From 224cc3081929a740bb8f193a751c0efe8434ec79 Mon Sep 17 00:00:00 2001 From: Antoine James Tournepiche Date: Tue, 15 Sep 2026 20:03:43 +0200 Subject: [PATCH 1/2] ci: cache Docker layers and Poetry dependencies Builds re-did every step on each run: the full apt/pip setup and a complete `poetry install`, both of them twice because the image is built for amd64 and arm64. - Import and export the GitHub Actions cache in the Docker build job, and cache the Poetry virtualenv in the lint job. - Install dependencies before copying the source, so the install layer is rebuilt only when the lockfile changes. - Mount a per-architecture BuildKit cache for Poetry's downloads. - Drop gcc: every dependency ships prebuilt wheels for both target architectures, so the apt layer is no longer needed (479MB -> 313MB). A multi-arch build takes 203s with an empty cache and 16s once the cache is imported. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/ci.yml | 7 +++++-- Dockerfile | 22 +++++++++------------- 2 files changed, 14 insertions(+), 15 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a1f73ec..0a8cff9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,12 +12,13 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install Poetry + run: pipx install poetry - name: Set up Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.13" - - name: Install Poetry - run: pipx install poetry + cache: poetry - name: Check poetry.lock is up to date run: poetry check --lock - name: Install dependencies @@ -44,3 +45,5 @@ jobs: push: false tags: dj4h:ci-check platforms: linux/amd64,linux/arm64 + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/Dockerfile b/Dockerfile index 03f60bd..3996567 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,26 +1,22 @@ +# syntax=docker/dockerfile:1 FROM python:3.13-slim -# Update the system -RUN apt update && apt upgrade -y - -# Install the required packages -RUN apt install -y --no-install-recommends gcc && apt clean +ARG TARGETPLATFORM # Install poetry -RUN pip install poetry==2.2.1 +RUN pip install --no-cache-dir poetry==2.2.1 WORKDIR /app -COPY ./ /app - -RUN sed -i 's/\r$//' entrypoint.sh +# Install the dependencies first, so this layer is only rebuilt when the lockfile changes +COPY pyproject.toml poetry.lock poetry.toml /app/ -# Disable in-project venvs -RUN poetry config virtualenvs.in-project false +RUN --mount=type=cache,target=/root/.cache/pypoetry,id=poetry-${TARGETPLATFORM},sharing=locked \ + poetry install --without dev -RUN poetry install --without dev +COPY ./ /app -RUN chmod +x entrypoint.sh +RUN sed -i 's/\r$//' entrypoint.sh && chmod +x entrypoint.sh # Run the application CMD ["/app/entrypoint.sh"] From 3c1d16b741ee6fe2b2be6d3e338db0c848a3ea14 Mon Sep 17 00:00:00 2001 From: Antoine James Tournepiche Date: Tue, 15 Sep 2026 21:20:03 +0200 Subject: [PATCH 2/2] build: pin the base image by exact version and digest The floating `python:3.13-slim` tag moved silently: nothing recorded when the base image changed, and the same commit could build a different image. Pinning makes builds reproducible and turns each base update into a reviewable pull request. The tag names the exact version and Debian suite alongside the digest so the two agree: a Python patch bump reads as 3.13.15 -> 3.13.16 in the diff, and a move to a new Debian suite has to rewrite `-trixie` rather than arriving as an opaque digest change. Dependabot only compares tags sharing the same suffix, so `-slim-trixie` keeps tracking its own variant; a digest with no tag would be tracked against `python:latest`. Co-Authored-By: Claude Opus 5 (1M context) --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 3996567..dd7c6cb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # syntax=docker/dockerfile:1 -FROM python:3.13-slim +FROM python:3.13.15-slim-trixie@sha256:9d2e5553305c7c7b0097999bb17187c69b921ccd6bc9d40e4bb5ebe652c00285 ARG TARGETPLATFORM