Answer the Question First
1. Yes. Adding a repos entry to renv.lock guarantees that renv::restore() can find package sources even when the server has no outbound network access. The lockfile must contain the exact repository URLs that were used when the project was created.
2. The primary environment variable that can override the lockfile’s repos setting is R_RENV_REPOS. If this variable is set, renv will use its value instead of the lockfile entry. Other R options such as repos (set via options(repos = …)) also influence the resolution, but R_RENV_REPOS is the dedicated override for renv.
3. A common strategy is to use a CRAN snapshot (e.g., via https://packagemanager.rstudio.com/all or https://cloud.r-project.org/ with a pinned mirror) and record that snapshot URL in the lockfile. Keep the same snapshot on both local and production machines to ensure identical package versions.
Why the repos Field Matters
The repos section tells renv where to download each package. Without it, renv falls back to the system’s default CRAN mirror, which may be unreachable or may have changed content since the lockfile was generated. In an offline environment this fallback simply fails, producing a generic “cannot open URL” error.
Steps to Resolve the Current Problem
Open the renv.lock file in a text editor.
Locate the top‑level repos key. If it is missing, add the following block, replacing https://cran.r-project.org with the exact mirror you used locally:
{
"repos": {
"CRAN": "https://cran.r-project.org"
}
}
Save the file.
On the production server, run:
Rscript -e "renv::restore(repos = getOption('repos'))"
If a custom mirror is required, set it explicitly:
Rscript -e "renv::restore(repos = list(CRAN = 'https://my.internal.cran/'))"
Verify that the installed package versions match those recorded in renv.lock by running:
Rscript -e "renv::status()"
Environment Variable Overrides
Consistent CRAN Snapshots Between Local and Production
1. Use a CRAN snapshot service (e.g., https://packagemanager.rstudio.com/all) that provides a stable URL for a specific date.
2. Record that URL in the repos section of renv.lock:
{
"repos": {
"CRAN": "https://packagemanager.rstudio.com/all/2026-09-01"
}
}
3. On all machines (local dev, CI, production), run renv::restore() without overriding repos. The snapshot guarantees that the same package binaries are fetched, ensuring reproducibility.
Ask for a Diagnostic Detail
Do you currently have a local CRAN mirror or a specific snapshot URL that you want to pin in the lockfile? Knowing this will allow us to provide the exact repository string to insert.