Skip to content

Add a digest-pinned uv to the ol-concourse-dsl image - #111

Merged
blarghmatey merged 1 commit into
mainfrom
dsl-image-uv
Sep 30, 2026
Merged

blarghmatey merged 1 commit into
mainfrom
dsl-image-uv

Conversation

@blarghmatey

Copy link
Copy Markdown
Member

What are the relevant tickets?

N/A. Follow-up to mitodl/ol-analytics-api#81.

Description (What does it do?)

ol-analytics-api now collects changelog fragments during bump_version_task, through a bump-my-version pre_commit_hooks entry that runs uv run --frozen --only-group release bin/collect-changelog. ol-concourse-dsl has no uv, so the hook first runs python3 -m pip install uv. That installs whatever uv PyPI has at release time, outside the lockfile hashes and the repo's exclude-newer window.

This copies uv 0.12.15 into the image from ghcr.io/astral-sh/uv, pinned by tag and index digest (amd64 + arm64), using the same COPY --from form as ol-django. Renovate's dockerfile manager should keep the tag and digest current the way it does the python:3.14-slim base. Once this image is published, the pip step can come out of the ol-analytics-api hook.

How can this be tested?

  • Built the image from this branch (wheel via uv build --package ol-concourse --out-dir pipeline_lib/dist/, as the pipeline does). uv --version and uvx --version report 0.12.15. bump-my-version --version reports 1.5.1, the same as a build from main. bash -c 'command -v uv' resolves /usr/bin/uv.
  • The digest matches docker buildx imagetools inspect ghcr.io/astral-sh/uv:0.12.15.
  • The ol-analytics-api hook passes under bump-my-version 1.5.1 (the version this rebuild ships) and under 1.3.0 (the currently published image). This covers a release with fragments and one without.

The image is published by build-and-publish-task-image (.concourse/docker.py) when pipeline_lib changes on main, so merging this rebuilds mitodl/ol-concourse-dsl:latest.

https://claude.ai/code/session_01VaJ4VtbQFPV63VWtQV6JEg

The bump-my-version pre_commit_hooks added in
mitodl/ol-analytics-api#81 run in this image
during bump_version_task and call `uv run --frozen --only-group release`.
The image has no uv, so the hook first runs `python3 -m pip install uv`,
which pulls an unpinned uv at release time, outside the lockfile hashes
and the repo's exclude-newer window. Copying a digest-pinned uv into the
image lets that hook step be dropped, and Renovate's dockerfile manager
keeps the tag and digest current.

Claude-Session: https://claude.ai/code/session_01VaJ4VtbQFPV63VWtQV6JEg
@blarghmatey
blarghmatey merged commit a8d1949 into main Sep 30, 2026
20 checks passed
@blarghmatey
blarghmatey deleted the dsl-image-uv branch September 30, 2026 14:49
blarghmatey added a commit to mitodl/ol-analytics-api that referenced this pull request Sep 30, 2026
mitodl/ol-concourse-dsl ships uv since
mitodl/ol-concourse#111, so the hook no longer
needs to install an unpinned uv from PyPI at release time.

Claude-Session: https://claude.ai/code/session_01VaJ4VtbQFPV63VWtQV6JEg
blarghmatey added a commit to mitodl/ol-analytics-api that referenced this pull request Sep 30, 2026
mitodl/ol-concourse-dsl ships uv since
mitodl/ol-concourse#111, so the hook no longer
needs to install an unpinned uv from PyPI at release time.

Claude-Session: https://claude.ai/code/session_01VaJ4VtbQFPV63VWtQV6JEg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant