py was written, npm was occasionally unreliable.
Travis does offer built-in caching on their paid plans, but this do-it-ourselves S3 solution is significantly cheaper since we only need caching and not Travis' other paid features.
travis-ci) and generate an access key for them. Note both the Access Key ID and the Secret Access Key.arn:aws:iam::XXXXXXXXXXXXXX:user/the-username-goes-hereCreate a new bucket. For a non-publicly-accessible bucket (like Bootstrap uses), it's recommended that the bucket name be random to increase security. On most *nix machines, you can easily generate a random UUID to use as the bucket name using Python:
python -c "import uuid; print(uuid.uuid4())"
Determine and note what your bucket's ARN is. The ARN for an S3 bucket is of the form: arn:aws:s3:::the-bucket-name-goes-here
In the bucket's Properties pane, in the "Permissions" section, click the "Edit bucket policy" button.
Input and submit an IAM Policy that grants the user at least read+write rights to the bucket. AWS has a policy generator and some examples to help with crafting the policy. Here's the policy that Bootstrap uses, with the sensitive bits censored:
{
    "Version": "2012-10-17",
    "Id": "PolicyTravisReadWriteNoAdmin",
    "Statement": [
        {
            "Sid": "StmtXXXXXXXXXXXXXX",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::XXXXXXXXXXXXXX:user/travis-ci"
            },
            "Action": [
                "s3:AbortMultipartUpload",
                "s3:GetObjectVersion",
                "s3:ListBucket",
                "s3:DeleteObject",
                "s3:DeleteObjectVersion",
                "s3:GetObject",
                "s3:PutObject"
            ],
            "Resource": [
                "arn:aws:s3:::XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX",
                "arn:aws:s3:::XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX/*"
            ]
        }
    ]
}
If you want deletion from the cache to be done automatically based on age (like Bootstrap does): In the bucket's Properties pane, in the "Lifecycle" section, add a rule to expire/delete files based on creation date.
Install the travis RubyGem: gem install travis
Encrypt the environment variables:
travis encrypt --repo twbs/bootstrap "AWS_ACCESS_KEY_ID=XXX"
travis encrypt --repo twbs/bootstrap "AWS_SECRET_ACCESS_KEY=XXX"
travis encrypt --repo twbs/bootstrap "TWBS_S3_BUCKET=XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"
Add the resulting secure environment variables to .travis.yml.
Read s3_cache.py's source code and Bootstrap's .travis.yml for how to invoke and make use of s3_cache.py.