I always advocate having custom-built docker images for CI, periodically refreshed for security fixes. CI should not run more than few seconds over the standard time to run the same thing from a dev machine.
However, other people around me are fine with apt installs and pip installs from global mirrors in every CI run. So I may be just autistic.
We set up a cache that detects when the project Dockerfiles or lockfiles change. If dependencies haven't changed, we check cache first, otherwise the image rebuilds as the first step of that pipeline and following pipeline steps use it. Best of both worlds.
wannabe44 · · focus · HN ↗
However, other people around me are fine with apt installs and pip installs from global mirrors in every CI run. So I may be just autistic.
pstuart · · focus · HN ↗
ehe78qhe · · focus · HN ↗