Skip to content

fix(docker): Fix CPU/TPU nightly Docker build dependencies - #490

Open
Toshi-31 wants to merge 1 commit into
mainfrom
fix-nightly-image-pipeline
Open

Toshi-31 wants to merge 1 commit into
mainfrom
fix-nightly-image-pipeline

Conversation

@Toshi-31

@Toshi-31 Toshi-31 commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fixes the CPU/TPU Docker image build pipeline so that Google Cloud Build can resume publishing daily maxdiffusion_jax_stable_stack_nightly images.

Root Causes

  1. Base Image EOL: python:3.12-slim-bullseye (Debian 11) package mirrors moved, breaking apt-get update.
  2. Retired APT Package: google-cloud-sdk was retired upstream by Google Cloud apt repositories in favor of google-cloud-cli, causing apt-get install -y google-cloud-sdk to exit with code 100.

Changes

  1. Upgrade BASEIMAGE default from python:3.12-slim-bullseye to python:3.12-slim-bookworm (Debian 12) in maxdiffusion_dependencies.Dockerfile and docker_build_dependency_image.sh.
  2. Replace google-cloud-sdk with google-cloud-cli in maxdiffusion_dependencies.Dockerfile, modernizing the GPG key dearmoring step.

How This Was Identified

  1. Automated Pipeline Outage: The scheduled nightly image build workflow (.github/workflows/build_runner.yml) was failing during the Docker build stage, halting the publication of nightly runner images (maxdiffusion_jax_stable_stack_nightly) to GCR.
  2. Build Log Analysis:
    • apt-get install -y google-cloud-sdk exited with code 100 (E: Unable to locate package google-cloud-sdk) because Google Cloud's apt repositories deprecated the package name google-cloud-sdk in favor of google-cloud-cli.
    • The Debian 11 python:3.12-slim-bullseye base image was hitting repository mirror archive warnings and outdated keyring handling for Google Cloud apt sources.

How This Fix Has Been Verified

  1. GitHub Actions CI Workflow:
  2. Container Build Verification:
    • Verified clean local/container builds for both CPU and TPU targets (bash docker_build_dependency_image.sh MODE=stable DEVICE=tpu) confirming google-cloud-cli installs without apt errors and dependencies resolve on Debian 12 (bookworm).
  3. Cluster Runtime Verification:
    • Deployed the resulting container image on the TPU benchmark cluster via XPK, confirming that the container initializes cleanly, detects TPU devices, and launches training workloads without missing library or runtime environment errors.

Some pylink formatting changes have also been done because unit tests were failing.

@Toshi-31
Toshi-31 requested a review from entrpn as a code owner September 24, 2026 18:09
@github-actions

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the base Docker images from Debian Bullseye to Bookworm (python:3.12-slim-bookworm) and replaces the deprecated google-cloud-sdk package with google-cloud-cli. It also modernizes the GPG key addition process in the GPU Dockerfile to avoid using the deprecated apt-key utility, alongside some minor formatting cleanups in Python files. Feedback on the GPU Dockerfile highlights a potential build failure if curl and gnupg are not pre-installed in the base image, suggesting they be explicitly installed before fetching the GPG key.

Comment thread maxdiffusion_gpu_dependencies.Dockerfile Outdated
@Toshi-31
Toshi-31 force-pushed the fix-nightly-image-pipeline branch from bbf4536 to b10375c Compare September 25, 2026 08:01
@Toshi-31 Toshi-31 changed the title fix(ci): Fix Docker build dependencies and format codebase for CI fix(docker): Fix CPU/TPU nightly Docker build dependencies Sep 25, 2026
@Toshi-31
Toshi-31 force-pushed the fix-nightly-image-pipeline branch from b10375c to 1c8ab7d Compare September 26, 2026 11:58
@prishajain1

Copy link
Copy Markdown
Collaborator

Can you add how this was identified and how this fix has been verified to work

@Toshi-31

Copy link
Copy Markdown
Collaborator Author

Can you add how this was identified and how this fix has been verified to work

Done

prishajain1
prishajain1 previously approved these changes Sep 26, 2026
@Toshi-31
Toshi-31 force-pushed the fix-nightly-image-pipeline branch from 1c8ab7d to 9d62dc4 Compare September 26, 2026 12:29
@mbohlool

Copy link
Copy Markdown
Collaborator

Thanks for fixing the nightly build pipeline! A couple of minor suggestions and a nit for consideration / follow-up:

💡 Suggestions

  1. GPU Dockerfile parity (maxdiffusion_gpu_dependencies.Dockerfile):
    maxdiffusion_gpu_dependencies.Dockerfile still references the retired google-cloud-sdk package and uses deprecated apt-key. While this PR is scoped to CPU/TPU, updating the GPU Dockerfile similarly (ensuring curl and gnupg are installed prior to dearmoring) would prevent GPU build breaks down the road.
  2. APT layer consolidation (maxdiffusion_dependencies.Dockerfile):
    Lines 20–27 currently run two separate apt-get update && apt-get install passes. Configuring the Google Cloud repository before the initial install could collapse them into a single RUN layer to shave off build time and reduce image size.

🟢 Nit

  • Stale comment (maxdiffusion_dependencies.Dockerfile:L9): The comment reads # Set environment variables for Google Cloud SDK and Python 3.10, but line 10 sets PYTHON_VERSION=3.12.

@Toshi-31

Copy link
Copy Markdown
Collaborator Author

Thanks for fixing the nightly build pipeline! A couple of minor suggestions and a nit for consideration / follow-up:

💡 Suggestions

  1. GPU Dockerfile parity (maxdiffusion_gpu_dependencies.Dockerfile):
    maxdiffusion_gpu_dependencies.Dockerfile still references the retired google-cloud-sdk package and uses deprecated apt-key. While this PR is scoped to CPU/TPU, updating the GPU Dockerfile similarly (ensuring curl and gnupg are installed prior to dearmoring) would prevent GPU build breaks down the road.
  2. APT layer consolidation (maxdiffusion_dependencies.Dockerfile):
    Lines 20–27 currently run two separate apt-get update && apt-get install passes. Configuring the Google Cloud repository before the initial install could collapse them into a single RUN layer to shave off build time and reduce image size.

🟢 Nit

  • Stale comment (maxdiffusion_dependencies.Dockerfile:L9): The comment reads # Set environment variables for Google Cloud SDK and Python 3.10, but line 10 sets PYTHON_VERSION=3.12.

Done

…le Cloud CLI

- Upgrade base image to python:3.12-slim-bookworm in docker_build_dependency_image.sh and maxdiffusion_dependencies.Dockerfile
- Replace retired google-cloud-sdk package with google-cloud-cli and modernize GPG keyring handling with gpg --dearmor
- Consolidate APT update and install passes into a single RUN layer in maxdiffusion_dependencies.Dockerfile and maxdiffusion_gpu_dependencies.Dockerfile
- Update stale comment in maxdiffusion_dependencies.Dockerfile to reference Python 3.12
- Format Wan SVG attention and AOT cache files with pyink
@Toshi-31
Toshi-31 force-pushed the fix-nightly-image-pipeline branch from e7831c7 to ff18ad0 Compare October 1, 2026 05:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants