Skip to content

fix(superset): Remove NodeJS from final image - #1623

Merged
dervoeti merged 1 commit into
mainfrom
fix/superset-no-nodejs-in-final-image
Aug 27, 2026
Merged

fix(superset): Remove NodeJS from final image#1623
dervoeti merged 1 commit into
mainfrom
fix/superset-no-nodejs-in-final-image

Conversation

@dervoeti

@dervoeti dervoeti commented Aug 27, 2026

Copy link
Copy Markdown
Member

Description

The Superset image ships a full Node and npm installation that is only needed to build the frontend.

The reason is the download location: nvm.sh was written to /stackable/nvm.sh, and nvm derives its installation directory from the location of that script when NVM_DIR is unset. Node therefore ends up in /stackable/versions, and the final image copies /stackable/ from the builder as a whole.

Setting NVM_DIR=/opt/nvm and downloading nvm.sh there keeps the whole nvm tree outside the copied directory. This mirrors what the cdxgen Node installation in /opt/node-cdxgen already does.

Besides the smaller image, this also removes a Node runtime that is never executed but is picked up by the vulnerability scans.

Other images were checked and are not affected: Airflow, NiFi, Kafka, Trino and OPA ship no Node at all, and OpenSearch Dashboards needs it at runtime.

Definition of Done Checklist

Note

Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant.

Please make sure all these things are done and tick the boxes

  • Changes are OpenShift compatible
  • All added packages (via microdnf or otherwise) have a comment on why they are added
  • Things not downloaded from Red Hat repositories should be mirrored in the Stackable repository and downloaded from there
  • All packages should have (if available) signatures/hashes verified
  • Add an entry to the CHANGELOG.md file
  • Integration tests ran successfully
TIP: Running integration tests with a new product image

The image can be built and uploaded to the kind cluster with the following commands:

boil build <IMAGE> --image-version <RELEASE_VERSION> --strip-architecture --load
kind load docker-image <MANIFEST_URI> --name=<name-of-your-test-cluster>

See the output of boil to retrieve the image manifest URI for <MANIFEST_URI>.

@dervoeti dervoeti changed the title fix: superset no nodejs in final image fix(superset): Remove NodeJS from final image Aug 27, 2026
@dervoeti dervoeti self-assigned this Aug 27, 2026
@dervoeti dervoeti moved this to Development: Waiting for Review in Stackable Engineering Aug 27, 2026
@Techassi Techassi moved this from Development: Waiting for Review to Development: In Review in Stackable Engineering Aug 27, 2026
@dervoeti
dervoeti added this pull request to the merge queue Aug 27, 2026
@dervoeti dervoeti moved this from Development: In Review to Development: Done in Stackable Engineering Aug 27, 2026
Merged via the queue into main with commit 57a0076 Aug 27, 2026
3 checks passed
@dervoeti
dervoeti deleted the fix/superset-no-nodejs-in-final-image branch August 27, 2026 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: Done

Development

Successfully merging this pull request may close these issues.

2 participants