Stale cache reported by podman build despite changed external package sources
0 reputation · 08 Feb 2026, 01:06 UTC
Goal: Understand why podman build --layers can report "Using cache" for a step while the resulting image contains stale output caused by changes to external inputs such as package repository metadata or remote downloads.
Constraints: The build cache key incorporates only the instruction text and, for COPY/ADD, the content or metadata of the files added inside the build context. Anything a RUN step fetches from outside the context (e.g., apt‑get update, curl of a mutable tag) does not influence the key, so the layer may be reused despite the external data having changed. It is unclear whether Podman should provide automatic invalidation for such external dependencies or whether users must rely on explicit cache‑busting techniques.
- Does Podman offer a built‑in mechanism to automatically invalidate a layer when external file metadata or repository state changes?
- Is using a changing ARG value (e.g., a timestamp) the recommended explicit cache‑busting approach for steps that depend on outside data?
- Can a
RUN --mount=type=cachebe configured to depend on external file checksums to achieve proper invalidation?