From 1b81310847d69ca3fb7df66f7c50dd05cf520e2e Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Tue, 28 Jul 2026 13:01:35 -0400 Subject: [PATCH] fix(docker): build the image from uv.lock too MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The other half of #2194. The runtime stage did `COPY pyproject.toml .` + `pip install .` and never copied uv.lock at all, so the SHIPPED IMAGE resolved its own dependency set — independently of CI and of the lock. CI could be green on one set of versions while the published image ran another, which makes a green run evidence about the tests and not about the artifact. Now: install uv, sync deps from the lock, then sync the project. Split into two syncs so the dependency layer caches on any build that doesn't touch the lock — the same shape CI uses, so image and CI can no longer disagree. `uv sync` installs into /app/.venv rather than the system interpreter, so PATH picks it up for the alembic + hypercorn CMD. The project stays editable, which keeps /app/src authoritative exactly as PYTHONPATH and the frontend-dist copy into src/scribe/static/ already assume. Not built locally (rules #10/#12) — the dev build job verifies it, and `main` already carries a working :latest, so a break here can't strand a deploy. --- Dockerfile | 23 ++++++++++++++++++++--- 1 file changed, 20 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 4c5e8c9..ffe1e79 100644 --- a/Dockerfile +++ b/Dockerfile @@ -12,10 +12,27 @@ RUN npm run build FROM python:3.14-slim AS runtime WORKDIR /app -COPY pyproject.toml . -COPY src/ src/ +# Installed from uv.lock, exactly like CI (issue #2194). This used to be +# `COPY pyproject.toml .` + `pip install .`, which never even copied the lock: +# the shipped image resolved its own dependency set, so CI could be green on one +# set of versions while the published image ran another. On 2026-07-28 that +# class of drift turned `main` red when mcp 2.0.0 shipped mid-session. RUN --mount=type=cache,target=/root/.cache/pip \ - pip install . + pip install --no-cache-dir uv + +# Dependencies before source, so the expensive layer is cached on every build +# that doesn't change the lock. +COPY pyproject.toml uv.lock ./ +RUN --mount=type=cache,target=/root/.cache/uv \ + uv sync --locked --no-dev --no-install-project + +COPY src/ src/ +RUN --mount=type=cache,target=/root/.cache/uv \ + uv sync --locked --no-dev + +# uv sync installs into a project venv rather than the system interpreter, so +# alembic and hypercorn in CMD have to be found there. +ENV PATH="/app/.venv/bin:$PATH" COPY --from=build-frontend /build/dist/ src/scribe/static/ COPY alembic.ini .