Skip to content

Load docker-sbx template images into sbx - #58

Merged
czpython merged 1 commit into
mainfrom
sbx-template-load
Sep 28, 2026
Merged

czpython merged 1 commit into
mainfrom
sbx-template-load

Conversation

@czpython

@czpython czpython commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

The docker-sbx provider built a template image with the host Docker engine but did not load it into sbx. sbx has its own image store, so it tried to pull the template from a registry. Host creation then failed with 403 Forbidden: pull failed for image "drukbox-template:<hash>".

build_template_image now saves the built image to a temporary tar file, loads it with sbx template load, and removes the Docker image. The Docker image only carries the build, and sbx is the only store that holds the template. delete_template_image removes the template with sbx template rm --force.

The sbx CLI reads the tar file and sends it to sandboxd. Thus the file can be in the system temporary directory. DockerAPI.save_image streams the image to disk, so a large image does not stay in memory. The sbx no image "<tag>" error now maps to DockerSbxNotFoundError, with the same pattern as a missing sandbox.

If the load fails, the Docker image stays. A new build of the same template uses the same tag.

Validation:

  • uv run pytest: 738 passed on SQLite. Ruff, format checks, and Pyright passed.
  • New tests cover the load, a failed load, the Docker save, the sbx template commands, and a missing template.
  • On sbx v0.45.1, DockerSbxProvider built a template with a marker file. sbx template ls listed docker.io/library/drukbox-template:<hash>, and docker images did not list it. A sandbox created from the template had the marker file. The deletion removed the template from sbx. A second deletion raised ProviderNotFoundError.

Not tested: the API container deployment and Postgres.

Fixes #55.

The change also applies the review checklist to docker_sbx/provider.py. The single-use _bootstrap_script helper is inlined into create_vm.

sbx has its own image store and does not see host Docker images. Thus
sbx tried to pull a built template from a registry, and host creation
failed.

build_template_image now saves the built image to a tar file, loads it
with `sbx template load`, and removes the Docker image. sbx is the only
store that holds the template, so delete_template_image removes it with
`sbx template rm`.
@czpython
czpython merged commit 2f5a471 into main Sep 28, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docker-sbx: a built template is not loaded into sbx, so host creation fails

1 participant