2.3 KiB
Core runtime dependency locks
The core image consumes committed, production-only locks for Pi and the Python harness. Refresh them from the repository root after intentionally changing the corresponding direct dependencies.
Pi runtime
Keep the exact Pi version in docker/pi-runtime/package.json, then regenerate its npm lock:
npm install --package-lock-only --ignore-scripts --no-audit --no-fund \
--prefix docker/pi-runtime
The image installs this tree with npm ci --omit=dev; do not replace it with an unpinned global
install.
Python runtime
Install uv and compile the harness's production dependencies for
Python 3.12. --universal retains platform markers and hashes for a cross-platform resolution;
the dev extra is deliberately absent.
uv pip compile harness/pyproject.toml docker/python-runtime/build-requirements.in \
--universal \
--python-version 3.12 \
--no-emit-package tht \
--generate-hashes \
--custom-compile-command \
'uv pip compile harness/pyproject.toml docker/python-runtime/build-requirements.in --universal --python-version 3.12 --no-emit-package tht --generate-hashes --output-file docker/python-runtime/requirements.lock' \
--output-file docker/python-runtime/requirements.lock
The small input file pins the harness's PEP 517 build backend as well; it is not derived from a
host environment. The image installs the resulting lock with pip's --require-hashes, then
installs the local tht project with --no-deps --no-build-isolation. This prevents both project
metadata and an isolated build environment from resolving unpinned packages.
Base images
Every FROM uses an exact tag plus a multi-platform manifest-list digest. To update one:
- Choose an exact patch tag that publishes both
linux/amd64andlinux/arm64. - Inspect it with
docker buildx imagetools inspect <tag>. - Replace both the human-readable tag and
@sha256:...digest. - Run
./scripts/verify-container-images.shand the Compose smoke. - Review the generated inventory under
.artifacts/container-images/.
The digest freezes image layers, but apt-get update and apk add still consume mutable package
repositories during a no-cache rebuild. Full OS-package immutability would require Debian/Alpine
snapshot repositories and is not claimed by this deployment.