R renv lockfile repository configuration missing
0 reputation · 18 Jul 2022, 04:55 UTC
0 reputation · 18 Jul 2022, 04:55 UTC
Ensure that renv::restore() can install all required packages on a production server that has no outbound network access.
Locally the restore succeeds because renv falls back to the system's CRAN mirror when the lockfile lacks a repos field. On a server without internet, the same restore silently fails with a generic “cannot open URL” message.
The lockfile does not specify a repository, creating uncertainty whether to hard‑code a mirror or rely on dynamic resolution. This can lead to inconsistent package versions and silent failures.
1. Should the repos entry be added to the renv.lock file to guarantee reproducible restores in offline environments?
2. What environment variables could override the lockfile’s repository setting on a production server, and how can they be controlled?
3. Is there a recommended strategy for maintaining consistent CRAN snapshots between local and production deployments?
29275 reputation · 18 Jul 2022, 08:59 UTC
1. Yes. Adding a repos entry to renv.lock guarantees that renv::restore() can find package sources even when the server has no outbound network access. The lockfile must contain the exact repository URLs that were used when the project was created.
2. The primary environment variable that can override the lockfile’s repos setting is R_RENV_REPOS. If this variable is set, renv will use its value instead of the lockfile entry. Other R options such as repos (set via options(repos = …)) also influence the resolution, but R_RENV_REPOS is the dedicated override for renv.
3. A common strategy is to use a CRAN snapshot (e.g., via https://packagemanager.rstudio.com/all or https://cloud.r-project.org/ with a pinned mirror) and record that snapshot URL in the lockfile. Keep the same snapshot on both local and production machines to ensure identical package versions.
The repos section tells renv where to download each package. Without it, renv falls back to the system’s default CRAN mirror, which may be unreachable or may have changed content since the lockfile was generated. In an offline environment this fallback simply fails, producing a generic “cannot open URL” error.
Open the renv.lock file in a text editor.
Locate the top‑level repos key. If it is missing, add the following block, replacing https://cran.r-project.org with the exact mirror you used locally:
{
"repos": {
"CRAN": "https://cran.r-project.org"
}
}
Save the file.
On the production server, run:
Rscript -e "renv::restore(repos = getOption('repos'))"
If a custom mirror is required, set it explicitly:
Rscript -e "renv::restore(repos = list(CRAN = 'https://my.internal.cran/'))"
Verify that the installed package versions match those recorded in renv.lock by running:
Rscript -e "renv::status()"
export R_RENV_REPOS='{"CRAN": "https://my.internal.cran/"}'
options(repos = …)): Influences the base R package installer, but renv prefers R_RENV_REPOS when present.1. Use a CRAN snapshot service (e.g., https://packagemanager.rstudio.com/all) that provides a stable URL for a specific date.
2. Record that URL in the repos section of renv.lock:
{
"repos": {
"CRAN": "https://packagemanager.rstudio.com/all/2026-09-01"
}
}
3. On all machines (local dev, CI, production), run renv::restore() without overriding repos. The snapshot guarantees that the same package binaries are fetched, ensuring reproducibility.
Do you currently have a local CRAN mirror or a specific snapshot URL that you want to pin in the lockfile? Knowing this will allow us to provide the exact repository string to insert.
Use comments to ask for clarification. Post a solution as an answer.
29,275 reputation · 18 Jul 2022, 10:29 UTC
While adding a repos entry to renv.lock is the most reliable way to guarantee reproducibility, renv also lets you override the repository without touching the file. This can be handy when you want to keep the lockfile portable across environments.
renv::restore() ArgumentsCall renv::restore(repos = c(CRAN = "file://…")) to point the restore process at a local mirror or a pre‑downloaded package archive. The lockfile remains unchanged, but the restore will fetch from the supplied URL.
Instead of a global R_RENV_REPOS, place a RENV_REPOS entry in .Renviron inside the project root. renv reads this before the global setting, giving you per‑project control without affecting other R sessions.
Running renv::snapshot(repos = "https://packagemanager.rstudio.com/all") locks the lockfile to the exact snapshot available at that URL. When you later restore offline, you can point renv to a cached copy of that snapshot (e.g., a local tarball) and the package versions will match exactly.
Download the snapshot tarball to the production server.
Run renv::restore(repos = c(CRAN = "file://path/to/snapshot")).
Confirm renv::status() reports no pending changes.