Skip to content

Reproducible builds: lock files, pinned images, slim CUDA image - #52

Merged
joeljose merged 1 commit into
mainfrom
build/reproducible
Sep 29, 2026
Merged

joeljose merged 1 commit into
mainfrom
build/reproducible

Conversation

@joeljose

Copy link
Copy Markdown
Owner

Closes #41.

Changes

  • Lock files. requirements.lock and requirements-cuda.lock are hash-locked and generated with uv pip compile, as described in CONTRIBUTING. The images install them with --require-hashes. requirements*.txt and pyproject.toml keep the ranges, and I raised the lower bounds to installable versions (numpy >= 1.23, scipy >= 1.9).
  • Base image. python:3.11.16-slim, pinned by digest, for both images.
  • CUDA image. It is the same slim base plus CuPy and the CUDA libraries it uses (runtime, NVRTC, cuFFT, cuBLAS) as nvidia-*-cu12 pip wheels, put on LD_LIBRARY_PATH. There is no more nvidia/cuda:*-devel base, and the Python is now the same as the CPU image (it was 3.10). The host only needs the driver and the Container Toolkit. pip install .[cuda] now includes the same wheels.
  • OpenCV. opencv-python-headless everywhere, so the libgl1/libglib2.0-0 apt layer is gone.
  • Docker user. A fixed non-root user (uid 1000), so docker build . needs no build args and the images aren't tied to whoever built them. The README, test.sh and CI use --user "$(id -u):$(id -g)" for bind mounts.
  • CI. Actions are pinned by SHA (checkout v6.1.0), and Dependabot watches Actions and the base image monthly (patches and digests only).

Acceptance criteria

docker build . and docker build -f Dockerfile.cuda . with no build args done
CUDA image >= 50% smaller 12.7 GB -> 3.54 GB (-72%); CPU 1.13 GB -> 0.78 GB
Builds reproducible from lock files done

Verification

  • ./test.sh: 97 passed, 1 skipped.
  • ./test.sh gpu on an RTX 4050 with the new slim image: 7 passed.
  • A real --gpu run on face.mp4 (VRAM check and save) works, and output files are owned by the calling user.

Not done

Publishing images to GHCR from tags. The issue suggested it, but it isn't in the acceptance criteria; it's easy to add with the release.

- Hash-locked requirements.lock / requirements-cuda.lock (uv), installed
  with --require-hashes on a digest-pinned python:3.11.16-slim
- The CUDA image uses the same base plus CuPy and the CUDA libraries as
  pip wheels instead of nvidia/cuda devel: 12.7 GB -> 3.5 GB
- opencv-python-headless everywhere (CPU image 1.13 GB -> 0.78 GB)
- A fixed non-root user, so docker build needs no UID build args
- Actions pinned by SHA; Dependabot for actions and the base image
- CONTRIBUTING documents how to regenerate the locks

Closes #41.
@joeljose
joeljose merged commit 81b0c00 into main Sep 29, 2026
2 checks passed
@joeljose
joeljose deleted the build/reproducible branch September 29, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build reproducibility: lock dependencies, fix Docker user handling, and slim down the CUDA image

1 participant