install deps in one layer to fix cache-mount deploy failure #77
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!77
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/containerfile-deps-cache-mount"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Fixes the broken deploy (
build-and-pushfailing at "Install dependencies", while localpodman buildonmainsucceeds).Root cause
The build stage split deps into two RUNs sharing a BuildKit cache mount:
The
/pnpm/storecache mount is not part of the image layer. With the deploy's registry layer cache (--cache-from/--cache-to), if thepnpm fetchlayer is a cache hit it's skipped → the store mount is empty; a followingpnpm install --offlinethat's a cache miss then installs against an empty store → fails. A partial cache — a--cache-topush interrupted mid-way when the fail2bancaddy-authjail banned the runner on the registry/v2handshake (bitborg-infra#127) — leaves exactlyfetch-hit +install-miss. Local builds don't import the registry cache, sofetchruns and it works.Fix
Collapse to a single online install RUN using the cache mount:
The deps layer is now self-contained (fetch+install together), so a layer hit reuses the built
node_modulesand a miss fetches+installs in one step — no empty-store failure mode. Lockfile unchanged;--prod+--frozen-lockfilepreserved.Also needed (ops, one-time)
Delete the corrupt
bitborg-web/cacheregistry package so the next build repopulates a clean cache. After that + this merge, the deploy is robust against interrupted cache pushes.Verify with a local
podman build -f Containerfile .on this branch before merge.