Hserver Failure Notes: Reproducibility · intermediate

A One-Line COPY Permission Bug Can Make an Image Non-Reproducible

A configuration file copied with the wrong mode can behave differently depending on the build context and base image defaults.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

Build definitions should encode runtime invariants, not just file content. This fits the Twelve-Factor build/release/run separation: the build stage should create a release artifact with predictable metadata. The social publisher build had a supervisor configuration whose runtime readability depended on the mode produced by the build context. That kind of permission can vary after source extraction, packaging or a different developer workstation.

The Dockerfile described which file to copy but not the permission invariant required by the process consuming it. Reproducibility was therefore relying on metadata outside the Dockerfile.

The build now uses COPY --chmod=644 for the supervisor configuration. The image itself establishes the intended permission instead of inheriting whatever mode happened to be present on the source filesystem. Files that have execution or readability requirements should declare them in the image build. A clean-build CI test can then verify behavior independently of the workstation that produced the source archive. The concrete hserver evidence is commit 484b33d, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc