Skip to content

cherrypick #62758 - #62759

Merged
aslonnie merged 1 commit into
ray-project:releases/2.55.1from
anyscale:lonnie-260419-2551cp3
Apr 19, 2026
Merged

aslonnie merged 1 commit into
ray-project:releases/2.55.1from
anyscale:lonnie-260419-2551cp3

Conversation

@aslonnie

Copy link
Copy Markdown
Contributor

declare ARG below FROM and explicitly re-set ENV from the ARG value, so the rayturbo build_arg takes effect in the RUN and /home/forge/.bazelrc is written with the correct cache URL.

declare ARG below FROM and explicitly re-set ENV from the ARG value, so
the rayturbo build_arg takes effect in the RUN and /home/forge/.bazelrc
is written with the correct cache URL.

Signed-off-by: Lonnie Liu <95255098+aslonnie@users.noreply.github.com>
@aslonnie
aslonnie requested a review from a team as a code owner April 19, 2026 17:00
@aslonnie
aslonnie merged commit 237c245 into ray-project:releases/2.55.1 Apr 19, 2026
2 of 4 checks passed

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies the manylinux-retag.Dockerfile by moving the BUILDKITE_BAZEL_CACHE_URL argument after the FROM instruction and adding it as an environment variable. Feedback suggests removing the ENV instruction because it unnecessarily persists potentially sensitive information in the image metadata and is redundant since the variable is already provided at runtime.

Comment on lines +13 to +14
ARG BUILDKITE_BAZEL_CACHE_URL
ENV BUILDKITE_BAZEL_CACHE_URL=${BUILDKITE_BAZEL_CACHE_URL}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using ENV to store BUILDKITE_BAZEL_CACHE_URL is redundant and potentially insecure.

  1. Security: ENV variables persist in the final image and are visible via docker inspect. If this URL contains sensitive information (e.g., credentials or tokens), it will be exposed in the image metadata.
  2. Redundancy: The ARG instruction is sufficient to make the variable available to the RUN block during the build process. Additionally, ci/ray_ci/container.py already passes this variable at runtime via the --env flag, so setting it as a default ENV in the Dockerfile is unnecessary.

It is recommended to use only ARG for build-time configuration that doesn't need to persist in the image environment.

ARG BUILDKITE_BAZEL_CACHE_URL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant