Repository navigation
Fix Debian 7 docker image builds failing due to outdated wget/curl TLS - #1017
Merged
Merged
Conversation
Motivation: Debian 7 (wheezy) is EOL and archive.debian.org has no updated openssl/ca-certificates package for it. The ancient wget/curl in the image can no longer complete a TLS handshake with GitHub or sdkman.io, so downloading CMake, Ninja, Go, the precompiled GCC toolchain, the OpenSSL source tarball, and SDKMAN/the JDK inside the debian:7 stage now fails outright, independent of the existing --no-check-certificate/insecure-ssl workarounds already in place for the (now separate) certificate-validation problem. Modifications: Split Dockerfile.debian into a multi-stage build: a new debian:bookworm-slim downloader stage with a modern curl fetches all HTTPS artifacts (CMake, Ninja, Go, the GCC tarball, the OpenSSL source tarball, SDKMAN, and the JDK), and the debian:7 stage now only COPYs those artifacts in and compiles, without ever making a TLS connection itself. Result: Debian 7 docker images build again.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation:
Debian 7 (wheezy) is EOL and archive.debian.org has no updated
openssl/ca-certificates package for it. The ancient wget/curl in the
image can no longer complete a TLS handshake with GitHub or
sdkman.io, so downloading CMake, Ninja, Go, the precompiled GCC
toolchain, the OpenSSL source tarball, and SDKMAN/the JDK inside the
debian:7 stage now fails outright, independent of the existing
--no-check-certificate/insecure-ssl workarounds already in place for
the (now separate) certificate-validation problem.
Modifications:
Split Dockerfile.debian into a multi-stage build: a new debian:bookworm-slim
downloader stage with a modern curl fetches all HTTPS artifacts (CMake,
Ninja, Go, the GCC tarball, the OpenSSL source tarball, SDKMAN, and the
JDK), and the debian:7 stage now only COPYs those artifacts in and
compiles, without ever making a TLS connection itself.
Result:
Debian 7 docker images build again.