From ea82e83d1f30abd20d8f85368c97fc65d4ac6df0 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Mon, 28 Sep 2026 20:56:58 +0200 Subject: [PATCH] portal image: a base at least as new as the builder's glibc --- portal/Dockerfile | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/portal/Dockerfile b/portal/Dockerfile index d069692..37e055f 100644 --- a/portal/Dockerfile +++ b/portal/Dockerfile @@ -2,11 +2,19 @@ # project.uhhm.no (the same artifact the bare-metal instances run). # PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is # the whole upgrade. -FROM debian:bookworm-slim +# +# Arch, because that is what the release is built on. The published +# binary is dynamically linked against that runner's glibc, so a +# debian:bookworm-slim base - glibc 2.36 against the 2.38 the binary +# asks for - starts and immediately exits with a version error. The +# base has to be at least as new as the builder, and the builder is +# Arch, so this is Arch. gdo's image is the same base for the same +# reason. +FROM archlinux:base ARG PORTAL_RELEASE -RUN apt-get update \ - && apt-get install -y --no-install-recommends ca-certificates curl \ - && rm -rf /var/lib/apt/lists/* +RUN pacman -Sy --noconfirm --needed ca-certificates curl \ + && pacman -Scc --noconfirm \ + && rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/* WORKDIR /app RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \ | tar -xz -C /app \