Skip to content

Revert "fix: bypass expired Debian 11 security repo in Dockerfile.build" - #7789

Merged
ycombinator merged 1 commit into
mainfrom
revert-7782-fix/debian11-expired-security-repo
Sep 9, 2026
Merged

ycombinator merged 1 commit into
mainfrom
revert-7782-fix/debian11-expired-security-repo

Conversation

@ycombinator

Copy link
Copy Markdown
Contributor

Reverts #7782

See #7782 (comment)

Copilot AI lite review requested due to automatic review settings September 9, 2026 10:33
@ycombinator
ycombinator requested a review from a team as a code owner September 9, 2026 10:33
@ycombinator ycombinator added the Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team label Sep 9, 2026
@mergify

mergify Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

This pull request does not have a backport label. Could you fix it @ycombinator? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-./d./d is the label to automatically backport to the 8./d branch. /d is the digit
  • backport-active-all is the label that automatically backports to all active branches.
  • backport-active-8 is the label that automatically backports to all active minor branches for the 8 major.
  • backport-active-9 is the label that automatically backports to all active minor branches for the 9 major.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The revert can reintroduce CI/build failures unless the upstream golang-crossbuild:*debian11 images used by CI have been republished with fixed apt sources (or the base image usage is updated/pinned accordingly).

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Reverts the previously-added temporary apt-get update validity-bypass in Dockerfile.build, returning the builder image setup to the default apt behavior when building Fleet Server’s cross-compile builder container.

Changes:

  • Removed the Acquire::Check-Valid-Until=false workaround from apt-get update in Dockerfile.build.
  • Removed the associated “temporary workaround” comment block explaining the Debian 11 EOL repository expiry.
File summaries
File Description
Dockerfile.build Removes the temporary apt validity-bypass during builder image creation.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Dockerfile.build
@ycombinator
ycombinator enabled auto-merge (squash) September 9, 2026 11:08
@github-actions github-actions Bot mentioned this pull request Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

TL;DR

The Buildkite E2E failure is a code/config regression introduced by this PR: reverting Dockerfile.build brings back the Debian 11 apt-get update expiry failure path, and one E2E case (TestAgentGracefulForceUnenroll) fails in that run. The immediate action is to keep a Bullseye-compatible apt workaround (or move off Bullseye base images) instead of fully reverting it.

Remediation

  • Restore a Debian-11-safe update path in Dockerfile.build (for example, reintroduce apt-get -o Acquire::Check-Valid-Until=false update), or update the crossbuild base tag to one that no longer relies on expired Bullseye security metadata.
  • Re-run the Buildkite E2E pipeline after the Dockerfile adjustment, focusing on testing/e2e and TestStandAloneRunningSuite/TestAgentGracefulForceUnenroll.
Investigation details

Root Cause

PR #7789 changes only Dockerfile.build and removes the prior Bullseye expiry workaround:

  • Dockerfile.build diff in this PR replaces:
    • apt-get -o Acquire::Check-Valid-Until=false update
      with:
    • apt-get update

This is consistent with the PR title/body (revert of #7782) and with the known Debian 11 security repo expiry issue that #7782 explicitly worked around.

Evidence

  • Build: https://buildkite.com/elastic/fleet-server/builds/16704
  • Failing job/step: E2E Test (.buildkite/scripts/e2e_test.sh)
  • Key failing test from log:
    • --- FAIL: TestStandAloneRunningSuite/TestAgentGracefulForceUnenroll (220.21s)
    • FAIL github.com/elastic/fleet-server/testing/e2e

Although the attached excerpt mostly shows toxiproxy connection-closure warnings, the deterministic signal in this run is the suite-level fail anchored on TestAgentGracefulForceUnenroll while this PR only changes Docker build plumbing. Given that scope, the safest interpretation is environment/runtime regression induced by the Dockerfile revert, not an application logic change in fleet-server packages.

Verification

  • Local re-run was not performed in this read-only detective workflow.

Follow-up

  • If maintainers want to confirm non-flakiness, compare with adjacent successful runs of the same test on commits that still include the fix: bypass expired Debian 11 security repo in Dockerfile.build #7782 workaround.
  • If this is intentionally reverting due to upstream image fix, pin and reference the specific fixed golang-crossbuild image digest/tag in PR notes so CI behavior is reproducible.

What is this? | From workflow: PR Buildkite Detective

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

@ycombinator
ycombinator merged commit 4096f5c into main Sep 9, 2026
15 checks passed
@ycombinator
ycombinator deleted the revert-7782-fix/debian11-expired-security-repo branch September 9, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants