Generating a Reproducible requirements.txt with Poetry Export for CI Pipelines
Use Poetry’s export command to create a reproducible requirements.txt for CI. Follow the guide to check file integrity, test installs, and recover common export issues.
31 Aug 2026, 22:51 UTC

Desired Outcome
Produce a requirements.txt that mirrors the exact dependency set recorded in poetry.lock. The file should be suitable for pip install -r requirements.txt in a CI job, ensuring that the CI environment installs the same package versions that Poetry resolves locally.
Prerequisites
- Poetry 1.2 or newer installed globally or per‑project (check with
poetry --version). - A valid
pyproject.tomland an up‑to‑datepoetry.lockin the repository root. - Python 3.8+ in the target CI environment (the same major/minor version as used locally is recommended).
- Write permission to create or overwrite
requirements.txtin the repository.
Focused Procedure
- Open a terminal and cd to the project root where
pyproject.tomllives. - Run the export command:
poetry export --without-hashes -f requirements.txt > requirements.txtExplanation of flags:
--without-hashesremoves the hash checks that Poetry adds by default, making the file compatible withpip install -rwithout requiring--hashsupport.-f requirements.txtforces the output format to a plainrequirements.txtfile.- Redirecting to
requirements.txtwrites the result to disk. If you prefer to keep the output on stdout, omit the redirection.
- Commit the generated file to version control or reference it directly in your CI configuration (e.g.,
pip install -r requirements.txt).
Expected Checks
- File existence: Verify that
requirements.txtexists and is non‑empty.test -s requirements.txt && echo "File OK" || echo "Missing or empty" - Reproducibility test: In a fresh virtual environment run:
Then comparepython -m venv .venv source .venv/bin/activate pip install -r requirements.txt pip list --format=freeze > installed.txtinstalled.txtwith the output ofpoetry show --tree --format=freezeto ensure identical package names and versions. - Dependency tree match: Run
and confirm that every top‑level dependency listed there appears inpoetry show --treerequirements.txtwith the exact version string.
Recovery Options
- Missing lock file: If the export fails with “No lock file found”, generate one with
poetry lockand retry. - Hash requirement: If your CI environment requires hash‑checking, remove
--without-hashesand keep the default hash lines. Ensure the CI runner supports--hashsyntax. - Unexpected packages: If
requirements.txtcontains packages you did not intend (e.g., optional extras), add the--without-optionalflag or explicitly exclude extras inpyproject.toml. Re‑export after adjustments. - Version mismatch: If
pip installpulls a different version, verify that thepoetry.lockfile is up‑to‑date. Runpoetry lock --no-updateto regenerate only the lock file without altering the lock state.
Limitations & Practical Verification
- Poetry’s export format changed in 1.3. Using an older Poetry version may not support
--without-hashes. Always confirmpoetry --version. - Exporting with
--devwill include development dependencies. Omit this flag for production CI builds. - Transitive dependencies may be renamed or re‑resolved by Poetry during export (e.g.,
typing‑extensionsvstyping‑extensions==4.5.0). Cross‑check againstpoetry.lockfor intended versions. - The exported file does not include environment markers for optional features. If your project relies on them, review the markers manually.
To verify reproducibility in production, store a checksum of the generated requirements.txt in your CI artifacts and compare it against future exports. A mismatch indicates a change in the lock file or Poetry version and warrants investigation.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.