quaint-telephone-89068
08/13/2026, 10:32 AMskip_push=True on docker_image targets does not prevent pushing images that are dependencies of an image that "should" be pushed. (Unsure if this applies to other publishable targets beyond docker_image)
Given a BUILD file like this in src/docker
docker_image(
name="python_base",
instructions=[
"FROM python:latest",
],
skip_push=True,
)
docker_image(
name="production",
repository="production-image",
image_tags=["latest"],
instructions=[
"ARG BASE_IMAGE=:python_base",
"FROM $BASE_IMAGE",
],
)
In pants 2.31 the command pants publish src/docker: will respect the skip_push field, and only push the :production image. But in pants 2.32, this command will attempt to publish both images.
Pants version
2.32
OS
Linux. Do not have MacOS available to test.
Additional info
This seems to only affect targets that are selected by the target selection on the cli command, not targets that are pulled in by dependency inference. For example, using pants publish src/docker:production will behave correctly. It will package src/docker:python_base, but not attempt to publish it.
Since listing exact target names on the cli is not very ergonomic, I came up with a workaround that can be applied more generically:
docker_image(
name="python_base",
instructions=[
"FROM python:latest",
],
# skip_push field is broken in pants 2.32. This tag is a workaround
tags=["no_push"],
skip_push=True,
)
Then using pants --tag="-no_push" publish src/docker: will work correctly, but still allow large-scale target selection.
pantsbuild/pants