Review separate package-index refresh and installation

Refresh package indexes and install packages in the same RUN.

Description

When an index refresh such as apt-get update runs in a separate RUN, Docker can reuse its earlier layer. If only the later installation command changes, installation may use a stale index and fail or produce unexpected results.

Combining the commands reruns the refresh when the installation instruction changes. The entire RUN can still be cached, so review build-cache policy when fresh package information is required.

Potential impact

  • Downloads or installation can fail against stale indexes and delay deployment.
  • Different cache states can make installation results harder to track.

Remediation

  • Keep index refresh and installation together, as in apt-get update && apt-get install ....
  • Refresh that layer’s cache when new information is needed. Manage base images, package versions and repositories when reproducibility is required.
  • The meaning of update differs between package managers. Distinguish index refresh from package upgrades and remove unnecessary caches in the same RUN.

Examples

The existing Ubuntu examples compare APT index-refresh and installation order only. Package-cache cleanup is omitted.

Before

dockerfile
FROM ubuntu:24.04

RUN apt-get update
RUN apt-get install -y curl

After

dockerfile
FROM ubuntu:24.04

RUN apt-get update \
    && apt-get install -y curl

Explanation:

  • Before: The refresh layer can be reused while the installation runs again.
  • After: Index refresh and installation run together. This does not eliminate whole-layer cache reuse or package-version changes.

References