From 6ee5dc33ae6f8d1438703bc16992caf6e6429284 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Tue, 26 May 2026 16:23:22 -0700 Subject: [PATCH] fix(docker): pin python 3.13 and use global Node for prisma generate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two upstream "use latest" channels recently drifted past what the project supports and broke `docker build` for the three legacy Dockerfiles (Dockerfile, docker/Dockerfile.database, docker/Dockerfile.non_root): 1. Wolfi's `python3` apk meta-package now resolves to CPython 3.14.x, but `pyproject.toml` pins `requires-python = ">=3.10, <3.14"`. `uv sync ... --python python3` therefore fails with "interpreter resolved to Python 3.14.x, which is incompatible with the project's Python requirement". 2. prisma-python's nodeenv now downloads Node 26.2.0, which on arm64 is dynamically linked against `libatomic.so.1` — a library wolfi-base doesn't ship. `prisma generate` then fails with "node: error while loading shared libraries: libatomic.so.1". Replace both implicit-latest assumptions with explicit pins in all three Dockerfiles: * `apk add python-3.13 python-3.13-dev` instead of the meta `python3` / `python3-dev` (concrete versioned wolfi packages). * `uv sync ... --python python3.13` (match the apk binary). * `ENV UV_PYTHON_DOWNLOADS=0` so uv refuses to silently substitute a managed CPython if the system interpreter ever goes missing. * `ENV PRISMA_USE_GLOBAL_NODE=true` so `prisma generate` uses the apk-installed nodejs instead of nodeenv's "latest" Node. This matches the pattern the newer componentized Dockerfiles (backend/, gateway/, migrations/) already use. 3.13 is also the version `docker/tests/nonroot.yaml` already asserts at `/usr/local/lib/python3.13/site-packages/prisma/`. --- Dockerfile | 12 +++++++----- docker/Dockerfile.database | 12 +++++++----- docker/Dockerfile.non_root | 15 +++++++++------ 3 files changed, 23 insertions(+), 16 deletions(-) diff --git a/Dockerfile b/Dockerfile index 9ad9ab31b65..f45b6bfd18a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -19,8 +19,8 @@ COPY --from=uvbin /uvx /usr/local/bin/uvx RUN apk add --no-cache \ bash \ gcc \ - python3 \ - python3-dev \ + python-3.13 \ + python-3.13-dev \ openssl \ openssl-dev \ nodejs \ @@ -29,6 +29,8 @@ RUN apk add --no-cache \ ENV UV_PROJECT_ENVIRONMENT=/app/.venv \ UV_LINK_MODE=copy \ + UV_PYTHON_DOWNLOADS=0 \ + PRISMA_USE_GLOBAL_NODE=true \ PATH="/app/.venv/bin:${PATH}" # Copy dependency metadata first for layer caching @@ -42,7 +44,7 @@ RUN uv sync --frozen --no-install-project --no-install-workspace --no-default-gr --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 + --python python3.13 # Copy full source tree COPY . . @@ -56,7 +58,7 @@ RUN uv sync --frozen --no-default-groups --no-editable \ --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 + --python python3.13 RUN prisma generate --schema=./schema.prisma @@ -68,7 +70,7 @@ FROM $LITELLM_RUNTIME_IMAGE AS runtime USER root -RUN apk add --no-cache bash openssl tzdata nodejs npm python3 libsndfile && \ +RUN apk add --no-cache bash openssl tzdata nodejs npm python-3.13 libsndfile && \ npm install -g npm@11.14.0 tar@7.5.11 glob@13.0.6 @isaacs/brace-expansion@5.0.1 brace-expansion@5.0.5 minimatch@10.2.4 diff@8.0.3 picomatch@4.0.4 && \ GLOBAL="$(npm root -g)" && \ for pkg in tar glob @isaacs/brace-expansion brace-expansion minimatch diff picomatch; do \ diff --git a/docker/Dockerfile.database