Skip to content

build(docker): Install dependencies into a venv - #353

Merged
oioki merged 1 commit into
masterfrom
build/granian-venv-path
Sep 10, 2026
Merged

oioki merged 1 commit into
masterfrom
build/granian-venv-path

Conversation

@oioki

@oioki oioki commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

Install Python dependencies into /opt/venv in the build stage and copy that single directory into the runtime stage, instead of copying out of the base image's /opt/python prefix.

The image workflow has been failing on master since the last green run in June:

ERROR: failed to build: failed to solve: failed to compute cache key: failed to calculate checksum of ref ...: "/opt/python/bin/granian": not found

Nothing in the repo changed. The dhi-mirror/python:3.13-debian13{,-dev} tags were rebuilt on 2026-09-03 and the interpreter prefix moved from /opt/python to /usr — scripts are now in /usr/bin and packages in /usr/lib/python3.13/site-packages, so /opt/python does not exist at all. Both COPY --from=build lines and the CMD were pointing at dead paths.

Retargeting those paths at /usr would also fix the build, but it leaves the same coupling to the base image's internal layout. A venv keeps the paths owned by this Dockerfile, so the next base image refresh cannot break it the same way.

Verified locally by building for linux/amd64 and running the image: granian starts and binds 0.0.0.0:8000 as nonroot; the container then exits only because GEOIP_PATH and GCP application default credentials aren't set outside the deployment.

Note that the image workflow's build job is gated on if: github.ref_name == github.event.repository.default_branch, so it is skipped on pull requests — this fix is not exercised by this PR's CI and only runs once it lands on master.

🤖 Generated with Claude Code

The dhi-mirror python base images moved the interpreter prefix from
/opt/python to /usr, so the runtime stage's COPY of
/opt/python/bin/granian no longer resolves and the master image build
fails with "failed to compute cache key". The Dockerfile itself has not
changed since June; the floating 3.13-debian13 tags were rebuilt
underneath it.

Install requirements into /opt/venv and copy that single directory into
the runtime stage instead of reaching into the base image's layout. The
paths are now owned by this Dockerfile, so a future base image refresh
that relocates site-packages cannot break the build again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@oioki
oioki marked this pull request as ready for review September 10, 2026 11:54
@oioki
oioki merged commit cfb561c into master Sep 10, 2026
18 checks passed
@oioki
oioki deleted the build/granian-venv-path branch September 10, 2026 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant