setup-node still downloaded although the image carried a perfect /opt/hostedtoolcache/node/26.8.2/x64/ tree. actions/tool-cache accepts a cached tool only when the sibling marker <version>/<arch>.complete exists (tc.find() tests it explicitly); a bare directory is ignored, so the probe fell through to the download. The marker is what tc.cacheDir() writes after installing a tool, so the baked entry must create it too. Job-container diagnostics also confirmed the path was never in question: RUNNER_TOOL_CACHE=/opt/hostedtoolcache, no mount over it, node -v from the baked path prints v26.8.2. CONTRIBUTING records both invariants — the marker, and the fact that a Dockerfile change keeps the same tag, which forcePull=false can hide.