fix(docker): Install into an explicit venv instead of the base image layout - #74
Merged
Merged
Conversation
…layout The main branch image build has been failing since the mirrored DHI base images were rebuilt: they moved Python out of `/opt/python` (`sysconfig` now reports `purelib=/usr/lib/python3.13/site-packages`, `scripts=/usr/bin` in both the `-dev` and runtime variants), so the runtime stage's `COPY --from=build /opt/python/...` fails with "not found". Rather than repoint the copy at `/usr`, install into a venv at `/opt/venv` that we own and copy that across. The build no longer depends on an internal layout of the upstream image, so a future base rebuild can't move the target again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Upx9gbisaXaMAwh8ToUQXx
alex-sentry
approved these changes
Sep 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Install the package into a venv at
/opt/venvin the build stage and copy that single directory into the runtime stage, instead of copying Python'ssite-packagesout of the base image's own tree.The main-branch image build has been failing since the mirrored DHI base images were rebuilt:
Nothing in this repo changed — the Dockerfile has been untouched since #67. The base images moved Python out of
/opt/python; confirmed against the images as they are today, both the-devand runtime variants reportsys.executable=/usr/bin/python3,purelib=/usr/lib/python3.13/site-packages,scripts=/usr/bin, and/opt/pythonno longer exists.The same break was fixed in getsentry/sentry-analytics#33 by repointing the copy at
/usr, and in getsentry/reload#353 by switching to a venv. This takes the venv approach — it was the follow-up the sentry-analytics PR called for. Either way the interpreter path in the image changes, so there is no migration cost to picking the one that isn't coupled to an upstream layout we don't control; a future base rebuild can't move the target again.Built locally against the current bases (linux/amd64) and smoke-tested: both
usageaccountant.datadog_fetcher(the defaultENTRYPOINT) andusageaccountant.bigquery_fetcherstart and print their--help, thebigqueryextra imports, and the container still runs asnonroot(uid 65532).One thing worth a reviewer's eye: the interpreter is now at
/opt/venv/bin/python3, not/opt/python/bin/python3. TheENTRYPOINThere is updated, but if any deployment overrides the command with an absolute path — thebigquery_fetcherjob would have to, since theENTRYPOINThardcodesdatadog_fetcher— that override needs updating too. An org-wide code search turned up no such reference outside this repo, but I can't see private deploy config.🤖 Generated with Claude Code
https://claude.ai/code/session_01Upx9gbisaXaMAwh8ToUQXx