Load docker-sbx template images into sbx - #58
Merged
Merged
Conversation
sbx has its own image store and does not see host Docker images. Thus sbx tried to pull a built template from a registry, and host creation failed. build_template_image now saves the built image to a tar file, loads it with `sbx template load`, and removes the Docker image. sbx is the only store that holds the template, so delete_template_image removes it with `sbx template rm`.
czpython
force-pushed
the
sbx-template-load
branch
from
September 28, 2026 08:26
825df24 to
2661e4b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The docker-sbx provider built a template image with the host Docker engine but did not load it into sbx. sbx has its own image store, so it tried to pull the template from a registry. Host creation then failed with
403 Forbidden: pull failed for image "drukbox-template:<hash>".build_template_imagenow saves the built image to a temporary tar file, loads it withsbx template load, and removes the Docker image. The Docker image only carries the build, and sbx is the only store that holds the template.delete_template_imageremoves the template withsbx template rm --force.The sbx CLI reads the tar file and sends it to sandboxd. Thus the file can be in the system temporary directory.
DockerAPI.save_imagestreams the image to disk, so a large image does not stay in memory. The sbxno image "<tag>"error now maps toDockerSbxNotFoundError, with the same pattern as a missing sandbox.If the load fails, the Docker image stays. A new build of the same template uses the same tag.
Validation:
uv run pytest: 738 passed on SQLite. Ruff, format checks, and Pyright passed.DockerSbxProviderbuilt a template with a marker file.sbx template lslisteddocker.io/library/drukbox-template:<hash>, anddocker imagesdid not list it. A sandbox created from the template had the marker file. The deletion removed the template from sbx. A second deletion raisedProviderNotFoundError.Not tested: the API container deployment and Postgres.
Fixes #55.
The change also applies the review checklist to
docker_sbx/provider.py. The single-use_bootstrap_scripthelper is inlined intocreate_vm.