Conversation
- Add openc3-ruby/uv_mirror_relock.sh, shipped as uv-mirror-relock, which re-resolves uv.lock against PYPI_URL and is a no-op at the default pypi.org - Run it before both uv sync --frozen steps in openc3/Dockerfile, since UV_DEFAULT_INDEX only steers resolution while a frozen sync fetches the absolute pythonhosted.org URLs the lockfile pins - Relock before rake build in docker-package-build.sh so the lock packaged into each plugin gem matches the warmed wheel cache - Document the re-resolve and the host-side uv lock --default-index workflow in .env, INSTALL.md, developing.md and environment.md Refs #2867 Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3891 +/- ##
==========================================
+ Coverage 79.85% 79.86% +0.01%
==========================================
Files 901 901
Lines 68154 68251 +97
Branches 2698 2698
==========================================
+ Hits 54426 54512 +86
- Misses 13057 13065 +8
- Partials 671 674 +3
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Pass the mirror explicitly to base and init images, report skipped relocks, and prevent source builds during dependency resolution.
…-image-builds-breaking-air-gappedproxy-environments
…sed-to-uv-during-docker-image-builds-breaking-air-gappedproxy-environments
|
Against uv 0.12.16, with both indexes on unroutable
Neither flag is sufficient alone: -uv lock --default-index "${PYPI_URL}/simple" "$@"
+uv lock --no-config --no-sources --default-index "${PYPI_URL}/simple" "$@"This does not change the results in your test plan. Neither One consequence for the description: once the mirror is authoritative, a plugin depending on a package published only to its author's private index fails to build rather than silently fetching from that index, so the mirror has to proxy any such index. #3896 makes the same change on the runtime plugin install path, in |
Add --no-config --no-sources to the uv lock invocation. --default-index does not win on its own: uv searches a named index declared in the project's own [tool.uv].index table first, and a [tool.uv].sources pin is project metadata that survives --no-config. Without both flags a plugin configuring its author's index relocks against that index, and the air-gapped build fails at the point this script exists to prevent. Refs #2867 Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
…sed-to-uv-during-docker-image-builds-breaking-air-gappedproxy-environments
- Pass --index-url "${PYPI_URL}/simple" to the pip install of uv in
openc3-ruby Dockerfile and Dockerfile-ubi so air-gapped builds stop
reaching for pypi.org
- Add UV_INSECURE_HOST build arg that maps to pip --trusted-host,
letting a plain-HTTP mirror be trusted
- Thread UV_INSECURE_HOST through .env, compose-build.yaml and
openc3_build_ubi.sh
Refs #2867
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
Refs #2867 Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
- Pass UV_INSECURE_HOST to pip through PIP_TRUSTED_HOST instead of an
unquoted ${UV_INSECURE_HOST:+--trusted-host ...} expansion
- Add --only-binary :all: so a mirror-served sdist never runs a setup
script
- Apply both to Dockerfile and Dockerfile-ubi in step
Refs #2867
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
|



Summary
uv sync --frozenfetches the pythonhosted.org URLs pinned inuv.lock, so a non-defaultPYPI_URLnever reached the mirror.uv-mirror-relock(from both base images) re-resolves the lock against ${PYPI_URL}/simple with --no-config --no-sources, so the mirror is the only index. It does nothing at the default pypi.org.openc3/Dockerfile, and beforerake buildindocker-package-build.shso plugin gems ship mirror locks.PYPI_URL_OVERRIDEbuild arg keeps the mirror when an image is rebuilt on its own against an older base image.-no-buildinopenc3/Dockerfile. After skip build scripts during uv sync #3897 merges, the post-relock syncs can move to--locked.pip install uvin both base images ignoredPYPI_URL.UV_INSECURE_HOSTtrusts a plain-HTTP mirror.Closes #2867
Test plan
openc3-ruby/uv_mirror_relock.sh, run inopenc3/pythonand the demo plugin against a local PEP 503 mirror:PYPI_URLunset orhttps://pypi.org- prints the skip, lock untouchedPYPI_URLat the mirror - no pythonhosted.org URLs left, every download URL points at the mirror[tool.uv].indexor[tool.uv.sources]names another index resolves against the mirror onlyscripts/linux/test_pypi_mirror.sh(runs./openc3.sh buildagainst the mirror with pypi.org and files.pythonhosted.org blackholed):verify-uv-cache.shpasses offlinebuild-ubimodeOther:
docker buildx build --call=checkandshellcheckclean./openc3.sh buildagainst Nexus, including init plugins