Description
When an index refresh such as apt-get update runs in a separate RUN, Docker can reuse its earlier layer. If only the later installation command changes, installation may use a stale index and fail or produce unexpected results.
Combining the commands reruns the refresh when the installation instruction changes. The entire RUN can still be cached, so review build-cache policy when fresh package information is required.
Potential impact
- Downloads or installation can fail against stale indexes and delay deployment.
- Different cache states can make installation results harder to track.
Remediation
- Keep index refresh and installation together, as in apt-get update && apt-get install ....
- Refresh that layer’s cache when new information is needed. Manage base images, package versions and repositories when reproducibility is required.
- The meaning of update differs between package managers. Distinguish index refresh from package upgrades and remove unnecessary caches in the same RUN.
Examples
The existing Ubuntu examples compare APT index-refresh and installation order only. Package-cache cleanup is omitted.
Before
dockerfile
FROM ubuntu:24.04
RUN apt-get update
RUN apt-get install -y curl
After
dockerfile
FROM ubuntu:24.04
RUN apt-get update \
&& apt-get install -y curl
Explanation:
- Before: The refresh layer can be reused while the installation runs again.
- After: Index refresh and installation run together. This does not eliminate whole-layer cache reuse or package-version changes.