Skip to content

fix(docker): Install into an explicit venv instead of the base image layout - #74

Merged
alex-sentry merged 1 commit into
mainfrom
fix/dhi-python-venv
Sep 10, 2026
Merged

alex-sentry merged 1 commit into
mainfrom
fix/dhi-python-venv

Conversation

@oioki

@oioki oioki commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

Install the package into a venv at /opt/venv in the build stage and copy that single directory into the runtime stage, instead of copying Python's site-packages out of the base image's own tree.

The main-branch image build has been failing since the mirrored DHI base images were rebuilt:

failed to compute cache key: failed to calculate checksum of ref ...:
"/opt/python/lib/python3.13/site-packages": not found

Nothing in this repo changed — the Dockerfile has been untouched since #67. The base images moved Python out of /opt/python; confirmed against the images as they are today, both the -dev and runtime variants report sys.executable=/usr/bin/python3, purelib=/usr/lib/python3.13/site-packages, scripts=/usr/bin, and /opt/python no longer exists.

The same break was fixed in getsentry/sentry-analytics#33 by repointing the copy at /usr, and in getsentry/reload#353 by switching to a venv. This takes the venv approach — it was the follow-up the sentry-analytics PR called for. Either way the interpreter path in the image changes, so there is no migration cost to picking the one that isn't coupled to an upstream layout we don't control; a future base rebuild can't move the target again.

Built locally against the current bases (linux/amd64) and smoke-tested: both usageaccountant.datadog_fetcher (the default ENTRYPOINT) and usageaccountant.bigquery_fetcher start and print their --help, the bigquery extra imports, and the container still runs as nonroot (uid 65532).

One thing worth a reviewer's eye: the interpreter is now at /opt/venv/bin/python3, not /opt/python/bin/python3. The ENTRYPOINT here is updated, but if any deployment overrides the command with an absolute path — the bigquery_fetcher job would have to, since the ENTRYPOINT hardcodes datadog_fetcher — that override needs updating too. An org-wide code search turned up no such reference outside this repo, but I can't see private deploy config.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Upx9gbisaXaMAwh8ToUQXx

…layout

The main branch image build has been failing since the mirrored DHI base
images were rebuilt: they moved Python out of `/opt/python` (`sysconfig`
now reports `purelib=/usr/lib/python3.13/site-packages`, `scripts=/usr/bin`
in both the `-dev` and runtime variants), so the runtime stage's
`COPY --from=build /opt/python/...` fails with "not found".

Rather than repoint the copy at `/usr`, install into a venv at `/opt/venv`
that we own and copy that across. The build no longer depends on an
internal layout of the upstream image, so a future base rebuild can't move
the target again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Upx9gbisaXaMAwh8ToUQXx
@alex-sentry
alex-sentry merged commit d7f527e into main Sep 10, 2026
13 of 14 checks passed
@alex-sentry
alex-sentry deleted the fix/dhi-python-venv branch September 10, 2026 12:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants