Skip to content

Fix broken apt sources, fail fast on apt errors, and smoke test the image - #20

Merged
kjake merged 2 commits into
masterfrom
claude/eager-fermi-xq00ss
Sep 28, 2026
Merged

kjake merged 2 commits into
masterfrom
claude/eager-fermi-xq00ss

Conversation

@kjake

@kjake kjake commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Summary

A review of the repo found that the custom apt configuration has been silently broken, so the image was not getting contrib, non-free or non-free-firmware packages at all.

Evidence from the Docker workflow build on 2026-09-21, for every platform:

W: Failed to fetch https://cdn-fastly.deb.debian.org/debian/dists/testing/InRelease  SSL connection failed: ... certificate verify failed
W: Failed to fetch https://security.debian.org/debian-security/dists/testing-security/updates/InRelease  ...
W: Failed to fetch https://cdn-fastly.deb.debian.org/debian/dists/testing-backports/InRelease  ...
W: Some index files failed to download. They have been ignored, or old ones used instead.

Root causes:

  1. sources.list uses https, but debian:testing-slim ships without ca-certificates, so every custom source fails during the build. Packages only came from the base image's own debian.sources, which is main only over http.
  2. testing-security/updates and testing-backports are not real suites. Once ca-certificates is installed, child images running apt-get update hit these entries.
  3. bootstrap.sh has no errexit, so all of this was swallowed and the build reported success.

Changes

  • apt sources: replace sources.list with a deb822 debian.sources covering testing, testing-updates and testing-security with main contrib non-free non-free-firmware. It overwrites the base image's file, so there are no duplicate entries. Bootstrap starts on http, installs ca-certificates, then switches to https and refreshes.
  • Fail fast: bootstrap.sh runs with errexit/pipefail and apt-get update --error-on=any, so a broken repository fails the build rather than publishing a stale image.
  • Drop the transitional apt-transport-https package.
  • Dockerfile: COPY instead of ADD, COPY --chmod in place of a separate chmod layer, and OCI labels. Existing ENV values and /app/lib/common.sh are unchanged for child images.
  • bashrc: the command-not-found handler called /usr/bin/python, which no longer exists; it now matches Debian's current handler.
  • Tests: new tests/smoke.sh checks apt config, that every repository and component resolves, installed tooling, environment, the common.sh helpers, and that the bashrc loads cleanly.
  • CI
    • The Anchore workflow now runs shellcheck, hadolint and the smoke test before scanning. Dependabot auto-merge waits on this workflow, so a failing test blocks auto-merges too.
    • The Docker workflow builds and smoke tests the native image before pushing. It also pushes a dated YYYYMMDD tag next to latest, so child images can pin a known-good snapshot.
    • Bump docker/build-push-action v5 → v7. This supersedes Dependabot's ci: bump docker/build-push-action from 5 to 7 #8, which passed CI in July but was never merged; it predates the auto-merge hardening.
    • Declare explicit workflow permissions.
  • .dockerignore excludes .git, .github and tests; README documents tags, contents, testing and CI.

Behavior changes for child images

  • /etc/apt/sources.list no longer exists; sources live in /etc/apt/sources.list.d/debian.sources. A child image that edits sources.list directly would need updating.
  • contrib/non-free/non-free-firmware packages now actually install.

Testing

  • Locally: shellcheck, hadolint and actionlint all pass.
  • Locally, against the currently published kjake/base:latest with SMOKE_OFFLINE=1: the smoke test fails 4 checks. It flags the legacy sources.list, the lack of https, and the missing components. Every other check passes, which confirms the test reproduces the problem.
  • Local build: the sandbox blocks Debian mirrors, and the build now correctly stops at the first failed apt-get update instead of continuing. The full build plus smoke test runs in the Anchore workflow on this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB


Generated by Claude Code

…mage

The custom sources.list used https before ca-certificates was installed,
so every configured repository failed during the build and the image
silently fell back to the base image's main-only sources. It also listed
suites that do not exist (testing-security/updates, testing-backports),
which break apt-get update in child images once ca-certificates is present.

- Replace sources.list with a deb822 debian.sources that enables contrib,
  non-free and non-free-firmware for testing, testing-updates and
  testing-security; bootstrap switches it to https after installing
  ca-certificates.
- Run bootstrap.sh with errexit and apt-get update --error-on=any so a
  broken repository fails the build instead of shipping a stale image.
- Drop the transitional apt-transport-https package.
- Use COPY instead of ADD, add OCI labels, and fix the bashrc
  command-not-found handler that called the removed /usr/bin/python.
- Add tests/smoke.sh and run it, plus shellcheck and hadolint, in the
  Anchore workflow that gates Dependabot auto-merge.
- Build and smoke test the image before publishing, and push a dated tag
  alongside latest.
- Bump docker/build-push-action to v7 and declare workflow permissions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB
testing-security normally carries no packages, so apt-cache policy lists
no indexes for it and the per-component checks failed even though
apt-get update fetched the suite successfully.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VjhVC5AtrNZY7RnkkuqPwB
@kjake
kjake marked this pull request as ready for review September 28, 2026 02:26
@kjake
kjake merged commit a312386 into master Sep 28, 2026
2 checks passed
@kjake
kjake deleted the claude/eager-fermi-xq00ss branch September 28, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants