Repository navigation
Conversation
Adds DEPLOY_BASE_IMAGES / DEPLOY_BUILD_BASE_IMAGES (runtime=image csv) to the webapp. The deployment initialize response carries the images for the deploy's runtime, and the CLI rewrites the Containerfile to build on them.
🦋 Changeset detectedLatest commit: fdf367a The changes in this PR will be included in the next version bump. This PR includes changesets to release 28 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📜 Recent review details
WalkthroughThe webapp parses per-runtime deploy and build image settings and returns matching images in deployment responses. Deployment initialization rejects native builds and clients that do not declare support when custom images are required. The CLI applies returned images when generating Containerfiles for standard deployments and rejects bundle deployments that require custom images. Containerfile generation uses runtime defaults when image fields are not configured. The changes also add API schemas, tests, self-hosting documentation, and release notes. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to Unset settings remain safe, and deployments without a configured runtime image continue using the CLI defaults. No actionable merge risk was identified in the reviewed changes. Security Architecture Review
Pre-merge checks |
|
Validate DEPLOY_BASE_IMAGES and DEPLOY_BUILD_BASE_IMAGES when the webapp starts: entries must name a known runtime and a digest-pinned image, with no duplicate runtimes. Invalid values fail startup instead of silently falling back to the published images. Honor the build-stage image when build extensions add image instructions: the build stage is created from the configured build image and the instructions are replayed on it, instead of being derived from the base with a toolchain install. Apply the server's base images on --from-bundle deploys by regenerating the bundle's Containerfile, and print the images in the deploy output. Docs: split the Node and Bun base image requirements, describe the validation rules and the paths the setting applies to.
Reject initialize-deployment requests from CLIs that cannot apply the instance's base images, so the setting is enforced rather than advisory. The CLI declares support on the paths that can honour it, and fails with a clear error on --native-build and --local-bundle, which cannot. Return the base images on the get-deployment response as well, so deploys that attach to an existing deployment build on them too. Validate image refs with one shared schema in core on both the server and the CLI: a single token pinned by digest. Reject the runtime alias node in favour of the concrete runtime keys, and report every invalid env entry in one error at startup. Build the custom build stage with the same customization block as the base stage, so instructions and package installs run in the same order.
…e set Native builds and local bundles cannot apply the instance's base images and never declared support, so the server was rejecting them with the message meant for outdated CLIs. Reject them with their own message on the server and drop the CLI-side checks that could never run. Docs: describe what the build stage uses without a build image entry, note that --from-bundle rewrites the Containerfile inside the bundle directory, and shorten the env table rows.
# Conflicts: # apps/webapp/app/env.server.ts
93465d8
Closes #5004
Lets a self-hosted operator require custom base images for every deploy to their instance, such as FIPS-validated or hardened Node images. Cloud never sets the variables, so nothing changes there.
baseImages; the CLI rewrites the Containerfile with them. A configured build image is also used when a project hasimage.instructions.--native-build,--local-bundleand--from-bundledeploys, are rejected with a clear error.Testing
apps/webapp/test/deployBaseImages.test.tsandpackages/cli-v3/src/deploy/buildImage.test.tscover the parsing, rejection and Containerfile cases. Typecheck, format and lint are clean.