feat(serve): add Sonatype Nexus as a shared cache tier - #514
Merged
tinder-maxwellelliott merged 1 commit intoOct 5, 2026
Merged
Conversation
Adds a Nexus raw hosted repository as an alternative to the S3 shared cache tier for multi-instance `serve` deployments. Entries are read and written with plain GET/PUT on <nexusUrl>/repository/<repo>/<prefix>/<key>.json and degrade exactly like S3: a failed read is a miss, a failed write stays local-only. New flags: --nexusUrl, --nexusRepository, --nexusPrefix, --nexusUsername (env BAZEL_DIFF_NEXUS_USERNAME) and --nexusCaCert. The password is environment-only (BAZEL_DIFF_NEXUS_PASSWORD) so it never appears in a process listing; URL-embedded credentials are rejected and redirects are not followed so basic auth is never replayed elsewhere. The Nexus and S3 flags are mutually exclusive. Uses attohttpc (already in the graph via rust-s3) with basic-auth enabled, plus rustls-pki-types for PEM parsing; no new crates. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
tinder-maxwellelliott
marked this pull request as ready for review
October 5, 2026 15:33
tinder-maxwellelliott
deleted the
claude/nexus-caching-bazel-diff-34420b
branch
October 5, 2026 16:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a Sonatype Nexus raw hosted repository as a shared cache tier for
bazel-diff serve, alongside the existing S3 tier. You can use one or the other, not both.Cache entries are read and written with plain
GET/PUTon<nexusUrl>/repository/<repo>/<prefix>/<key>.json. The Nexus tier fails the same way S3 does: a failed read is treated as a cache miss and the revision is regenerated, and a failed write leaves the entry on local disk only. An outage slows things down but never fails a request.Changes
src/server.rs:RemoteCacheis now an enum overS3(the existing code, renamedS3Cache) and a newNexusbackend. The Nexus client:400when writing: it usually means the repository's deployment policy forbids redeploy.src/main.rs: new flags--nexusUrl,--nexusRepository,--nexusPrefix,--nexusUsername(alsoBAZEL_DIFF_NEXUS_USERNAME), and--nexusCaCert(a PEM bundle of extra CA certificates, for a Nexus behind an internal CA).BAZEL_DIFF_NEXUS_PASSWORDenvironment variable, so it never shows up in a process listing.Debugoutput.--nexusUrland--nexusRepositoryrequire each other and conflict with--s3Bucket.Commands::Servenow wraps its args in aBox, because clippy'slarge_enum_variantfired once the new fields were added.attohttpc(already pulled in by rust-s3; this enables itsbasic-authfeature) andrustls-pki-types(for PEM parsing). No new crates are downloaded.cargo-bazel-lock.jsonis repinned.tools/readme_template.mdand regeneratesREADME.md. It covers repository setup, credentials and user tokens, required privileges, TLS, redirects, and retention via a Nexus cleanup policy.Why
This gives teams that run Nexus instead of AWS a way to share the hash cache across a fleet of
serveinstances. A revision then gets hashed once across the fleet instead of once per instance.Notes for reviewers
400. Requests still succeed, but each one logs a warning.--nexusCaCertis only checked as valid PEM at startup. A file that parses but contains a broken certificate would fail on every request (each logged as a cache miss), not at startup.tiny_httpmock. They cover a hit, a miss, an upload with basic auth, failure statuses (500/401/302/400) each making exactly one request with no redirect followed, connection errors, URL building and validation, error-body truncation, password redaction, and loading the CA bundle.--s3Bucket.cargo test --lib --binspasses, and so do clippy (-D warnings),cargo fmt --check,bazel build //:bazel-diff-rust, andbazel test //src:rust_tests //src:cli_tests.bazel query. I have not tested against a real Nexus instance.tools/serve_consistency.pyonly covers the S3 tier so far. A mock Nexus mode for it would extend the multi-instance consistency checks to this backend.🤖 Generated with Claude Code