The image has not built since #157: its uv sync runs before the source is copied #166
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#166
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Deploying the
0.3.0branch to the test instance (for #163) failed in the image build, in thebuildstage:A failed build leaves the running container alone, so the instance kept running the image from 8 September and nothing was lost.
Cause
4346dfa5(#157) gave the Python build its own stage and, in the same move, put dependencies first so that a change to the application would not re-resolve them:uv syncinstalls the project as well as its dependencies unless told otherwise, and at that point there is nosrc/. Nothing syncs again after the source arrives. Before #157 the file copiedsrcfirst, which is why the test instance's image from 8 September built.Why nobody saw it
The commit says it plainly: "Read rather than measured, because nothing here builds an image (#81)." CI never builds the image, and
tests/test_image_build.pyreads the Dockerfile rather than running it. This deploy was the first build since, so no image of the 0.3.0 branch can have been built since4346dfa5, and the release workflow's image job would fail the same way.What fixing it is
uv's documented pattern for exactly this (Docker guide, intermediate layers): sync the dependencies with
--no-install-projectbefore the source is copied, and sync again after it to install the project.The layer caching #157 wanted survives: a change to
srcre-runs only the second sync, which installs one project and no dependencies.And a test that reads the order.
tests/test_image_build.pyalready splits the file into stages (#157). It can assert that a sync beforeCOPY srcpasses--no-install-project, and that one after it installs the project. It currently insists on exactly oneuv syncline, so that part changes too. That is not a substitute for #81, which is the real fix for "nothing here builds an image".Worth being careful about
--no-install-projectbelongs only on the first sync. On both lines, the image would ship without Postulo installed in its environment, which is the same failure at run time instead of at build time.Classification
Bug. Blocks building the 0.3.0 image, and so the release.
Done in
b6cfb8f7, and built rather than read: the test instance's deploy built the image and is running it.The fix
As proposed, uv's documented pattern:
Checked on the instance
Image postulo:latest Built; the container was recreated, started and reports healthy, and/healthzanswersok.SECURE_SSL_REDIRECTone (#82).Tests
test_the_project_is_installed_once_its_source_is_therereads thebuildstage: a sync beforeCOPY srcmust pass--no-install-project, and one after it must install the project. On the old Dockerfile it fails with runs before there is a project. The other sync tests now check every sync line rather than insisting on exactly one.Worth knowing
This is the third mistake in the Dockerfile that reading it did not catch, after #121 and #154. #81 is still the real fix: a CI job that builds the image.