Fix broken apt sources, fail fast on apt errors, and smoke test the image - #20
Merged
Merged
Conversation
…mage The custom sources.list used https before ca-certificates was installed, so every configured repository failed during the build and the image silently fell back to the base image's main-only sources. It also listed suites that do not exist (testing-security/updates, testing-backports), which break apt-get update in child images once ca-certificates is present. - Replace sources.list with a deb822 debian.sources that enables contrib, non-free and non-free-firmware for testing, testing-updates and testing-security; bootstrap switches it to https after installing ca-certificates. - Run bootstrap.sh with errexit and apt-get update --error-on=any so a broken repository fails the build instead of shipping a stale image. - Drop the transitional apt-transport-https package. - Use COPY instead of ADD, add OCI labels, and fix the bashrc command-not-found handler that called the removed /usr/bin/python. - Add tests/smoke.sh and run it, plus shellcheck and hadolint, in the Anchore workflow that gates Dependabot auto-merge. - Build and smoke test the image before publishing, and push a dated tag alongside latest. - Bump docker/build-push-action to v7 and declare workflow permissions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB
testing-security normally carries no packages, so apt-cache policy lists no indexes for it and the per-component checks failed even though apt-get update fetched the suite successfully. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A review of the repo found that the custom apt configuration has been silently broken, so the image was not getting
contrib,non-freeornon-free-firmwarepackages at all.Evidence from the Docker workflow build on 2026-09-21, for every platform:
Root causes:
sources.listuses https, butdebian:testing-slimships withoutca-certificates, so every custom source fails during the build. Packages only came from the base image's owndebian.sources, which ismainonly over http.testing-security/updatesandtesting-backportsare not real suites. Onceca-certificatesis installed, child images runningapt-get updatehit these entries.bootstrap.shhas noerrexit, so all of this was swallowed and the build reported success.Changes
sources.listwith a deb822debian.sourcescoveringtesting,testing-updatesandtesting-securitywithmain contrib non-free non-free-firmware. It overwrites the base image's file, so there are no duplicate entries. Bootstrap starts on http, installsca-certificates, then switches to https and refreshes.bootstrap.shruns witherrexit/pipefailandapt-get update --error-on=any, so a broken repository fails the build rather than publishing a stale image.apt-transport-httpspackage.COPYinstead ofADD,COPY --chmodin place of a separatechmodlayer, and OCI labels. ExistingENVvalues and/app/lib/common.share unchanged for child images.command-not-foundhandler called/usr/bin/python, which no longer exists; it now matches Debian's current handler.tests/smoke.shchecks apt config, that every repository and component resolves, installed tooling, environment, thecommon.shhelpers, and that the bashrc loads cleanly.YYYYMMDDtag next tolatest, so child images can pin a known-good snapshot.docker/build-push-actionv5 → v7. This supersedes Dependabot's ci: bump docker/build-push-action from 5 to 7 #8, which passed CI in July but was never merged; it predates the auto-merge hardening.permissions..dockerignoreexcludes.git,.githubandtests; README documents tags, contents, testing and CI.Behavior changes for child images
/etc/apt/sources.listno longer exists; sources live in/etc/apt/sources.list.d/debian.sources. A child image that editssources.listdirectly would need updating.contrib/non-free/non-free-firmwarepackages now actually install.Testing
kjake/base:latestwithSMOKE_OFFLINE=1: the smoke test fails 4 checks. It flags the legacysources.list, the lack of https, and the missing components. Every other check passes, which confirms the test reproduces the problem.apt-get updateinstead of continuing. The full build plus smoke test runs in the Anchore workflow on this PR.🤖 Generated with Claude Code
https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB
Generated by Claude Code