local_repository vs http_archive for Private Dependencies Under Hermetic Sandbox
0 reputation · 14 Jul 2020, 05:29 UTC
0 reputation · 14 Jul 2020, 05:29 UTC
A workspace declares a private dependency that exists on developer machines at a fixed absolute path. Using local_repository in WORKSPACE (or MODULE.bazel with local_path_override) lets the build succeed locally without network access. In production CI and remote execution, the same absolute path does not exist, and the hermetic sandbox prevents access to undeclared host files, causing the build to fail.
--incompatible_strict_action_env, sandbox mode) is mandatory in production and remote executors.sha256 is available without an internal artifact server.Switching to http_archive with an internal URL and declared sha256 restores hermeticity and reproducibility, but requires publishing the artifact to an internal server and populating the remote cache. Keeping local_repository preserves local speed but breaks production unless the same path is materialized in every executor (e.g., via a checked-in vendor directory or CI-mounted volume), which re-introduces non-hermetic assumptions.
Which approach better satisfies the constraint that the same source tree must build identically on a developer laptop, in CI, and on a remote executor without manual path provisioning? Should the dependency be vendored into the repository to avoid both network fetch and host-path reliance, or is an internal artifact server with pre-seeded remote cache the lower-maintenance path?
A thoughtful contribution can make all the difference. Be the first to share one.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.