Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion ci/docker/manylinux-retag.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,11 @@

ARG MANYLINUX_VERSION
ARG HOSTTYPE
ARG BUILDKITE_BAZEL_CACHE_URL
FROM rayproject/manylinux2014:${MANYLINUX_VERSION}-jdk-${HOSTTYPE}

ARG BUILDKITE_BAZEL_CACHE_URL
ENV BUILDKITE_BAZEL_CACHE_URL=${BUILDKITE_BAZEL_CACHE_URL}
Comment on lines +13 to +14

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using ENV to store BUILDKITE_BAZEL_CACHE_URL is redundant and potentially insecure.

  1. Security: ENV variables persist in the final image and are visible via docker inspect. If this URL contains sensitive information (e.g., credentials or tokens), it will be exposed in the image metadata.
  2. Redundancy: The ARG instruction is sufficient to make the variable available to the RUN block during the build process. Additionally, ci/ray_ci/container.py already passes this variable at runtime via the --env flag, so setting it as a default ENV in the Dockerfile is unnecessary.

It is recommended to use only ARG for build-time configuration that doesn't need to persist in the image environment.

ARG BUILDKITE_BAZEL_CACHE_URL

# Still keep bazelrc updates to allow BUILDKITE_BAZEL_CACHE_URL to be used.
RUN <<EOF
#!/bin/bash
Expand Down