Skip to content

[8.19](backport #7782) fix: bypass expired Debian 11 security repo in Dockerfile.build - #7788

Closed
mergify[bot] wants to merge 1 commit into
8.19from
mergify/bp/8.19/pr-7782
Closed

mergify[bot] wants to merge 1 commit into
8.19from
mergify/bp/8.19/pr-7782

Conversation

@mergify

@mergify mergify Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

⚠️ TEMPORARY WORKAROUND — Revert once elastic/golang-crossbuild#754 is merged and new images are published

What is the problem this PR solves?

The Buildkite Package x86_64 and Package aarch64 jobs are failing (e.g. build #16689) because Debian 11 (Bullseye) reached EOL and its security repository's InRelease file has expired. apt-get update in Dockerfile.build fails with:

E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease is expired

The root cause fix is in the upstream base image: elastic/golang-crossbuild#754, which switches Debian 11 sources to the archive and snapshot mirrors. This PR should be reverted once that PR is merged and new golang-crossbuild images are published.

How does this PR solve the problem?

Passes -o Acquire::Check-Valid-Until=false to apt-get update in Dockerfile.build to bypass the expiry check. This does not change the Debian version being built for — the base image remains golang-crossbuild:*-debian11. Since Debian 11 is EOL, the security repo has no new updates regardless, so bypassing the validity check has no practical security impact.

How to test this PR locally

Trigger a packaging build or run locally:

docker build -t fleet-server-builder:test --build-arg GO_VERSION=$(cat .go-version) --build-arg SUFFIX=main-debian11 -f Dockerfile.build .

Design Checklist

  • I have ensured my design is stateless and will work when multiple fleet-server instances are behind a load balancer.
  • I have or intend to scale test my changes, ensuring it will work reliably with 100K+ agents connected.
  • I have included fail safe mechanisms to limit the load on fleet-server: rate limiting, circuit breakers, caching, load shedding, etc.

Checklist

  • I have commented my code, particularly in hard-to-understand areas

Related issues

Temporary workaround for the Buildkite package build failures caused by
the Debian 11 (Bullseye) security repository's InRelease file expiring
after EOL. The root cause fix is upstream in golang-crossbuild:
elastic/golang-crossbuild#754

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
(cherry picked from commit bc44a05)
@mergify
mergify Bot requested a review from a team as a code owner September 9, 2026 07:20
@mergify mergify Bot added the backport label Sep 9, 2026
@mergify
mergify Bot requested review from samuelvl and swiatekm and removed request for a team September 9, 2026 07:20
@mergify mergify Bot added the backport label Sep 9, 2026
@github-actions github-actions Bot added bug Something isn't working Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team skip-changelog labels Sep 9, 2026
@ycombinator

Copy link
Copy Markdown
Contributor

Closing unmerged as main PR was no longer needed: #7782 (comment)

@ycombinator ycombinator closed this Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport bug Something isn't working skip-changelog Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant