Commit 7447758
authored
feat(dockerfile)!: remove venv, install pip packages into base Python (#59)
* feat(dockerfile)!: remove venv, install pip packages into base Python
Pip packages used to be installed into /opt/venv, which was created
with --system-site-packages. On base images that already shipped a
Python environment (pytorch/pytorch, python:3.11-slim, etc.) pip's
dependency resolver still re-downloaded packages like torch into the
venv, duplicating gigabytes of content. The --system-site-packages
flag only helps at import time, not at install time.
Install pip packages directly into whatever Python is on PATH. On
images with a pre-existing Python environment (conda, python images)
pip sees existing packages and skips them. On Debian/Ubuntu images
where pip would otherwise be blocked by PEP 668, the marker file at
/usr/lib/python*/EXTERNALLY-MANAGED is removed once before the first
pip step. PEP 668 is a host-system protection against apt/pip
conflicts; it does not apply inside containers.
BREAKING CHANGE: /opt/venv no longer exists in generated Dockerfiles.
ENV VIRTUAL_ENV and the /opt/venv/bin PATH prefix are gone. Scripts
that explicitly reference /opt/venv/bin/python or similar paths must
be updated to use /usr/bin/python3, /opt/conda/bin/python, or
whichever Python the chosen base image provides.
The runtime user no longer has write access to pip-installed
packages by default. Interactive 'pip install' inside a running
container now requires either 'pip install --user foo' (installs to
the user's home) or running the container with '--user 0' to
temporarily run as root.
* test(dockerfile): cover pip marker removal and no-venv behaviour
* docs: remove venv mention from features list
* fix(dockerfile): flatten create_user shell structure for shellcheck
Replace nested 'else; if' patterns with 'elif' and '||' short-circuits
to eliminate hadolint SC1075 errors on generated Dockerfiles. Also
suppress DL4006 on the user-creation RUN: the pipe's failure semantics
are intentional (getent failure means 'no such user', which is the
branch we want to take) and pipefail would be a no-op.
Resolves shellcheck-flagged errors in generated Dockerfiles across
all projects. No behavioural change.1 parent d7bbc07 commit 7447758
5 files changed
Lines changed: 106 additions & 234 deletions
File tree
- src/container_magic
- generators
- templates
- tests/unit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
71 | | - | |
| 71 | + | |
72 | 72 | | |
73 | 73 | | |
74 | 74 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
178 | 178 | | |
179 | 179 | | |
180 | 180 | | |
181 | | - | |
| 181 | + | |
182 | 182 | | |
183 | 183 | | |
184 | 184 | | |
| |||
190 | 190 | | |
191 | 191 | | |
192 | 192 | | |
193 | | - | |
| 193 | + | |
194 | 194 | | |
195 | 195 | | |
196 | 196 | | |
| |||
202 | 202 | | |
203 | 203 | | |
204 | 204 | | |
205 | | - | |
| 205 | + | |
206 | 206 | | |
207 | 207 | | |
208 | 208 | | |
| |||
235 | 235 | | |
236 | 236 | | |
237 | 237 | | |
238 | | - | |
| 238 | + | |
239 | 239 | | |
240 | | - | |
| 240 | + | |
241 | 241 | | |
242 | | - | |
243 | | - | |
244 | | - | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
245 | 245 | | |
246 | 246 | | |
247 | 247 | | |
| |||
307 | 307 | | |
308 | 308 | | |
309 | 309 | | |
310 | | - | |
| 310 | + | |
311 | 311 | | |
312 | 312 | | |
313 | 313 | | |
| |||
369 | 369 | | |
370 | 370 | | |
371 | 371 | | |
372 | | - | |
| 372 | + | |
373 | 373 | | |
374 | 374 | | |
375 | 375 | | |
| |||
392 | 392 | | |
393 | 393 | | |
394 | 394 | | |
395 | | - | |
| 395 | + | |
396 | 396 | | |
397 | 397 | | |
398 | | - | |
| 398 | + | |
399 | 399 | | |
400 | 400 | | |
401 | | - | |
| 401 | + | |
402 | 402 | | |
403 | 403 | | |
404 | 404 | | |
| |||
408 | 408 | | |
409 | 409 | | |
410 | 410 | | |
411 | | - | |
| 411 | + | |
412 | 412 | | |
413 | 413 | | |
414 | | - | |
| 414 | + | |
415 | 415 | | |
416 | 416 | | |
417 | 417 | | |
| |||
425 | 425 | | |
426 | 426 | | |
427 | 427 | | |
428 | | - | |
429 | | - | |
430 | | - | |
431 | | - | |
432 | | - | |
433 | | - | |
434 | | - | |
435 | | - | |
436 | | - | |
437 | | - | |
438 | | - | |
439 | | - | |
440 | | - | |
441 | | - | |
442 | | - | |
443 | 428 | | |
444 | 429 | | |
445 | 430 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
37 | 38 | | |
38 | 39 | | |
39 | | - | |
40 | | - | |
| 40 | + | |
| 41 | + | |
41 | 42 | | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
42 | 48 | | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
58 | 52 | | |
59 | | - | |
60 | 53 | | |
61 | 54 | | |
62 | 55 | | |
63 | 56 | | |
64 | | - | |
65 | | - | |
| 57 | + | |
| 58 | + | |
66 | 59 | | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
67 | 64 | | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | | - | |
72 | | - | |
73 | | - | |
74 | | - | |
75 | | - | |
76 | | - | |
77 | | - | |
78 | | - | |
79 | | - | |
80 | | - | |
81 | | - | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
82 | 68 | | |
83 | | - | |
84 | 69 | | |
85 | 70 | | |
86 | 71 | | |
| |||
122 | 107 | | |
123 | 108 | | |
124 | 109 | | |
125 | | - | |
| 110 | + | |
126 | 111 | | |
127 | 112 | | |
128 | 113 | | |
129 | | - | |
130 | | - | |
131 | | - | |
132 | | - | |
133 | | - | |
134 | | - | |
135 | | - | |
136 | | - | |
137 | | - | |
138 | | - | |
139 | | - | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
140 | 120 | | |
141 | 121 | | |
142 | 122 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
308 | 308 | | |
309 | 309 | | |
310 | 310 | | |
311 | | - | |
| 311 | + | |
312 | 312 | | |
313 | 313 | | |
314 | 314 | | |
| |||
324 | 324 | | |
325 | 325 | | |
326 | 326 | | |
327 | | - | |
| 327 | + | |
328 | 328 | | |
329 | 329 | | |
330 | | - | |
331 | | - | |
| 330 | + | |
| 331 | + | |
0 commit comments