b/docker/Dockerfile.database index c84003a065f..66f303cd1e3 100644 --- a/docker/Dockerfile.database +++ b/docker/Dockerfile.database @@ -18,8 +18,8 @@ COPY --from=uvbin /uvx /usr/local/bin/uvx RUN apk add --no-cache \ bash \ gcc \ - python3 \ - python3-dev \ + python-3.13 \ + python-3.13-dev \ openssl \ openssl-dev \ nodejs \ @@ -28,6 +28,8 @@ RUN apk add --no-cache \ ENV UV_PROJECT_ENVIRONMENT=/app/.venv \ UV_LINK_MODE=copy \ + UV_PYTHON_DOWNLOADS=0 \ + PRISMA_USE_GLOBAL_NODE=true \ PATH="/app/.venv/bin:${PATH}" # Copy dependency metadata first for layer caching @@ -41,7 +43,7 @@ RUN uv sync --frozen --no-install-project --no-install-workspace --no-default-gr --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 + --python python3.13 # Copy full source tree COPY . . @@ -55,7 +57,7 @@ RUN uv sync --frozen --no-default-groups --no-editable \ --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 + --python python3.13 RUN prisma generate --schema=./schema.prisma @@ -66,7 +68,7 @@ FROM $LITELLM_RUNTIME_IMAGE AS runtime USER root -RUN apk add --no-cache bash openssl tzdata nodejs npm python3 libsndfile && \ +RUN apk add --no-cache bash openssl tzdata nodejs npm python-3.13 libsndfile && \ npm install -g npm@11.12.1 tar@7.5.11 glob@11.1.0 @isaacs/brace-expansion@5.0.1 minimatch@10.2.4 diff@8.0.3 && \ GLOBAL="$(npm root -g)" && \ find "$GLOBAL/npm" -type d -name "tar" -path "*/node_modules/tar" | while read d; do \ diff --git a/docker/Dockerfile.non_root b/docker/Dockerfile.non_root index 8717e5b3fcd..e12cf583e47 100644 --- a/docker/Dockerfile.non_root +++ b/docker/Dockerfile.non_root @@ -16,8 +16,8 @@ COPY --from=uvbin /uvx /usr/local/bin/uvx RUN for i in 1 2 3; do \ apk add --no-cache \ - python3 \ - python3-dev \ + python-3.13 \ + python-3.13-dev \ gcc \ bash \ coreutils \ @@ -30,8 +30,10 @@ RUN for i in 1 2 3; do \ ENV UV_PROJECT_ENVIRONMENT=/app/.venv \ UV_LINK_MODE=copy \ + UV_PYTHON_DOWNLOADS=0 \ PATH="/app/.venv/bin:${PATH}" \ LITELLM_NON_ROOT=true \ + PRISMA_USE_GLOBAL_NODE=true \ PRISMA_BINARY_CACHE_DIR=/app/.cache/prisma-python/binaries \ XDG_CACHE_HOME=/app/.cache @@ -47,7 +49,7 @@ RUN --mount=type=cache,target=/app/.cache/uv,id=litellm-uv-cache \ --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 + --python python3.13 # Copy full source tree COPY . . @@ -67,7 +69,7 @@ RUN --mount=type=cache,target=/app/.cache/uv,id=litellm-uv-cache \ --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3 \ + --python python3.13 \ --no-sources-package litellm-proxy-extras; \ else \ uv sync --frozen --no-default-groups --no-editable \ @@ -75,7 +77,7 @@ RUN --mount=type=cache,target=/app/.cache/uv,id=litellm-uv-cache \ --extra proxy-runtime \ --extra extra_proxy \ --extra semantic-router \ - --python python3; \ + --python python3.13; \ fi RUN prisma generate --schema=./schema.prisma @@ -92,7 +94,7 @@ RUN for i in 1 2 3; do \ apk upgrade --no-cache && break || sleep 5; \ done && \ for i in 1 2 3; do \ - apk add --no-cache python3 bash openssl tzdata libsndfile nodejs && break || sleep 5; \ + apk add --no-cache python-3.13 bash openssl tzdata libsndfile nodejs && break || sleep 5; \ done COPY --from=builder /app /app @@ -103,6 +105,7 @@ ENV PATH="/app/.venv/bin:${PATH}" \ PRISMA_BINARY_CACHE_DIR=/app/.cache/prisma-python/binaries \ HOME=/app \ LITELLM_NON_ROOT=true \ + PRISMA_USE_GLOBAL_NODE=true \ XDG_CACHE_HOME=/app/.cache \ PRISMA_SKIP_POSTINSTALL_GENERATE=1 \ PRISMA_HIDE_UPDATE_MESSAGE=1 \