ci: restore debian bullseye integration test via archive.debian.org - #1937
Merged
ShubhenduSinghF5 merged 3 commits intoSep 17, 2026
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## dev-v2 #1937 +/- ##
=========================================
Coverage ? 52.30%
=========================================
Files ? 51
Lines ? 3518
Branches ? 0
=========================================
Hits ? 1840
Misses ? 1533
Partials ? 145 Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
Debian bullseye reached LTS end-of-life on 2026-08-31 and the bullseye-security InRelease signature expired 2026-09-08, breaking apt-get update against the default deb.debian.org sources. PR nginx#1925 worked around this by dropping bullseye from the integration test matrix entirely. NGINX OSS and NGINX Plus still support bullseye, so agent CI should continue to validate against it. Rewrite the base image's apt sources.list to archive.debian.org for bullseye-slim only, guarded by a VERSION_CODENAME check in /etc/os-release so no other matrix row is affected. archive.debian.org is a Debian-project-maintained mirror that serves EOL releases with a non-expiring signing key already present in the base image's debian-archive-keyring package. Base image registry is unchanged: still docker.io/library/debian. No new external hosts are contacted from the shipped Agent binary or its packaged artifacts; this affects test/docker/ image builds only.
ShubhenduSinghF5
force-pushed
the
ss-restore-bullseye-archive
branch
from
September 16, 2026 17:12
a051a58 to
cc2c733
Compare
Previous commit rewrote /etc/apt/sources.list to archive.debian.org
inside the Dockerfile. That fixed InRelease expiry, but exposed a
second failure mode: debian:bullseye-slim ships preinstalled packages
from bullseye-security (e.g. perl-base 5.32.1-4+deb11u5, gpgv
2.2.27-2+deb11u3) that don't exist in archive.debian.org, so apt's
solver reports unmet dependencies:
gnupg : Depends: gpgv (< 2.2.27-2+deb11u2.1~)
but 2.2.27-2+deb11u3 is to be installed
perl : Depends: perl-base (= 5.32.1-4+deb11u3)
but 5.32.1-4+deb11u5 is to be installed
Switch to Debian's official EOL archive image
(docker.io/debian/eol:bullseye-slim), which is built directly from
archive.debian.org — its preinstalled packages and repo indices are
mutually consistent. Same publisher, same registry (docker.io),
signed with the same debian-archive-keyring key.
Scope the swap to OS_RELEASE=debian and OS_VERSION=bullseye-slim only
(Makefile conditional), so bookworm and every other matrix row are
byte-for-byte unchanged. OS_RELEASE stays 'debian' so the downstream
nginx-agent apt URL (packages.nginx.org/nginx-agent/debian/) is
unaffected.
Drop the now-redundant sed block from
test/docker/nginx-oss/deb/Dockerfile — debian/eol's sources.list
already targets archive.debian.org.
The debian/eol:bullseye-slim image was rebuilt after Debian 11 LTS EOL to point 'bullseye' and 'bullseye-updates' at archive.debian.org, but left 'bullseye-security' on deb.debian.org where the security pool has been pruned (InRelease still resolves but individual .deb files 404). The image's own /etc/apt/sources.list ships snapshot.debian.org URLs (commented) at the timestamp the image was built (20250809T133719Z), providing a fully self-consistent frozen apt world where preinstalled packages match repo indices. Enable those URLs plus the standard Acquire::Check-Valid-Until=false for archived snapshots. No version pins and no --allow-downgrades; the snapshot is the maintainer's documented answer for this scenario.
ShubhenduSinghF5
force-pushed
the
ss-restore-bullseye-archive
branch
from
September 17, 2026 07:08
e7c7b90 to
11111ca
Compare
balakoteswar
approved these changes
Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed changes
Restore
bullseye-slimto the integration test matrix. PR #1925 dropped it because Debian 11 LTS EOL (2026-08-31) broke everydebian:bullseye-slimCI job:bullseye-securitywas pruned fromdeb.debian.organd the base image itself started drifting out of a consistent apt state.NGINX OSS and NGINX Plus continue to support bullseye, so the agent must too.
Fix (three coordinated pieces)
Makefile— forbullseye-slimonly, swap the base image fromdebian:bullseye-slimto
debian/eol:bullseye-slim(the maintainer-blessed post-EOL image). All othermatrix rows resolve
BASE_IMAGEunchanged..github/workflows/ci.yml— restorebullseye-slimto the integrationtest matrix (revert of the PR ci: bump packager base image from bullseye to bookworm #1925 removal).
test/docker/nginx-oss/deb/Dockerfile— for bullseye only, rewrite/etc/apt/sources.listto thesnapshot.debian.orgURLs that thedebian/eolimage maintainer already ships pre-configured (as commentedlines) at timestamp
20250809T133719Z, and setAcquire::Check-Valid-Until "false"(standard practice for pinned snapshots).Guarded by a
VERSION_CODENAME=bullseyecheck in/etc/os-release;other matrix rows are byte-for-byte unchanged.
Checklist
CONTRIBUTINGdocumentmake install-toolsand have attached any dependency changes to this pull requestREADME.md)