@@ -102,7 +102,7 @@ elif [[ "${explicit_target}" == "0" ]]; then
102102 crates/navigator-server/* |deploy/docker/Dockerfile.server)
103103 build_server=1
104104 ;;
105- crates/navigator-sandbox/* |deploy/docker/Dockerfile.sandbox|python/* |pyproject.toml|uv.lock|dev-sandbox-policy.rego)
105+ crates/navigator-sandbox/* |deploy/docker/Dockerfile.sandbox|deploy/docker/openclaw-start.sh| python/* |pyproject.toml|uv.lock|dev-sandbox-policy.rego)
106106 build_sandbox=1
107107 ;;
108108 deploy/docker/Dockerfile.pki-job)
131131
132132build_start=$( date +%s)
133133
134- # Capture the sandbox image ID before rebuild so we can detect if it changed.
135- sandbox_image_id_before=" "
136- if [[ " ${build_sandbox} " == " 1" ]]; then
137- sandbox_image_id_before=$( docker images -q " navigator-sandbox:${IMAGE_TAG} " 2> /dev/null || true)
138- fi
134+ # Capture image IDs before rebuild so we can detect what changed.
135+ declare -A image_id_before=()
136+ for component in server sandbox pki-job; do
137+ var=" build_${component// -/ _} "
138+ if [[ " ${! var} " == " 1" ]]; then
139+ image_id_before[${component} ]=$( docker images -q " navigator-${component} :${IMAGE_TAG} " 2> /dev/null || true)
140+ fi
141+ done
139142
140143server_pid=" "
141144sandbox_pid=" "
@@ -174,36 +177,22 @@ build_end=$(date +%s)
174177log_duration " Image builds" " ${build_start} " " ${build_end} "
175178
176179declare -a pushed_images=()
177-
178- # Detect whether the sandbox image actually changed by comparing the Docker
179- # image ID before and after the build. This is a content-addressable hash so
180- # identical builds produce the same ID regardless of registry digest quirks.
181- sandbox_image_changed=0
182- if [[ " ${build_sandbox} " == " 1" ]]; then
183- sandbox_image_id_after=$( docker images -q " navigator-sandbox:${IMAGE_TAG} " 2> /dev/null || true)
184- if [[ -n " ${sandbox_image_id_before} " && -n " ${sandbox_image_id_after} " \
185- && " ${sandbox_image_id_before} " != " ${sandbox_image_id_after} " ]]; then
186- sandbox_image_changed=1
187- elif [[ -z " ${sandbox_image_id_before} " && -n " ${sandbox_image_id_after} " ]]; then
188- # First build — treat as changed
189- sandbox_image_changed=1
180+ declare -a changed_images=()
181+
182+ for component in server sandbox pki-job; do
183+ var=" build_${component// -/ _} "
184+ if [[ " ${! var} " == " 1" ]]; then
185+ docker tag " navigator-${component} :${IMAGE_TAG} " " ${IMAGE_REPO_BASE} /${component} :${IMAGE_TAG} "
186+ pushed_images+=(" ${IMAGE_REPO_BASE} /${component} :${IMAGE_TAG} " )
187+
188+ # Detect whether the image actually changed by comparing Docker image IDs.
189+ id_after=$( docker images -q " navigator-${component} :${IMAGE_TAG} " 2> /dev/null || true)
190+ id_before=${image_id_before[${component}]:- }
191+ if [[ -z " ${id_before} " || " ${id_before} " != " ${id_after} " ]]; then
192+ changed_images+=(" ${component} " )
193+ fi
190194 fi
191- fi
192-
193- if [[ " ${build_server} " == " 1" ]]; then
194- docker tag " navigator-server:${IMAGE_TAG} " " ${IMAGE_REPO_BASE} /server:${IMAGE_TAG} "
195- pushed_images+=(" ${IMAGE_REPO_BASE} /server:${IMAGE_TAG} " )
196- fi
197-
198- if [[ " ${build_sandbox} " == " 1" ]]; then
199- docker tag " navigator-sandbox:${IMAGE_TAG} " " ${IMAGE_REPO_BASE} /sandbox:${IMAGE_TAG} "
200- pushed_images+=(" ${IMAGE_REPO_BASE} /sandbox:${IMAGE_TAG} " )
201- fi
202-
203- if [[ " ${build_pki_job} " == " 1" ]]; then
204- docker tag " navigator-pki-job:${IMAGE_TAG} " " ${IMAGE_REPO_BASE} /pki-job:${IMAGE_TAG} "
205- pushed_images+=(" ${IMAGE_REPO_BASE} /pki-job:${IMAGE_TAG} " )
206- fi
195+ done
207196
208197if [[ " ${# pushed_images[@]} " -gt 0 ]]; then
209198 push_start=$( date +%s)
@@ -215,13 +204,15 @@ if [[ "${#pushed_images[@]}" -gt 0 ]]; then
215204 log_duration " Image push" " ${push_start} " " ${push_end} "
216205fi
217206
218- # If the sandbox image changed, evict the stale copy from k3s's containerd
219- # store so new sandbox pods pull the updated image from the registry.
220- # Without this, k3s uses its cached copy (imagePullPolicy defaults to
221- # IfNotPresent for non-:latest tags) and sandbox pods run stale code.
222- if [[ " ${sandbox_image_changed} " == " 1" ]]; then
223- echo " Sandbox image changed (${sandbox_image_id_before:- <none>} -> ${sandbox_image_id_after} ), evicting stale image from k3s..."
224- docker exec " ${CONTAINER_NAME} " crictl rmi " ${IMAGE_REPO_BASE} /sandbox:${IMAGE_TAG} " > /dev/null 2>&1 || true
207+ # Evict stale images from k3s's containerd store so new pods pull the
208+ # updated image from the registry. Without this, k3s uses its cached copy
209+ # (imagePullPolicy defaults to IfNotPresent for non-:latest tags) and pods
210+ # run stale code.
211+ if [[ " ${# changed_images[@]} " -gt 0 ]]; then
212+ echo " Evicting stale images from k3s: ${changed_images[*]} "
213+ for component in " ${changed_images[@]} " ; do
214+ docker exec " ${CONTAINER_NAME} " crictl rmi " ${IMAGE_REPO_BASE} /${component} :${IMAGE_TAG} " > /dev/null 2>&1 || true
215+ done
225216fi
226217
227218if [[ " ${needs_helm_upgrade} " == " 1" ]]; then
0 commit comments