Skip to content

Commit 701591d

Browse files
committed
fix(webapp,cli): reject native builds server-side when base images are set
Native builds and local bundles cannot apply the instance's base images and never declared support, so the server was rejecting them with the message meant for outdated CLIs. Reject them with their own message on the server and drop the CLI-side checks that could never run. Docs: describe what the build stage uses without a build image entry, note that --from-bundle rewrites the Containerfile inside the bundle directory, and shorten the env table rows.
1 parent d5c1239 commit 701591d

4 files changed

Lines changed: 18 additions & 26 deletions

File tree

‎apps/webapp/app/v3/services/initializeDeployment.server.ts‎

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -148,13 +148,19 @@ export class InitializeDeploymentService extends BaseService {
148148
throw new ServiceValidationError("UNMANAGED deployments are not supported");
149149
}
150150

151-
if (
152-
resolveDeployBaseImages(runtime, {
153-
base: env.DEPLOY_BASE_IMAGES,
154-
buildBase: env.DEPLOY_BUILD_BASE_IMAGES,
155-
}) &&
156-
payload.supportsInstanceBaseImages !== true
157-
) {
151+
const requiredBaseImages = resolveDeployBaseImages(runtime, {
152+
base: env.DEPLOY_BASE_IMAGES,
153+
buildBase: env.DEPLOY_BUILD_BASE_IMAGES,
154+
});
155+
156+
if (requiredBaseImages && payload.isNativeBuild) {
157+
throw new ServiceValidationError(
158+
"This instance requires custom deploy base images, which native builds cannot apply. Deploy without --native-build or --local-bundle.",
159+
400
160+
);
161+
}
162+
163+
if (requiredBaseImages && payload.supportsInstanceBaseImages !== true) {
158164
throw new ServiceValidationError(
159165
"This instance requires custom deploy base images, which this version of the CLI cannot apply. Upgrade the trigger.dev CLI and deploy again.",
160166
400

‎docs/self-hosting/env/webapp.mdx‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -97,8 +97,8 @@ mode: "wide"
9797
| `DEPLOY_REGISTRY_NAMESPACE` | No | trigger | Deploy registry namespace. |
9898
| `DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY` | No | — | Raw IAM policy JSON applied via SetRepositoryPolicy to every ECR repo created by the webapp. Use to grant cross-account pull access to EKS workers when the ECR account is separate from the cluster account. |
9999
| `DEPLOY_IMAGE_PLATFORM` | No | linux/amd64 | Deploy image platform, same values as docker `--platform` flag. |
100-
| `DEPLOY_BASE_IMAGES` | No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. Projects with `runtime: "node"` resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an upgrade message, and deploys using `--native-build` or `--local-bundle` fail when base images are configured. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
101-
| `DEPLOY_BUILD_BASE_IMAGES` | No | — | Build-stage images per runtime. Same format and validation as `DEPLOY_BASE_IMAGES`. Defaults to the published `-build` images. |
100+
| `DEPLOY_BASE_IMAGES` | No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
101+
| `DEPLOY_BUILD_BASE_IMAGES` | No | — | Build-stage images per runtime, same format and validation. Without an entry the build stage uses the published build image, or the base image plus a toolchain install when build extensions add image instructions. |
102102
| `DEPLOY_TIMEOUT_MS` | No | 480000 (8m) | Deploy timeout (ms). |
103103
| `DEPLOY_QUEUE_TIMEOUT_MS` | No | 900000 (15m) | Deploy queue timeout (ms). |
104104
| **Object store (S3)** | | | |

‎docs/self-hosting/overview.mdx‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -110,9 +110,9 @@ DEPLOY_BASE_IMAGES="node-26=registry.example.com/node-fips:26@sha256:<64-charact
110110

111111
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. With the Helm chart, set them through `webapp.extraEnvVars`.
112112

113-
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build` or `--local-bundle` fail with an error when base images are configured, since those paths cannot apply them.
113+
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build` or `--local-bundle` are rejected when base images are configured, since those paths cannot apply them.
114114

115-
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the bundle's Containerfile with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
115+
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the Containerfile inside the bundle directory with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
116116

117117
You own a custom base image. A Node image must provide:
118118

@@ -128,7 +128,7 @@ A Bun image must provide:
128128
- a `bun` user
129129
- glibc, so native modules built in the build stage load at runtime
130130

131-
A `DEPLOY_BUILD_BASE_IMAGES` image must contain everything the base image provides, plus the toolchain the published build images include: `python3`, `make` and `g++`. When a project's build extensions add image instructions, those instructions are replayed on the build-stage image, so it must be able to run them. Without a `DEPLOY_BUILD_BASE_IMAGES` entry, the build stage is created from your base image and the toolchain is installed with `apt-get`, so the base image must be Debian-based for those projects.
131+
A `DEPLOY_BUILD_BASE_IMAGES` image must contain everything the base image provides, plus the toolchain the published build images include: `python3`, `make` and `g++`. When a project's build extensions add image instructions, those instructions are replayed on the build-stage image, so it must be able to run them. Without a `DEPLOY_BUILD_BASE_IMAGES` entry, the build stage uses the published build image. The exception is a project whose build extensions add image instructions: its build stage is created from your base image and the toolchain is installed with `apt-get`, so the base image must be Debian-based for those projects. To avoid the published build image entirely, set both `DEPLOY_BASE_IMAGES` and `DEPLOY_BUILD_BASE_IMAGES`.
132132

133133
<Warning>
134134
`image.pkgs` and build extensions that run `apt-get` (such as `aptGet` and `playwright`) assume a

‎packages/cli-v3/src/commands/deploy.ts‎

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1498,13 +1498,6 @@ async function handleNativeBuildServerDeploy({
14981498

14991499
const deployment = initializeDeploymentResult.data;
15001500

1501-
if (deployment.baseImages) {
1502-
$deploymentSpinner.stop("Failed to initialize deployment");
1503-
throw new Error(
1504-
"This instance requires custom deploy base images, which cannot be applied with --native-build. Deploy without that flag."
1505-
);
1506-
}
1507-
15081501
const rawDeploymentLink = `${dashboardUrl}/projects/v3/${config.project}/deployments/${deployment.shortCode}`;
15091502
const rawTestLink = `${dashboardUrl}/projects/v3/${config.project}/test?environment=${
15101503
options.env === "prod" ? "prod" : "stg"
@@ -1838,13 +1831,6 @@ async function handleLocalBundleDeploy({
18381831

18391832
const deployment = initializeDeploymentResult.data;
18401833

1841-
if (deployment.baseImages) {
1842-
$deploymentSpinner.stop("Failed to initialize deployment");
1843-
throw new Error(
1844-
"This instance requires custom deploy base images, which cannot be applied with --local-bundle. Deploy without that flag."
1845-
);
1846-
}
1847-
18481834
const rawDeploymentLink = `${dashboardUrl}/projects/v3/${config.project}/deployments/${deployment.shortCode}`;
18491835
const rawTestLink = `${dashboardUrl}/projects/v3/${config.project}/test?environment=${
18501836
options.env === "prod" ? "prod" : "stg"

0 commit comments

Comments
 (0)