From 78c039a845d9bb38531839eb318967265d3ae991 Mon Sep 17 00:00:00 2001 From: JonJagger Date: Thu, 3 Sep 2026 15:43:18 +0100 Subject: [PATCH] Stop tagging the differ image :latest Nothing reads it. docker-compose.yml names the image by ${CYBER_DOJO_DIFFER_IMAGE}:${CYBER_DOJO_DIFFER_TAG}, the short sha, and no sibling repo names cyberdojo/differ:latest. Nothing passes it as cache_from either, so the comments calling it the image-layer build cache described nothing. Keeping it had a cost. remove_all_but_current exempted :latest, so the build it last pointed at survived every later build's cleanup, and the tag moving to each new build left the previous image behind untagged. Removing the exemption lets those go, and this build stays protected by its own sha tag, which is what names it everywhere. cyberdojo/differ: stays: local development names the differ image with the dockerhub name the versioner env-vars carry rather than the ECR one. --- bin/build_image.sh | 10 ++++------ bin/lib.sh | 8 +++----- 2 files changed, 7 insertions(+), 11 deletions(-) diff --git a/bin/build_image.sh b/bin/build_image.sh index a2183920..a3169a8c 100755 --- a/bin/build_image.sh +++ b/bin/build_image.sh @@ -80,14 +80,12 @@ build_image() fi if [ "${type}" == 'server' ]; then - # Create latest tag for image build cache - docker tag "${image_name}" "${CYBER_DOJO_DIFFER_IMAGE}:latest" # Tag image-name for local development where differs name comes from echo-versioner-env-vars docker tag "${image_name}" "cyberdojo/differ:${CYBER_DOJO_DIFFER_TAG}" - # After tagging, so removing an earlier build's tags takes its last tag with - # them and the image itself goes, rather than being left dangling when - # :latest moves to this build. check_args rejects 'server' inside CI, so the - # image pulled by the 'Download docker image' CI job is never at risk here. + # After tagging, so this build is protected by its own tag, and removing an + # earlier build's tags takes its last tag with them and the image itself + # goes. check_args rejects 'server' inside CI, so the image pulled by the + # 'Download docker image' CI job is never at risk here. remove_old_images echo echo " echo CYBER_DOJO_DIFFER_SHA=${CYBER_DOJO_DIFFER_SHA}" diff --git a/bin/lib.sh b/bin/lib.sh index 7fac321a..d3027caf 100644 --- a/bin/lib.sh +++ b/bin/lib.sh @@ -103,9 +103,8 @@ remove_old_images() remove_all_but_current "${dil}" cyberdojo/differ } -# Keeps :latest, which preserves the image-layer build cache, and this commit's -# tag, which names the build just made. Every older tag goes, and an earlier -# build whose last tag was one of those goes with it. +# Keeps this commit's tag, which names the build just made. Every older tag +# goes, and an earlier build whose last tag was one of those goes with it. remove_all_but_current() { local -r docker_image_ls="${1}" @@ -115,8 +114,7 @@ remove_all_but_current() local tagged_name for tagged_name in $(echo "${docker_image_ls}" | grep "${name}:" || true) do - if [ "${tagged_name}" != "${name}:latest" ] \ - && [ "${tagged_name}" != "${name}:${CYBER_DOJO_DIFFER_TAG}" ]; then + if [ "${tagged_name}" != "${name}:${CYBER_DOJO_DIFFER_TAG}" ]; then docker image rm --force "${tagged_name}" || echo " skipped ${tagged_name} (in use)" fi done