You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit d5c1239
Browse filesBrowse the repository at this point in the historyBrowse files
feat(cli,webapp): enforce instance base images end to end
Reject initialize-deployment requests from CLIs that cannot apply the instance's base images, so the setting is enforced rather than advisory. The CLI declares support on the paths that can honour it, and fails with a clear error on --native-build and --local-bundle, which cannot.
Return the base images on the get-deployment response as well, so deploys that attach to an existing deployment build on them too.
Validate image refs with one shared schema in core on both the server and the CLI: a single token pinned by digest. Reject the runtime alias node in favour of the concrete runtime keys, and report every invalid env entry in one error at startup.
Build the custom build stage with the same customization block as the base stage, so instructions and package installs run in the same order.
Copy file name to clipboardExpand all lines: .changeset/instance-deploy-base-images.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,4 +3,4 @@
3
3
"trigger.dev": patch
4
4
---
5
5
6
-
Self-hosted instances can require custom base images for deploys, such as FIPS-validated or hardened Node images, with the new `DEPLOY_BASE_IMAGES` webapp setting. The CLI builds on the base images the instance specifies.
6
+
Self-hosted instances can require custom deploy base images per runtime via the new `DEPLOY_BASE_IMAGES`and `DEPLOY_BUILD_BASE_IMAGES`webapp settings. The CLI builds on the images the instance specifies, and older CLIs are rejected with an upgrade message.
Copy file name to clipboardExpand all lines: docs/self-hosting/env/webapp.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -97,7 +97,7 @@ mode: "wide"
97
97
|`DEPLOY_REGISTRY_NAMESPACE`| No | trigger | Deploy registry namespace. |
98
98
|`DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY`| No | — | Raw IAM policy JSON applied via SetRepositoryPolicy to every ECR repo created by the webapp. Use to grant cross-account pull access to EKS workers when the ECR account is separate from the cluster account. |
99
99
|`DEPLOY_IMAGE_PLATFORM`| No | linux/amd64 | Deploy image platform, same values as docker `--platform` flag. |
100
-
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node`, `node-22`, `node-24`, `node-26`, `bun`. The digest is required. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
100
+
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. Projects with `runtime: "node"` resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an upgrade message, and deploys using `--native-build` or `--local-bundle` fail when base images are configured. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
101
101
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage images per runtime. Same format and validation as `DEPLOY_BASE_IMAGES`. Defaults to the published `-build` images. |
102
102
|`DEPLOY_TIMEOUT_MS`| No | 480000 (8m) | Deploy timeout (ms). |
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node`, `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. With the Helm chart, set them through `webapp.extraEnvVars`.
111
+
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. With the Helm chart, set them through `webapp.extraEnvVars`.
112
+
113
+
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build` or `--local-bundle` fail with an error when base images are configured, since those paths cannot apply them.
112
114
113
115
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the bundle's Containerfile with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
0 commit comments