Skip to content

Pull base images and reference BUILD_DATE in the package update - #5

Merged
aaaaaaaalex merged 2 commits into
mainfrom
fix/build-pull-and-cache-bust
Sep 30, 2026
Merged

aaaaaaaalex merged 2 commits into
mainfrom
fix/build-pull-and-cache-bust

Conversation

@aaaaaaaalex

@aaaaaaaalex aaaaaaaalex commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

📝 Links

📝 Description

Makes sure the package update in the image actually runs, on a current base, however the image is built.

  • Reference BUILD_DATE in the package update. Docker re-runs a RUN when an ARG declared ahead of it changes, but other builders — including podman, which ci/build-and-push-images.sh uses — need the value used in the instruction itself. The update now echoes it.
  • The local build script pulls base images and passes BUILD_DATE. It reused any local copy of nginx-126:latest without checking the registry and never passed BUILD_DATE, so it could build on a stale base and reuse a cached update.

Not changed: the on-push-main and on-push-release workflows publish to upstream's quay.io/kubev2v, do not run on this fork, and build on fresh runners with no layer cache, so the update already runs there.

🎥 Demo

Built with docker build --pull and run locally:

  • The base is fetched from the registry (lookup 1.1s rather than 0.0s from a local copy) and is the registry's current nginx-126 (build date 2026-09-30).
  • The same BUILD_DATE twice leaves the update cached; a new value makes it re-run.
  • Runs as uid 1001 with no restarts, /var/log/nginx owned by 1001:0, 4.22 loader __load_plugin_entry__("forklift-console-plugin", …), no package updates pending.

The podman script path is untested (podman is not installed here).

📝 CC://

🤖 Generated with Claude Code

aaaaaaaalex and others added 2 commits September 30, 2026 15:03
Docker re-runs a RUN when an ARG declared ahead of it changes, but other
builders need the value used in the instruction itself. Referencing it
makes the update re-run on every build whichever builder is used.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
The podman build reused any local copy of a floating base tag and never
passed BUILD_DATE, so it could build on a stale base and reuse a cached
package update.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 14:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@aaaaaaaalex
aaaaaaaalex merged commit 86567c2 into main Sep 30, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants