Skip to content

build(builder): make the lake-builder image rebuildable (bookworm, go.dev) - #9203

Merged
klesh merged 1 commit into
apache:mainfrom
DoDiODev:pr/lake-builder-rebuildable
Oct 11, 2026
Merged

klesh merged 1 commit into
apache:mainfrom
DoDiODev:pr/lake-builder-rebuildable

Conversation

@DoDiODev

@DoDiODev DoDiODev commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

devops/docker/lake-builder/Dockerfile (the source of mericodev/lake-builder:latest, which test.yml, test-e2e.yml, golangci-lint.yml and migration-script-lint.yml run in) can no longer be built:

  1. Debian 11 (bullseye) is gone. Its LTS period ended on 2026-08-31 and bullseye-security now answers 404, so the apt -y upgrade in every stage fails (libc6-dev, libssl-dev, libexpat1, … 404 Not Found). All three stages are based on bullseye (debian:bullseye ×2, python:3.9-slim-bullseye).
  2. The Go installer is fetched from git.io, which GitHub shut down in 2022 (curl -L https://git.io/vQhTU | bash).

So the next builder-* tag would fail, and any change to the CI toolchain baked into the image is currently impossible.

Changes

Stage / step Before After
debian-amd64 (sysroot for the libgit2 cross-build) debian:bullseye debian:bookworm
builder (libgit2 1.5.0) debian:bullseye debian:bookworm
final image python:3.9-slim-bullseye python:3.11-slim-bookworm (same line as the runtime image in backend/Dockerfile, #9005)
Go toolchain git.io installer script, Go 1.26.2 official go.dev/dl archive, Go 1.26.6, SHA-256 verified — version and checksum identical to backend/scripts/install-go.sh
swag v1.16.1 v1.16.6 (same as backend/Dockerfile and backend/Makefile; the library require in backend/go.mod is moved to v1.16.6 by Dependabot #9201)

mockery (v3.7.4), libgit2 (1.5.0), uv, GOPATH/GOROOT/PATH handling and the package list are unchanged. All packages exist under the same names in bookworm; libgit2 is now linked against OpenSSL 3 consistently in both the sysroot and the final image.

Python stays in the image because the Build Python steps in test.yml/test-e2e.yml still need it; once the Python subsystem is removed (#9092), the final stage can move to debian:bookworm-slim.

No workflow, Go, Python or lock-file change. The image only changes once a maintainer pushes a builder-* tag.

Verification

Check Result
docker build of the unchanged Dockerfile on upstream/main (as in build-builder.yml, ubuntu-24.04) ❌ 404 Not Found from bullseye-security (tzdata, openssl, ca-certificates, …)
same build with this PR ✅
Tools in the image Debian 12.15, Python 3.11.17, Go 1.26.6, mockery v3.7.4, swag v1.16.6 (prints v1.16.4, the version constant was not bumped upstream in that tag), uv 0.12.23, libgit2 1.5.0 linked against libssl.so.3
migration-script-lint.yml steps inside the new image ✅
test.yml steps inside the new image (install-libgit2.sh/install-go.sh/install-mockery.sh report "already installed", go mod tidy guard, make build-python, make unit-test) ✅

Fork run: https://github.com/DoDiODev/devlake/actions/runs/37490191399 (throwaway workflow that runs the same steps via docker run, since an unpublished image cannot be used as container:).

After merge, a maintainer needs to push a builder-* tag so that build-builder.yml publishes the new mericodev/lake-builder:latest.

The image behind `mericodev/lake-builder:latest` can no longer be built:

- Debian 11 (bullseye) left LTS on 2026-08-31 and `bullseye-security`
  now returns 404, so `apt -y upgrade` fails in all three stages.
- The Go toolchain was installed through a `git.io` short link, which
  GitHub shut down in 2022.

Move the libgit2 cross-build stages to `debian:bookworm` and the final
stage to `python:3.11-slim-bookworm` (same line as backend/Dockerfile).
Install Go 1.26.6 from go.dev with the SHA-256 used by
backend/scripts/install-go.sh, and align swag with backend/Makefile
(v1.16.6).

@klesh klesh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
Thanks for your contribution.

@klesh
klesh merged commit 0ce8f28 into apache:main Oct 11, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants