You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 701591d
Browse filesBrowse the repository at this point in the historyBrowse files
fix(webapp,cli): reject native builds server-side when base images are set
Native builds and local bundles cannot apply the instance's base images and never declared support, so the server was rejecting them with the message meant for outdated CLIs. Reject them with their own message on the server and drop the CLI-side checks that could never run.
Docs: describe what the build stage uses without a build image entry, note that --from-bundle rewrites the Containerfile inside the bundle directory, and shorten the env table rows.
Copy file name to clipboardExpand all lines: docs/self-hosting/env/webapp.mdx
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -97,8 +97,8 @@ mode: "wide"
97
97
|`DEPLOY_REGISTRY_NAMESPACE`| No | trigger | Deploy registry namespace. |
98
98
|`DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY`| No | — | Raw IAM policy JSON applied via SetRepositoryPolicy to every ECR repo created by the webapp. Use to grant cross-account pull access to EKS workers when the ECR account is separate from the cluster account. |
99
99
|`DEPLOY_IMAGE_PLATFORM`| No | linux/amd64 | Deploy image platform, same values as docker `--platform` flag. |
100
-
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. Projects with `runtime: "node"` resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an upgrade message, and deploys using `--native-build` or `--local-bundle` fail when base images are configured. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
101
-
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage images per runtime. Same format and validation as `DEPLOY_BASE_IMAGES`. Defaults to the published `-build` images. |
100
+
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
101
+
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage images per runtime, same format and validation. Without an entry the build stage uses the published build image, or the base image plus a toolchain install when build extensions add image instructions. |
102
102
|`DEPLOY_TIMEOUT_MS`| No | 480000 (8m) | Deploy timeout (ms). |
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. With the Helm chart, set them through `webapp.extraEnvVars`.
112
112
113
-
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build` or `--local-bundle`fail with an error when base images are configured, since those paths cannot apply them.
113
+
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build` or `--local-bundle`are rejected when base images are configured, since those paths cannot apply them.
114
114
115
-
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the bundle's Containerfile with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
115
+
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the Containerfile inside the bundle directory with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
116
116
117
117
You own a custom base image. A Node image must provide:
118
118
@@ -128,7 +128,7 @@ A Bun image must provide:
128
128
- a `bun` user
129
129
- glibc, so native modules built in the build stage load at runtime
130
130
131
-
A `DEPLOY_BUILD_BASE_IMAGES` image must contain everything the base image provides, plus the toolchain the published build images include: `python3`, `make` and `g++`. When a project's build extensions add image instructions, those instructions are replayed on the build-stage image, so it must be able to run them. Without a `DEPLOY_BUILD_BASE_IMAGES` entry, the build stage is created from your base image and the toolchain is installed with `apt-get`, so the base image must be Debian-based for those projects.
131
+
A `DEPLOY_BUILD_BASE_IMAGES` image must contain everything the base image provides, plus the toolchain the published build images include: `python3`, `make` and `g++`. When a project's build extensions add image instructions, those instructions are replayed on the build-stage image, so it must be able to run them. Without a `DEPLOY_BUILD_BASE_IMAGES` entry, the build stage uses the published build image. The exception is a project whose build extensions add image instructions: its build stage is created from your base image and the toolchain is installed with `apt-get`, so the base image must be Debian-based for those projects. To avoid the published build image entirely, set both `DEPLOY_BASE_IMAGES` and `DEPLOY_BUILD_BASE_IMAGES`.
132
132
133
133
<Warning>
134
134
`image.pkgs` and build extensions that run `apt-get` (such as `aptGet` and `playwright`) assume a
0 commit comments