fix: bypass expired Debian 11 security repo in Dockerfile.build - #7782
Conversation
Temporary workaround for the Buildkite package build failures caused by the Debian 11 (Bullseye) security repository's InRelease file expiring after EOL. The root cause fix is upstream in golang-crossbuild: elastic/golang-crossbuild#754 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
🟢 Approval recommended
The change is narrowly scoped to the stated CI breakage, is clearly documented as temporary, and preserves existing build behavior aside from bypassing the expired metadata check.
Pull request overview
This PR applies a temporary workaround to keep Fleet Server’s packaging/build image functional now that Debian 11 (Bullseye) security repository metadata has expired, unblocking CI packaging jobs that run apt-get update inside Dockerfile.build.
Changes:
- Add an explanatory comment documenting the temporary nature of the workaround and linking the upstream fix to revert to.
- Pass
-o Acquire::Check-Valid-Until=falsetoapt-get updateso APT proceeds despite expiredInReleasemetadata.
File summaries
| File | Description |
|---|---|
| Dockerfile.build | Bypasses Debian 11 repo metadata “Valid-Until” expiry during apt-get update, with clear revert guidance tied to the upstream base image fix. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Caution agentic threat detected DetailsPotential security threats were detected in the agent output. Review the workflow run logs for details. TL;DRThe failing Remediation
Investigation detailsRoot CauseThe only hard failure in the provided job log is from the upload step in PR change scope is limited to Relevant changed file in PR:
Evidence
Verification
Follow-up
What is this? | From workflow: PR Buildkite Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
|
@Mergifyio backport 9.5 9.4 8.19 |
✅ Backports have been createdDetails
|
|
No longer needed as elastic/golang-crossbuild#754 was merged. Will revert. |
What is the problem this PR solves?
The Buildkite
Package x86_64andPackage aarch64jobs are failing (e.g. build #16689) because Debian 11 (Bullseye) reached EOL and its security repository'sInReleasefile has expired.apt-get updateinDockerfile.buildfails with:The root cause fix is in the upstream base image: elastic/golang-crossbuild#754, which switches Debian 11 sources to the archive and snapshot mirrors. This PR should be reverted once that PR is merged and new
golang-crossbuildimages are published.How does this PR solve the problem?
Passes
-o Acquire::Check-Valid-Until=falsetoapt-get updateinDockerfile.buildto bypass the expiry check. This does not change the Debian version being built for — the base image remainsgolang-crossbuild:*-debian11. Since Debian 11 is EOL, the security repo has no new updates regardless, so bypassing the validity check has no practical security impact.How to test this PR locally
Trigger a packaging build or run locally:
Design Checklist
Checklist
Related issues