Skip to content

ci: bump packager base image from bullseye to bookworm - #1925

Merged
ShubhenduSinghF5 merged 3 commits into
nginx:dev-v2from
ShubhenduSinghF5:ss-fix-packager-bookworm
Sep 10, 2026
Merged

ci: bump packager base image from bullseye to bookworm#1925
ShubhenduSinghF5 merged 3 commits into
nginx:dev-v2from
ShubhenduSinghF5:ss-fix-packager-bookworm

Conversation

@ShubhenduSinghF5

Copy link
Copy Markdown

Summary

Debian 11 (bullseye) reached its LTS end-of-life on 2026-08-31. The Debian LTS team has stopped re-signing the bullseye-security suite, so its InRelease file's Valid-Until: timestamp is now expired. apt-get install inside the CI packager image fails hard as a result:

E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease
   is expired (invalid since 1d 9h 52min 52s). Updates for this repository will not be applied.
...
The command '/bin/sh -c apt-get update && apt-get install -y make jq gnupg gnupg1 ...' returned a non-zero code: 100

This breaks the Build unsigned snapshot and Build signed snapshot jobs on every open PR against dev-v2 right now (not tied to any single PR — it's environmental drift).

Fix

Bump the packager base image one release forward:

-FROM docker.io/golang:1.24-bullseye AS base
+FROM docker.io/golang:1.24-bookworm AS base
  • bookworm = Debian 12, current stable, security suite refreshed regularly through 2028.
  • All apt packages the packager installs (gpgv1, monkeysphere, aptly, debsig-verify, createrepo-c, dnf, rpm, and the lib*-dev family) are available in bookworm.
  • Only the internal CI builder image changes — the .deb / .rpm / .apk artifacts we ship to customers are unchanged (they are produced by nfpm inside this container).

Scope

  • scripts/packages/packager/Dockerfile (1 line)

Test plan

CI on this PR will exercise the change end-to-end:

  • Build unsigned snapshot — must go green (this is the currently-red job).
  • All other jobs unchanged.

Locally I confirmed that bookworm is the only bullseye reference in an active Dockerfile (test/docker/performance/Dockerfile has a commented-out 1~bullseye PKG_RELEASE line that is inert; the 500+ matches under pkgs*.nginx.* are published customer package filenames, unrelated to the build image).

Risk

Very low. Base image bump on a builder-only container.

Related

Blocks every open PR that runs build-unsigned-snapshot — including #1837 (nginx master process bug fix).

Debian 11 (bullseye) reached LTS end-of-life on 2026-08-31. The bullseye-security suite is no longer being re-signed, so its InRelease file '"Valid-Until"' timestamp has expired. apt-get install now fails inside the CI packager image with:

  E: Release file for .../bullseye-security/InRelease is expired

This breaks the "Build unsigned snapshot" and "Build signed snapshot" jobs on every PR against dev-v2. Bump the base image to golang:1.24-bookworm (Debian 12, currently the stable release with a fresh security suite). All apt packages used by the packager image (gpgv1, monkeysphere, aptly, debsig-verify, createrepo-c, dnf, rpm, and the lib*-dev family) are still available in bookworm.

Signed-off-by: shusingh <shu.singh@f5.com>
@ShubhenduSinghF5
ShubhenduSinghF5 requested a review from a team as a code owner September 9, 2026 07:13
@codecov

codecov Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (dev-v2@ed76366). Learn more about missing BASE report.

Additional details and impacted files
@@            Coverage Diff            @@
##             dev-v2    #1925   +/-   ##
=========================================
  Coverage          ?   52.16%           
=========================================
  Files             ?       51           
  Lines             ?     3518           
  Branches          ?        0           
=========================================
  Hits              ?     1835           
  Misses            ?     1538           
  Partials          ?      145           

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update ed76366...ff25966. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Debian bookworm dropped gnupg1, gpgv1 and monkeysphere (all GPG 1.x-era tooling). apt-get install fails on bookworm with:

  E: Package 'monkeysphere' has no installation candidate

None of these three packages are actually invoked by any script, Makefile, or packaging helper in this repo (grep confirms zero references outside this Dockerfile). They were vestigial residue from an era when debsig-verify needed PGP v3 tooling; modern gpg 2.x (installed as the gnupg package, still present) handles everything the packager and debsig-verify need.

Also drops a pre-existing duplicate "make" in the same apt-get line.

Signed-off-by: shusingh <shu.singh@f5.com>
Debian bullseye reached LTS end-of-life on 2026-08-31 and the
bullseye-security InRelease signature expired on 2026-09-08, causing
apt-get update to fail in every debian:bullseye-slim CI job since.

Debian bullseye is no longer a supportable target for nginx-agent v2.47+.
Remove it from the integration test matrix in ci.yml and update the
supported-OS table in Makefile accordingly. Customers still on bullseye
should upgrade to bookworm; the packages built by the bookworm packager
(bumped in the previous commit) remain compatible with bullseye runtimes
that pull from unfrozen third-party repos.

@devbgv devbgv left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ShubhenduSinghF5
ShubhenduSinghF5 merged commit baea216 into nginx:dev-v2 Sep 10, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants