diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-22 11:04:30 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-22 11:04:30 +0200 |
| commit | 88b55ee4d2920f1bfbf9fe75bfe3ceec6cb9ba9b (patch) | |
| tree | 9ab2d6c251d6a99a87eef93cec06c590e89debd3 /image-builder/build-full-image.sh | |
| parent | cd4f992a29da96b835c14545a0cb05e7e87ca291 (diff) | |
| download | sbo-dockerbuild-88b55ee4d2920f1bfbf9fe75bfe3ceec6cb9ba9b.tar.gz sbo-dockerbuild-88b55ee4d2920f1bfbf9fe75bfe3ceec6cb9ba9b.zip | |
image-builder: prune superseded images right after each push
A rebuild leaves the image it replaced untagged but still resident, which
is ~33G for sbo-full:current. Nothing reclaimed it until the daily 07:00
prune, so the next variant built on top of that dead weight.
That was enough to break the chain. Exporting a 33G image needs roughly
its own size again in transient space, and with the old cache floor the
volume was short at 03:20: build-full-image.sh failed ten nights running
(2026-09-13 through 09-22) with "no space left on device", always in the
same export/unpack phase. build-sbo-testbuild.sh then saw an unchanged
parent and skipped, correctly and silently, so the -current tags sat six
days stale while 15.0 kept rebuilding fine.
Prune at the point where the superseded image becomes dangling: after
the push, while the tag just pushed is the only thing referencing its
layers. `docker image prune -f` only removes untagged images, so the
chain's own tags are never at risk. Best-effort, since a failed prune
costs space, not correctness.
bootstrap.sh is left alone: its images are ~150MB, so a superseded one
is noise next to the transient peak this addresses.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'image-builder/build-full-image.sh')
| -rwxr-xr-x | image-builder/build-full-image.sh | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/image-builder/build-full-image.sh b/image-builder/build-full-image.sh index 6f88db7..6ca0288 100755 --- a/image-builder/build-full-image.sh +++ b/image-builder/build-full-image.sh @@ -225,6 +225,16 @@ DOCKERFILE return 1 fi + # The rebuild left the previous image untagged but still resident, ~33G for + # -current. Waiting for a daily prune means the next variant builds on top + # of that dead weight: exporting a 33G image needs its own size again in + # transient space, and the volume was short enough that the -current build + # failed six nights running with "no space left on device". Drop it here, + # while the tag we just pushed is the only one referencing its layers. + # Best-effort: a failed prune costs space, not correctness. + _log " Pruning superseded images..." + docker image prune -f >/dev/null 2>&1 || _warn " image prune failed (ignored)" + _log "=== Done: ${FULL_TAG} ===" } |
