You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a6bd65a
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/self-hosting/env/webapp.mdx
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -98,8 +98,8 @@ mode: "wide"
98
98
|`DEPLOY_REGISTRY_NAMESPACE`| No | trigger | Deploy registry namespace. |
99
99
|`DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY`| No | — | Raw IAM policy JSON applied via SetRepositoryPolicy to every ECR repo created by the webapp. Use to grant cross-account pull access to EKS workers when the ECR account is separate from the cluster account. |
100
100
|`DEPLOY_IMAGE_PLATFORM`| No | linux/amd64 | Deploy image platform, same values as docker `--platform` flag. |
101
-
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on. Comma-separated `runtime=image@sha256:<digest>` entries, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Runtimes: `node-22`, `node-24`, `node-26`, `bun`. The digest is required. An invalid value prevents the webapp from starting. See [custom base images](/self-hosting/overview#custom-base-images). |
102
-
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage images per runtime, same format and validation. Without an entry the build stage uses the published build image, or the base image plus a toolchain install when build extensions add image instructions. |
101
+
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on, as comma-separated `runtime=image@sha256:<digest>`. See [custom base images](/self-hosting/overview#custom-base-images). |
102
+
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage images, in the same format as `DEPLOY_BASE_IMAGES`. See [custom base images](/self-hosting/overview#custom-base-images). |
103
103
|`DEPLOY_TIMEOUT_MS`| No | 480000 (8m) | Deploy timeout (ms). |
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. With the Helm chart, set them through `webapp.extraEnvVars`.
111
+
Entries are comma-separated `runtime=image@sha256:<digest>`. The runtimes are `node-22`, `node-24`, `node-26` and `bun`, and every image must be pinned by digest. An invalid value prevents the webapp from starting. Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. With the Helm chart, set the variables through `webapp.extraEnvVars`.
112
112
113
-
Projects with `runtime: "node"` in their config resolve to the current default Node runtime (`node-24` today), so set that key for them. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade. Deploys using `--native-build`or`--local-bundle`are rejected when base images are configured, since those paths cannot apply them.
113
+
Runtimes with an entry build on that image; the others keep the published images. Deploys from CLI versions that cannot apply the images are rejected with an error asking to upgrade, and so are `--native-build`and`--local-bundle`deploys. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
114
114
115
-
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. It applies to deploys built with the CLI's local build path, which is what self-hosted instances use. `--from-bundle` deploys regenerate the Containerfile inside the bundle directory with these images. This is a self-hosting setting and does not apply to Trigger.dev Cloud.
115
+
You own a custom base image. It must provide:
116
116
117
-
You own a custom base image. A Node image must provide:
118
-
119
-
-`node` on `PATH` at the runtime's major version
120
-
-`busybox`, `ca-certificates`, `dumb-init`, `git` and `openssl`
121
-
- a `node` user
122
-
- glibc, so native modules built in the build stage load at runtime
123
-
124
-
A Bun image must provide:
125
-
126
-
-`bun` and `node` on `PATH`, because the final stage starts the app with `dumb-init node`
117
+
-`node` on `PATH` at the runtime's major version (for `bun`, both `bun` and `node`, because the final stage starts the app with `dumb-init node`)
127
118
-`busybox`, `ca-certificates`, `dumb-init`, `git` and `openssl`
128
-
- a `bun` user
119
+
- a `node` user (a `bun` user for the Bun runtime)
129
120
- glibc, so native modules built in the build stage load at runtime
130
121
131
-
A `DEPLOY_BUILD_BASE_IMAGES` image must contain everything the base image provides, plus the toolchain the published build images include: `python3`, `make` and `g++`. When a project's build extensions add image instructions, those instructions are replayed on the build-stage image, so it must be able to run them. Without a `DEPLOY_BUILD_BASE_IMAGES`entry, the build stage uses the published build image. The exception is a project whose build extensions add image instructions: its build stage is created from your base image and the toolchain is installed with `apt-get`, so the base image must be Debian-based for those projects. To avoid the published build image entirely, set both `DEPLOY_BASE_IMAGES` and `DEPLOY_BUILD_BASE_IMAGES`.
122
+
A `DEPLOY_BUILD_BASE_IMAGES` image needs everything the base image provides, plus `python3`, `make` and `g++`. Build extensions that add image instructionsare replayed on it. Without an entry, the build stage uses the published build image, except for projects whose build extensions add image instructions: those build from your base image and install the toolchain with `apt-get`, so that base must be Debian-based. To avoid the published images entirely, set both variables.
132
123
133
124
<Warning>
134
125
`image.pkgs` and build extensions that run `apt-get` (such as `aptGet` and `playwright`) assume a
0 commit comments