← Problem Library
CI/CD L5 CICD-055 · 21 min

CodeBuild local cache reuses stale base layer after package repository changed

Build time looks great, but the produced image quietly carries an older package baseline because local Docker layer cache survives a repository-side base image update.

CI/CDPlatform ReliabilityLevel 5Pro21 min
Scenario

Build time looks great, but the produced image quietly carries an older package baseline because local Docker layer cache survives a repository-side base image update.

What to check first
  • Identify the primary failure signal in the Build Cache Integrity scenario.
  • Separate visible symptoms from the underlying technical dependency.
  • Describe the safest recovery path and the follow-up prevention work.
Checking checklist
  1. Summarize the current impact and the last known change.
  2. Collect direct evidence from logs, runtime state, and configuration before changing anything.
  3. Separate immediate recovery from permanent prevention work.
Recovery and prevention

Choose the smallest safe recovery action first, then record the prevention work that reduces repeat incidents.

Questions worth viewing together
Why are cache-accelerated builds risky after base image changes?

The build can stay fast and green while quietly reusing layers that no longer match the intended security baseline.