[Fix] Docker: restore pre-uv Prisma cache path for /app/.cache mounts

The uv migration added PRISMA_BINARY_CACHE_DIR=/app/.cache/... and
XDG_CACHE_HOME=/app/.cache to the runtime stages of Dockerfile and
Dockerfile.database. BINARY_PATHS in the generated prisma client was
baked to point into /app/.cache, so any deployment that mounts a volume
there (common with securityContext.readOnlyRootFilesystem: true and an
emptyDir/tmpfs for a writable cache) wipes the pre-downloaded query
engine at pod startup, producing BinaryNotFoundError during connect().

Before the uv migration, prisma-python defaulted to $HOME/.cache =
/root/.cache (runtime stage runs as root), which was unaffected by any
/app/* volume mounts. Restore that behaviour: drop the env vars from
the runtime stage, re-run prisma generate there so the query engine
AND the baked BINARY_PATHS both land in /root/.cache, and remove the
stale builder-stage /app/.cache (~800 MB).

Dockerfile.non_root is intentionally left alone — its /app/.cache
location is by design for the hardened offline-install flow.
This commit is contained in:
Yuneng Jiang 2026-04-21 15:30:42 -07:00
parent 7cc22dbe19
commit 731c549876
No known key found for this signature in database
2 changed files with 18 additions and 6 deletions

View File

@ -94,15 +94,21 @@ RUN apk add --no-cache bash openssl tzdata nodejs npm python3 libsndfile supervi
{ apk del --no-cache npm 2>/dev/null || true; }
WORKDIR /app
ENV PRISMA_BINARY_CACHE_DIR=/app/.cache/prisma-python/binaries \
XDG_CACHE_HOME=/app/.cache \
PATH="/app/.venv/bin:${PATH}"
ENV PATH="/app/.venv/bin:${PATH}"
COPY --from=builder /app /app
RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \
find /app/.venv -type d -path "*/tornado/test" -delete
# Regenerate the Prisma client in the runtime stage so the baked-in
# BINARY_PATHS resolve to a location outside /app. Users with volume mounts
# that shadow /app/.cache (e.g. readOnlyRootFilesystem + emptyDir) would
# otherwise lose access to the pre-downloaded query engine at runtime.
# Drop the builder's /app/.cache afterwards — it's stale and adds ~800 MB
# the runtime doesn't use.
RUN rm -rf /app/.cache && prisma generate --schema=./schema.prisma
EXPOSE 4000/tcp
COPY docker/supervisord.conf /etc/supervisord.conf

View File

@ -92,15 +92,21 @@ RUN apk add --no-cache bash openssl tzdata nodejs npm python3 libsndfile supervi
{ apk del --no-cache npm 2>/dev/null || true; }
WORKDIR /app
ENV PRISMA_BINARY_CACHE_DIR=/app/.cache/prisma-python/binaries \
XDG_CACHE_HOME=/app/.cache \
PATH="/app/.venv/bin:${PATH}"
ENV PATH="/app/.venv/bin:${PATH}"
COPY --from=builder /app /app
RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \
find /app/.venv -type d -path "*/tornado/test" -delete
# Regenerate the Prisma client in the runtime stage so the baked-in
# BINARY_PATHS resolve to a location outside /app. Users with volume mounts
# that shadow /app/.cache (e.g. readOnlyRootFilesystem + emptyDir) would
# otherwise lose access to the pre-downloaded query engine at runtime.
# Drop the builder's /app/.cache afterwards — it's stale and adds ~800 MB
# the runtime doesn't use.
RUN rm -rf /app/.cache && prisma generate --schema=./schema.prisma
EXPOSE 4000/tcp
COPY docker/supervisord.conf /etc/supervisord.conf