-
Notifications
You must be signed in to change notification settings - Fork 733
Adding document analyzing CI/dockerfile #3940
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
30881d4 to
91edb07
Compare
| golang:${GO_VERSION}-bookworm => hack-build-base-debian | ||
| golang:${GO_VERSION}-alpine => hack-build-base | ||
| ubuntu:${UBUNTU_VERSION} => hack-base | ||
| ``` |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
( I once had a BuildKit PR to allow injecting a hook to update CAs, but it wasn't accepted 😞 moby/buildkit#4669 Still thinking about an alternative... )
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah.
I always end-up doing some ridiculous monkeying for that kind of stuff (same for overloading apt config, netrc, etc). Deviating the base like here, or using secrets (secrets is neat, but forces you to have additional --mount for every RUN, which is highly unpractical).
I just think the Dockerfile as a front-end is not aging too well... things like Dagger or Earthly are kinda touching on this overall question (eg: of a better frontend for developer that leverages the buildkit DAG).
But then, Dockerfile is everywhere now, so... something "new" comes up with a price...
|
Let's keep this PR open a little while. I'll add more measurements. Marking draft. |
c6c16f1 to
0331f8f
Compare
Signed-off-by: apostasie <spam_blackhole@farcloser.world>
0331f8f to
e52580e
Compare
|
@AkihiroSuda if you are fine with it, let's merge this. I would like to have a baseline merged in for the ongoing CI build work. |
AkihiroSuda
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
Title says all.
Sharing audit notes in a new document (we can also just slap this into an issue if it is better - I don't mind either way).
I am rewriting the Dockerfile now and will provide an updated audit to see if we have measurable improvements.