#160 🐳 Is your Dockerfile shipping unnecessary bloat?

Happy Wednesday!

Here is issue #160 of our newsletter, bringing you news and the best tools for your current or future Rails projects…

1. 🐳 Your Dockerfile might be shipping gcc, make, and RSpec into production without realizing it. Gelsey breaks down why multi-stage Dockerfiles are worth the extra setup, using the throwaway build stage in Rails' own default Dockerfile as the example. See how splitting build tools from your final image shrinks it, speeds up layer caching, and cuts your CVE surface.

2. 🔒 Selling a gem behind a license, or keeping an internal SDK off RubyGems.org? The path you pick matters more than it looks. Henrique compares Git-based gems, self-hosted registries like Gemstash and Geminabox, and full commercial token-gated distribution used by Sidekiq Pro and Rails LTS.

3. 🔐 Rails 8 killed the need for Devise. But how do you actually test the new built-in generator? Prabin Poudel’s latest Minitest Rails chapter breaks down the entire flow: sign-in, sign-out, guest-only browsing, and password resets. It covers both integration coverage and system-test browser smokes.

4. 📖 Five chapters in, and the defaults are the point. Aaron Sumner’s Testing Rails from Scratch dives into Rails’ built-in Minitest stack from the ground up. Now covering Rails 8.1 and Ruby 4.0, with chapters 1–5 live on Leanpub and chapter 6 nearly ready. Grab it for $9 with lifetime updates while the book is still in progress.

5. 🐢 A production server that quietly stalls, on a schedule nobody can reproduce on demand, is the worst kind of bug. Babylist's engineering team traced a recurring Server-Sent Events hang back to a subtle race condition in Rails itself and got the fix merged upstream. A good read for anyone running long-lived streaming connections in production.

6. ⏱️ The account has an ID. The request log shows a successful INSERT. The worker still gets RecordNotFound. RailsRevelry traces why after_save can hand a job an ID before another connection can see the row; the "record clock" and the "transaction clock" are two different things. This deep dive explains why after_commit is the only guarantee for cross-connection visibility.

7. 💎 Omakase Agents by Esshka: What if you skipped the tool abstraction, the JSON parsing, and the registry to keep in sync? This ~800-line Ruby framework turns an agent into a plain object where fields are state, ordinary methods are tools, and runtime-defined methods are written by the model at runtime. It returns real Ruby objects instead of JSON to parse and comes with practical Rails guidance on threading, connection pooling, and keeping generation off the request thread.

8. 📈 "Rails and AI pair well together" has been a vibe. Now there's a leaderboard. The Rails Foundation commissioned Evil Martians to build Agents on Rails, an ongoing benchmark of coding agents on real Rails codebases. The first report ranked Claude Opus 5 at 92% accuracy and found that knowing a Rails API by name mattered more than raw model strength. A follow-up added four more models and dug into behavioral quirks the pass rate doesn't show, like GLM 5.3 re-running the test suite 20 times per task.

Upcoming Events & Learning

Check out our other articles on: ​​​Ruby | Rails | Compatibility | ​​Upgrades​​​​ | ​​​​Tech Debt​​​ | AI

Bookmark, share, or save them for later. We hope these links are helpful. 😉

Best,

The ​​​​​​FastRuby.io​​​​​​ Team

Do you know anyone who would love to receive this newsletter? Tell them to subscribe👇 and catch the latest issue right in their inbox.

Don't wait to bring your Rails application up to date.

We will get on a quick call and recommend a couple of options to start upgrading your Rails app.