Skip to content

Reuse the registry cache whatever the umask - #449

Open
lyrixx wants to merge 1 commit into
mainfrom
build-context-permissions
Open

lyrixx wants to merge 1 commit into
mainfrom
build-context-permissions

Conversation

@lyrixx

@lyrixx lyrixx commented Oct 6, 2026

Copy link
Copy Markdown
Member

Refs #430

The build cache depends on the permissions of the files of the build context. A checkout made with a 002 umask (the default one of many Linux distributions) gets 664 files and 775 directories, instead of the 644 / 755 ones of the CI checkout. So it never reuses the registry cache pushed by the CI: the COPY php/mods-available/ of php-base misses, then every following step is rebuilt.

castor docker:build and castor docker:push now give the files tracked by git their git permissions (644 or 755, and 755 for their directories) before building. Untracked files (e.g. the private key of the local certificates) are left untouched, and so are the additional build contexts (the application of the production images).

COPY --chmod doesn't help: the cache key is computed on the source files, before the chmod.

Tests

Local builds of frontend and builder with a fresh buildx builder (no local cache), importing the registry caches of docker-starter:

Checkout Cached steps Duration
umask 022 (like the CI) everything 15s
umask 002, before this PR nothing after php-base 4/6, 6 runs out of 6 88s
umask 002, COPY --chmod=u=rwX,go=rX same —
umask 002, with this PR everything 12s

The private key of the certificates (600, untracked) keeps its permissions.

The build cache depends on the permissions of the files of the build
context: a checkout made with a 002 umask (the default one of many Linux
distributions) gets 664 files instead of the 644 ones of the CI, and
never reuses the registry cache it pushes. The very first COPY of
php-base misses, then every following step is rebuilt.

COPY --chmod does not help: the cache key is computed on the source
files, before the chmod.

"castor docker:build" and "castor docker:push" now give the files tracked
by git their git permissions (644 or 755, and 755 for their directories)
before building. Untracked files (e.g. the certificates private key) are
left untouched.
@lyrixx
lyrixx requested a review from pyrech October 8, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant