Repository navigation
build(builder): make the lake-builder image rebuildable (bookworm, go.dev) - #9203
Merged
Merged
Conversation
The image behind `mericodev/lake-builder:latest` can no longer be built: - Debian 11 (bullseye) left LTS on 2026-08-31 and `bullseye-security` now returns 404, so `apt -y upgrade` fails in all three stages. - The Go toolchain was installed through a `git.io` short link, which GitHub shut down in 2022. Move the libgit2 cross-build stages to `debian:bookworm` and the final stage to `python:3.11-slim-bookworm` (same line as backend/Dockerfile). Install Go 1.26.6 from go.dev with the SHA-256 used by backend/scripts/install-go.sh, and align swag with backend/Makefile (v1.16.6).
klesh
approved these changes
Oct 11, 2026
klesh
left a comment
Contributor
There was a problem hiding this comment.
LGTM
Thanks for your contribution.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
devops/docker/lake-builder/Dockerfile(the source ofmericodev/lake-builder:latest, whichtest.yml,test-e2e.yml,golangci-lint.ymlandmigration-script-lint.ymlrun in) can no longer be built:bullseye-securitynow answers404, so theapt -y upgradein every stage fails (libc6-dev,libssl-dev,libexpat1, …404 Not Found). All three stages are based on bullseye (debian:bullseye×2,python:3.9-slim-bullseye).git.io, which GitHub shut down in 2022 (curl -L https://git.io/vQhTU | bash).So the next
builder-*tag would fail, and any change to the CI toolchain baked into the image is currently impossible.Changes
debian-amd64(sysroot for the libgit2 cross-build)debian:bullseyedebian:bookwormbuilder(libgit2 1.5.0)debian:bullseyedebian:bookwormpython:3.9-slim-bullseyepython:3.11-slim-bookworm(same line as the runtime image inbackend/Dockerfile, #9005)git.ioinstaller script, Go 1.26.2go.dev/dlarchive, Go 1.26.6, SHA-256 verified — version and checksum identical tobackend/scripts/install-go.shswagbackend/Dockerfileandbackend/Makefile; the library require inbackend/go.modis moved to v1.16.6 by Dependabot #9201)mockery(v3.7.4), libgit2 (1.5.0),uv,GOPATH/GOROOT/PATHhandling and the package list are unchanged. All packages exist under the same names in bookworm; libgit2 is now linked against OpenSSL 3 consistently in both the sysroot and the final image.Python stays in the image because the
Build Pythonsteps intest.yml/test-e2e.ymlstill need it; once the Python subsystem is removed (#9092), the final stage can move todebian:bookworm-slim.No workflow, Go, Python or lock-file change. The image only changes once a maintainer pushes a
builder-*tag.Verification
docker buildof the unchanged Dockerfile onupstream/main(as inbuild-builder.yml,ubuntu-24.04)404 Not Foundfrombullseye-security(tzdata,openssl,ca-certificates, …)v1.16.4, the version constant was not bumped upstream in that tag), uv 0.12.23, libgit2 1.5.0 linked againstlibssl.so.3migration-script-lint.ymlsteps inside the new imagetest.ymlsteps inside the new image (install-libgit2.sh/install-go.sh/install-mockery.shreport "already installed",go mod tidyguard,make build-python,make unit-test)Fork run: https://github.com/DoDiODev/devlake/actions/runs/37490191399 (throwaway workflow that runs the same steps via
docker run, since an unpublished image cannot be used ascontainer:).After merge, a maintainer needs to push a
builder-*tag so thatbuild-builder.ymlpublishes the newmericodev/lake-builder:latest.