Conversation
The base stage installed gcc, g++, libffi-dev and python3-dev to build C extensions, and they stayed in both the full and lite images: 290 MB installed. Nothing is compiled any more. cffi, gevent, greenlet and zope-interface all ship cp314 manylinux wheels for amd64 and arm64, and the sdist-only packages in uv.lock are pure Python. python3-dev also pulled Debian's libpython3.13 into a Python 3.14 image.
`COPY . .` put the whole build context into /app, including tests/, docs/ and developer-tool caches. .dockerignore now excludes them. It applies to every stage, so src/ can't be listed there (frontend-builder needs it); the final stages remove it after the built dist is copied. data/ stays, since languages.py reads data/book-languages.json at runtime, and genDebug.sh stays because the final stage chmod +x's it. Also drops the venv's pip, which uv seeded alongside the system pip. Nothing installs at runtime. setuptools stays: deps still import pkg_resources. Extracted from DrNgo/shelfmark-fork@075caff and re-applied onto upstream v1.4.0 by Rob Martin, without that commit's ffmpeg and Mesa/LLVM removals.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
While checking why each build took so much disk on my server, I looked at what's actually in the runtime image. A good share of it is there for the build and never used after.
The C toolchain. The base stage installs
gcc,g++,libffi-devandpython3-devfor building C extensions, and they stay in both the full and lite images, which is 290 MB installed. Nothing gets compiled any more. Every compiled dependency inuv.lock(cffi, gevent, greenlet, zope-interface) ships a cp314 manylinux wheel for both amd64 and arm64, and the packages that only have an sdist are pure Python.python3-devwas also pulling Debian'slibpython3.13into a 3.14 image.The build context.
COPY . .puts the whole context into/app, sotests/,docs/and the frontend source ship too..dockerignorenow leaves out the trees nothing reads at runtime.src/can't go in.dockerignorebecause the frontend-builder stage needs it, so both final stages remove it after the built dist is copied. The venv's ownpipgoes as well, since uv seeds one and nothing installs at runtime. This part is @DrNgo's work from his fork, and the commit carries his name.Measured by building both targets on native amd64 and arm64 runners:
Compressed, the full image goes from 617 MB to 504 MB on amd64.
On both architectures the image builds, reaches healthy, and Chromium starts the same way the bypasser starts it (xvfb,
_get_browser_args()). The Python suite passes too. It's also running on my own install now.If a dependency ever needs compiling again, the clean fix is a builder stage that builds the wheel and copies it in, rather than putting the toolchain back in the runtime image. Happy to add that now if you'd rather have it in place.