devcontainers / devcontainers/cli
Empty ${localEnv:} in mount source should skip the mount, not pass empty source to Docker
- Dominant language
- TypeScript
- Stars
- 3k
- Forks
- 457
- Avg merge
- 13h 17m
- Merged PRs (30d)
- 6
Description
## Problem
When a `devcontainer.json` defines a mount using `${localEnv:SSH_AUTH_SOCK}` and the environment variable is unset or empty, the CLI resolves it to an empty string and passes `source=,target=/run/ssh-agent.sock,type=bind` to `docker run`. Docker rejects this:
```
invalid argument "source=,target=/run/ssh-agent.sock,type=bind" for "--mount" flag: invalid value for 'source': value is empty
```
This is particularly problematic when using pre-built images (via `devcontainers/ci`) because the mount is baked into the image's `devcontainer.metadata` label and cannot be overridden at runtime (the spec merges mount arrays by concatenation).
## Expected behavior
When `${localEnv:VAR}` resolves to empty in a mount's `source`, the CLI should skip that mount entirely rather than passing an invalid empty source to Docker.
## Reproduction
1. Create a `devcontainer.json` with:
```json
"mounts": [
"source=${localEnv:SSH_AUTH_SOCK},target=/run/ssh-agent.sock,type=bind"
]
```
2. Run `devcontainer up` in an environment where `SSH_AUTH_SOCK` is unset
3. Observe Docker failure due to empty mount source
## Context
- CLI version: 0.85.0
- Related: devcontainers/ci#166 (request to disable mounts in CI builds)
- This affects any CI/CD environment that uses pre-built devcontainer images where the build host had `SSH_AUTH_SOCK` set but the runtime host does not
Contributor guide
Assessment
This issue has not been assessed yet.