install deps in one layer to fix cache-mount deploy failure #77

Sammanfogat
supernaut sammanfogade 3 incheckningar från fix/containerfile-deps-cache-mount in i main 2026-07-21 06:43:55 +00:00
Ägare

Fixes the broken deploy (build-and-push failing at "Install dependencies", while local podman build on main succeeds).

Root cause

The build stage split deps into two RUNs sharing a BuildKit cache mount:

RUN --mount=type=cache,target=/pnpm/store pnpm fetch
RUN --mount=type=cache,target=/pnpm/store pnpm install --frozen-lockfile --prod --offline

The /pnpm/store cache mount is not part of the image layer. With the deploy's registry layer cache (--cache-from/--cache-to), if the pnpm fetch layer is a cache hit it's skipped → the store mount is empty; a following pnpm install --offline that's a cache miss then installs against an empty store → fails. A partial cache — a --cache-to push interrupted mid-way when the fail2ban caddy-auth jail banned the runner on the registry /v2 handshake (bitborg-infra#127) — leaves exactly fetch-hit + install-miss. Local builds don't import the registry cache, so fetch runs and it works.

Fix

Collapse to a single online install RUN using the cache mount:

RUN --mount=type=cache,target=/pnpm/store pnpm install --frozen-lockfile --prod

The deps layer is now self-contained (fetch+install together), so a layer hit reuses the built node_modules and a miss fetches+installs in one step — no empty-store failure mode. Lockfile unchanged; --prod + --frozen-lockfile preserved.

Also needed (ops, one-time)

Delete the corrupt bitborg-web/cache registry package so the next build repopulates a clean cache. After that + this merge, the deploy is robust against interrupted cache pushes.

Verify with a local podman build -f Containerfile . on this branch before merge.

**Fixes the broken deploy** (`build-and-push` failing at "Install dependencies", while local `podman build` on `main` succeeds). ## Root cause The build stage split deps into two RUNs sharing a BuildKit cache mount: ``` RUN --mount=type=cache,target=/pnpm/store pnpm fetch RUN --mount=type=cache,target=/pnpm/store pnpm install --frozen-lockfile --prod --offline ``` The `/pnpm/store` cache mount is **not** part of the image layer. With the deploy's registry layer cache (`--cache-from`/`--cache-to`), if the `pnpm fetch` layer is a cache **hit** it's skipped → the store mount is empty; a following `pnpm install --offline` that's a cache **miss** then installs against an empty store → **fails**. A **partial** cache — a `--cache-to` push interrupted mid-way when the fail2ban `caddy-auth` jail banned the runner on the registry `/v2` handshake (bitborg-infra#127) — leaves exactly `fetch`-hit + `install`-miss. Local builds don't import the registry cache, so `fetch` runs and it works. ## Fix Collapse to a single online install RUN using the cache mount: ``` RUN --mount=type=cache,target=/pnpm/store pnpm install --frozen-lockfile --prod ``` The deps layer is now self-contained (fetch+install together), so a layer hit reuses the built `node_modules` and a miss fetches+installs in one step — no empty-store failure mode. Lockfile unchanged; `--prod` + `--frozen-lockfile` preserved. ## Also needed (ops, one-time) Delete the corrupt `bitborg-web/cache` registry package so the next build repopulates a clean cache. After that + this merge, the deploy is robust against interrupted cache pushes. Verify with a local `podman build -f Containerfile .` on this branch before merge.
supernaut lade till 2 incheckningar 2026-07-21 06:35:13 +00:00
The build stage split deps into `pnpm fetch` then `pnpm install --offline`,
both sharing a --mount=type=cache pnpm store. That store is NOT in the image
layer, so with the deploy's registry layer cache (--cache-from/--cache-to) a
cache HIT on the fetch layer skips it (empty store), and a MISS on the install
layer then runs --offline against an empty store → 'Install dependencies' fails.
A partial cache (a --cache-to push interrupted by the fail2ban /v2 ban, see
gitborg-infra#127) produced exactly fetch-hit + install-miss, breaking CI while
local builds (no registry cache) worked. Collapse to one online install RUN.

Immediate ops fix is to delete the corrupt gitborg-web/cache registry package;
this prevents recurrence.
supernaut lade till 1 incheckning 2026-07-21 06:36:42 +00:00
chore: update lockfile
Alla kontroller lyckades
ci / ci (pull_request) Successful in 53s
8d814d942a
supernaut sammanfogade incheckning c462c31163 till main 2026-07-21 06:43:55 +00:00
supernaut tog bort grenen fix/containerfile-deps-cache-mount 2026-07-21 06:43:56 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!77
Ingen beskrivning angiven.