build(docker): Install dependencies into a venv - #353
Merged
Merged
Conversation
The dhi-mirror python base images moved the interpreter prefix from /opt/python to /usr, so the runtime stage's COPY of /opt/python/bin/granian no longer resolves and the master image build fails with "failed to compute cache key". The Dockerfile itself has not changed since June; the floating 3.13-debian13 tags were rebuilt underneath it. Install requirements into /opt/venv and copy that single directory into the runtime stage instead of reaching into the base image's layout. The paths are now owned by this Dockerfile, so a future base image refresh that relocates site-packages cannot break the build again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Install Python dependencies into
/opt/venvin the build stage and copy that single directory into the runtime stage, instead of copying out of the base image's/opt/pythonprefix.The
imageworkflow has been failing on master since the last green run in June:Nothing in the repo changed. The
dhi-mirror/python:3.13-debian13{,-dev}tags were rebuilt on 2026-09-03 and the interpreter prefix moved from/opt/pythonto/usr— scripts are now in/usr/binand packages in/usr/lib/python3.13/site-packages, so/opt/pythondoes not exist at all. BothCOPY --from=buildlines and theCMDwere pointing at dead paths.Retargeting those paths at
/usrwould also fix the build, but it leaves the same coupling to the base image's internal layout. A venv keeps the paths owned by this Dockerfile, so the next base image refresh cannot break it the same way.Verified locally by building for
linux/amd64and running the image: granian starts and binds0.0.0.0:8000asnonroot; the container then exits only becauseGEOIP_PATHand GCP application default credentials aren't set outside the deployment.Note that the
imageworkflow's build job is gated onif: github.ref_name == github.event.repository.default_branch, so it is skipped on pull requests — this fix is not exercised by this PR's CI and only runs once it lands on master.🤖 Generated with Claude Code