Repository navigation
feat(agent): refresh agent CLIs on docker build --force and flag stale images - #70
Merged
Merged
Conversation
…e images `agent docker build --force` replayed Docker's layer cache, which keys a RUN step on its command text, so the rebuilt image kept the old Claude Code and Codex binaries. A forced build now passes --pull and a fresh AGENT_CLI_CACHEBUST build arg (declared just above the install step, so the apt layer stays cached). Since the image pins both CLIs, also surface when it goes stale: `agent docker doctor` reports the image's age and the Claude Code/Codex versions inside it, and `agent run` prints a rebuild hint once the default image is older than 14 days.
A cached rebuild over an existing image re-tagged :latest to the first cached install layer, undoing a `agent docker build --force` on every test run with Docker available. Fresh CI runners still build it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
agent docker build --forcedidn't actually update Claude Code or Codex. It ran a plaindocker build, and Docker caches aRUNstep by its command text, not by what the installer would download today, so the install layer was replayed from cache. Since the image pins both CLIs (DISABLE_AUTOUPDATER=1, read-only install tree), there was no way to upgrade them short ofdocker rmi+ pruning the build cache.Changes
--forcenow refreshes the image--pullso the base image (and its OS patches) is re-resolved.AGENT_CLI_CACHEBUSTbuild arg. TheARGis declared just above the Claude Code/Codex install step, so only that step onward re-runs and the apt layer stays cached.--pullonly (they don't declare the arg).agent runis unchanged.Stale images are now visible
agent docker doctorshows the default image's age and the Claude Code/Codex versions inside it (read via a throwaway--network nonecontainer).--jsongainsdefault_image_created_at,default_image_stale,claude_code_version,codex_version. Staleness doesn't affectready/ the exit code.agent runprints a one-line stderr hint when the agent runs from the default image and it's older than 14 days. Onedocker image inspect, no container start; suppressed by--silent; not shown for custom-image profiles.Verification
agent docker build --forceon a real image: Claude Code 2.1.292 → 2.1.295, Codex 0.160.1 → 0.162.0; the apt layer stayedCACHED.agent docker doctorthen reportsbuilt today (Claude Code 2.1.295, Codex 0.162.0).ARGplacement in the Dockerfile, age formatting, the 14-day threshold, version parsing.cargo fmt --checkclean,cargo testpasses; no new clippy warnings.Test fix
sandbox_image_lifecyclenow builds the default image only when it's missing. It used to do a cached rebuild every run, which re-tagged a developer's local:latestback to the first cached install layer and silently undid--force. Fresh CI runners still exercise the real build.