Skip to content

fix(dockerless): preserve runtime environment after build cleanup #1446

Description

@skevetter

Report and source evidence

The customer reports that Kubernetes containers still have PATH=/usr/local/bin:/.dockerless:/.dockerless/bin after #1426: #1426 (comment) . Customer PR #1425 included commit 7a69169 to move Dockerless credential cleanup before applying the built image environment. #1426 addressed vanished SSH-agent socket ownership and deleted-CWD Git handling but omitted the Dockerless change. Read-only inspection found deferred environment restoration still present on main 4e77d10 and v1.23.1. Customer reproduction is reported, not independently rerun yet.

Required behavior

Ensure temporary Dockerless build credential/environment cleanup finishes before the final built-image runtime environment is installed, so stale builder PATH/DOCKER_CONFIG cannot overwrite the runtime values. Preserve cleanup on build failure/cancellation and error propagation; avoid double cleanup. Review and credit the customer's implementation instead of blindly cherry-picking unrelated changes.

Regression coverage

  • Unit coverage must exercise the real cleanup/application sequence, verify ordering and exact final PATH/DOCKER_CONFIG, and cover failure/cancellation/nil-cleanup paths as applicable.
  • Add an actual Kubernetes Dockerless-build E2E fixture, not only a prebuilt-image startup fixture. Verify effective PATH preserves required image directories and an executable available only through the image-defined PATH works in the user shell/exec path. Keep the SSH-agent lifecycle coverage.
  • Demonstrate regression tests fail on the old ordering and pass with the fix. Run relevant unit/race/vet/lint/hooks and the actual registered Kubernetes integration cases; report never-run or blocked gates accurately.

Scope and delivery

Keep the fix limited to Dockerless build cleanup and its regression coverage. Avoid unrelated driver/runtime/provider changes and coordinate any overlap with #1424 or other open work. The pull request must reference Closes #1446, include test evidence and attribution to the original fix, and pass required reviews and CI before merge.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions