Skip to main content
theauth-go ships a benchmark gate that runs on every pull request and fails if any curated benchmark regresses more than 25% (the default threshold).

Curated benchmarks

The authoritative list lives in benchgate/curated.txt. Edit that file to add or remove benchmarks; the gate script picks it up automatically.

Running locally

Threshold

The default regression threshold is 25%. To change it:
  • Globally for CI: update THRESHOLD_PCT in .github/workflows/bench.yml.
  • For a single local run: THRESHOLD_PCT=10 ./scripts/bench-gate.sh --check diff.txt.

CI workflow

The bench workflow (.github/workflows/bench.yml) runs on every pull request and on pushes to main. Key design decisions:
  • Base caching: the base-branch benchmark output is cached by commit SHA so re-runs of the same PR do not re-benchmark the base.
  • Cold-base fallback: when no cache exists the workflow checks out the base commit, runs the benchmarks, saves the cache, then returns to the PR SHA.
  • PR comment: on pull requests the diff is posted as a PR comment so reviewers see the delta without downloading artifacts.
  • Artifacts: pr-bench.txt, base-bench.txt, and diff.txt are uploaded as workflow artifacts (retained 90 days).

Adding a benchmark

  1. Write the benchmark in the appropriate package following existing conventions (see internal/bench/ for examples).
  2. Add the benchmark name to benchgate/curated.txt with a comment explaining what regression it catches.
  3. Run BENCH_TIME=1x BENCH_COUNT=1 ./scripts/bench-gate.sh locally to confirm it appears and exits 0.

Noisy benchmark skip annotation

If a benchmark routinely produces more than 10% noise, add a # gate:skip line in benchgate/curated.txt:
Do not skip a benchmark without a reference to a tracking issue.
Last modified on October 7, 2026