build(docker): lock core runtime dependencies
This commit is contained in:
@@ -115,3 +115,92 @@ mount content.
|
||||
- The image was built and smoked on Docker Desktop arm64. The chosen official multi-arch base
|
||||
images and Pi package are architecture-neutral at the package level, but amd64 still needs a CI
|
||||
build/smoke before being advertised as verified.
|
||||
|
||||
## Reproducibility Review Fix
|
||||
|
||||
The original image pinned Pi's direct version in the Dockerfile but resolved its transitives at
|
||||
build time, and pip resolved all harness dependencies from ranges. Both paths now consume committed
|
||||
locks.
|
||||
|
||||
### Lock generation
|
||||
|
||||
Pi uses the minimal `docker/pi-runtime/package.json` and its committed npm v3 lock. It was generated
|
||||
with:
|
||||
|
||||
```text
|
||||
npm install --package-lock-only --ignore-scripts --no-audit --no-fund \
|
||||
--prefix docker/pi-runtime
|
||||
```
|
||||
|
||||
The package manifest specifies exact `@earendil-works/pi-coding-agent` version `0.80.3`; a lock
|
||||
inspection confirmed that same resolved package version. Docker installs it with:
|
||||
|
||||
```text
|
||||
npm ci --omit=dev --ignore-scripts --no-audit --no-fund
|
||||
```
|
||||
|
||||
The Python lock was generated directly from the harness production metadata plus one explicit,
|
||||
pinned PEP 517 build-backend input—not from a host `pip freeze`:
|
||||
|
||||
```text
|
||||
uv pip compile harness/pyproject.toml docker/python-runtime/build-requirements.in \
|
||||
--universal \
|
||||
--python-version 3.12 \
|
||||
--no-emit-package tht \
|
||||
--generate-hashes \
|
||||
--custom-compile-command \
|
||||
'uv pip compile harness/pyproject.toml docker/python-runtime/build-requirements.in --universal --python-version 3.12 --no-emit-package tht --generate-hashes --output-file docker/python-runtime/requirements.lock' \
|
||||
--output-file docker/python-runtime/requirements.lock
|
||||
```
|
||||
|
||||
`pytest`, `ruff`, and `testcontainers` are absent. All production direct and transitive packages
|
||||
are exact and hashed. `setuptools==80.9.0` is explicit so the local harness install can use
|
||||
`--no-build-isolation` without an unpinned build-time resolution. Refresh instructions are in
|
||||
`docker/LOCKS.md`.
|
||||
|
||||
### No-cache rebuild and verification
|
||||
|
||||
Final build command:
|
||||
|
||||
```text
|
||||
docker build --no-cache -f docker/core.Dockerfile -t thothii-core:test .
|
||||
```
|
||||
|
||||
Result: exit 0. The logs showed Pi `0.80.3`, Node `v22.19.0`, a hash-enforced Python dependency
|
||||
install, explicit `setuptools==80.9.0`, and a non-isolated local `tht` wheel build. No isolated
|
||||
build-dependency download occurred.
|
||||
|
||||
Fresh runtime checks:
|
||||
|
||||
```text
|
||||
docker run --rm --entrypoint /app/docker/smoke/core-smoke.sh thothii-core:test
|
||||
backend listening on http://127.0.0.1:8787
|
||||
v22.19.0
|
||||
Python 3.12.13
|
||||
core smoke: ok
|
||||
|
||||
docker run --rm thothii-core:test tht --version
|
||||
0.1.0
|
||||
|
||||
/opt/venv/bin/pip check
|
||||
No broken requirements found.
|
||||
```
|
||||
|
||||
An in-container package inspection reconfirmed Pi `0.80.3`. Non-root UID, runtime version floors,
|
||||
doctor's expected concise exit 1/no traceback, `/health`, and arbitrary `tht` routing all passed.
|
||||
|
||||
The full filename containment scan found no `.env`, PEM, private-key, P12, or PFX file in `/app`;
|
||||
`/app/harness/workspaces` remains absent. Image environment and `docker history --no-trunc` were
|
||||
re-inspected and contain only public package/build commands and non-sensitive runtime metadata.
|
||||
|
||||
Final locked image size:
|
||||
|
||||
```text
|
||||
220003986 10001:10001
|
||||
```
|
||||
|
||||
That is **220,003,986 bytes** (about 209.8 MiB), 1,415,022 bytes smaller than the original image.
|
||||
|
||||
Remaining concern: the universal lock is resolved for Python 3.12 and includes hashes/markers for
|
||||
all supported platforms, but only Linux arm64 has been built and smoked locally; amd64 remains a CI
|
||||
verification gate.
|
||||
|
||||
Reference in New Issue
Block a user