contree build in CLI 0.9.4 interprets a documented Dockerfile subset on the client and produces Sandboxes image checkpoints. It is distinct from importing an already-built OCI image and is not a general Docker build service.
Prerequisites and files
Complete Set up access, installjq, and run uv tool install "contree-cli==0.9.4". Create Dockerfile:
verify.py beside it:
Dockerfile and verify.py; the second block reuses CONTREE_SESSION, tag, and first_uuid from the first. Build, resolve the tag to an immutable UUID, and perform two independent read-only runs:
version-1. They leave the session on the first image because -D discards each run’s changes. The checks verify that the session still refers to the recorded UUID and print labelled read results.
Rebuild with a new value:
version-2 and that the disposable read leaves the session on the refreshed image. A tag can move, so evaluations should use the recorded UUID rather than the example tag.
The labelled reads should show:
FROM, RUN, COPY/ADD, WORKDIR, ENV, ARG, and USER; multi-stage AS is parsed but not executed. Each RUN creates a retained layer, and the client cache can reuse layers. Use --no-cache when a refresh must ignore that cache. A failed build should be retried from its declared inputs after correcting the failing directive; do not use the tag for downstream work until the rebuild passes. Checkpoint layers remain subject to image retention.
The verification reads the file created by the Dockerfile RUN. CLI 0.9.4 applies Dockerfile ENV while interpreting build steps, but this workflow does not rely on that value being inherited by later operations.
Registry imports instead use images.import_from() or images.oci() and capture a filesystem root. OCI runtime configuration does not define a later Sandboxes command.
The example leaves a named local CLI session, a movable remote tag, and its retained build images. Use a different unique name for another run. Remove local session bookkeeping with the documented CLI session command when it is no longer needed. Removing a tag can make its image eligible for deletion under the retention policy. Contact support if you need to delete retained images.
See Prepare and reuse environments and the CLI Dockerfile tutorial.