Skip to content

Fix Docker bake building from main instead of PR branch - #473

Merged
ghostwriternr merged 1 commit into
mainfrom
fix/docker-bake-source-context
Mar 9, 2026
Merged

ghostwriternr merged 1 commit into
mainfrom
fix/docker-bake-source-context

Conversation

@ghostwriternr

@ghostwriternr ghostwriternr commented Mar 9, 2026 •

Copy link
Copy Markdown
Member

Bug

Since pull_request_target was introduced in #458, every PR's Docker image has been built from the main branch instead of the PR branch. This means E2E tests always run against stale container code, forcing contributors to manually delete container configs to test their changes.

Root Cause

docker/bake-action@v6 defaults to Git remote context at the workflow ref. For pull_request_target, that ref is always the base branch (main) — not the PR head. Despite actions/checkout correctly placing PR code on disk, the bake action bypasses local files and pulls source directly from main.

Evidence from PR #437 CI logs:

  • PR head commit: ae42c52
  • Bake context used: 856f4dd (main HEAD)
  • E2E failure: container missing PR's backup gitignore feature

Fix

Add source: . to the bake action, switching it from Git remote context to path context. This makes bake use the locally checked-out PR code, which actions/checkout already places correctly.

All existing CI optimizations (content-addressed Docker cache, GHCR layer cache, deploy-skip, docker-skip) are unaffected — they operate independently of the bake source parameter.

docker/bake-action@v6 defaults to Git remote context at the workflow
ref. Since pr-privileged.yml uses pull_request_target, this ref is
always the base branch (main), causing every PR Docker image to contain
main's code instead of the PR's changes. Adding source: . forces bake
to use the locally checked-out PR code.
@changeset-bot

changeset-bot Bot commented Mar 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d29d8fb

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ghostwriternr
ghostwriternr merged commit 8a08527 into main Mar 9, 2026
14 checks passed
@ghostwriternr
ghostwriternr deleted the fix/docker-bake-source-context branch March 9, 2026 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants