diff --git a/Dockerfile.cicd-base b/Dockerfile.cicd-base index d3116e8..161f787 100644 --- a/Dockerfile.cicd-base +++ b/Dockerfile.cicd-base @@ -19,34 +19,10 @@ ENV TZ=America/New_York # Configure timezone RUN ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone -# Install apt-fast with proper GPG handling -RUN apt-get clean && \ - rm -rf /var/lib/apt/lists/* && \ - for i in 1 2 3; do \ - echo "Attempt $i: Updating package lists..." && \ - apt-get update && break || \ - (echo "Update attempt $i failed, retrying..." && sleep 10); \ - done && \ - apt-get install -y \ - software-properties-common \ - gnupg \ - ca-certificates \ - curl \ - wget \ - && for i in 1 2 3; do \ - echo "Attempt $i: Adding apt-fast PPA..." && \ - add-apt-repository -y ppa:apt-fast/stable && \ - apt-get update && \ - apt-get install -y apt-fast && \ - break || \ - (echo "apt-fast installation attempt $i failed, retrying..." && sleep 10); \ - done \ - && rm -rf /var/lib/apt/lists/* - -# Configure apt-fast to use apt (not apt-get) with optimized settings -RUN echo 'apt-fast apt-fast/maxdownloads string 10' | debconf-set-selections && \ - echo 'apt-fast apt-fast/dlflag boolean true' | debconf-set-selections && \ - echo 'apt-fast apt-fast/aptmanager string apt' | debconf-set-selections +# Force apt repositories onto HTTPS so runner network policy does not depend on plain HTTP access. +RUN set -eux; \ + find /etc/apt -type f \( -name 'sources.list' -o -name '*.sources' -o -name '*.list' \) -print0 \ + | xargs -0 sed -i 's|http://ports.ubuntu.com/ubuntu-ports|https://ports.ubuntu.com/ubuntu-ports|g; s|http://archive.ubuntu.com/ubuntu|https://archive.ubuntu.com/ubuntu|g; s|http://security.ubuntu.com/ubuntu|https://security.ubuntu.com/ubuntu|g' # Configure apt timeouts and retries RUN echo 'Acquire::Retries "3";' > /etc/apt/apt.conf.d/80retries && \ @@ -54,8 +30,23 @@ RUN echo 'Acquire::Retries "3";' > /etc/apt/apt.conf.d/80retries && \ echo 'Acquire::https::Timeout "60";' >> /etc/apt/apt.conf.d/80retries && \ echo 'Acquire::ftp::Timeout "60";' >> /etc/apt/apt.conf.d/80retries -# Install system dependencies using apt-fast -RUN apt-fast update && apt-fast install -y \ +# Install system dependencies using plain apt-get for runner compatibility. +RUN set -eux; \ + apt-get clean; \ + rm -rf /var/lib/apt/lists/*; \ + for i in 1 2 3; do \ + echo "Attempt $i: Updating package lists..."; \ + if apt-get update; then \ + break; \ + fi; \ + if [ "$i" -lt 3 ]; then \ + echo "Update attempt $i failed, retrying..."; \ + sleep 10; \ + else \ + exit 1; \ + fi; \ + done; \ + apt-get install -y --no-install-recommends \ git \ curl \ ca-certificates \ @@ -75,12 +66,15 @@ RUN apt-fast update && apt-fast install -y \ libxkbcommon0 \ libasound2 \ tzdata \ + gnupg \ + wget \ && rm -rf /var/lib/apt/lists/* # Install Python 3.14 with retry and fallback mechanisms RUN for i in 1 2 3; do \ echo "Attempt $i: Adding deadsnakes PPA..." && \ add-apt-repository -y ppa:deadsnakes/ppa && \ + find /etc/apt -type f \( -name 'sources.list' -o -name '*.sources' -o -name '*.list' \) -print0 | xargs -0 sed -i 's|http://|https://|g' && \ apt-get update && \ break || \ (echo "Attempt $i failed, retrying in 10s..." && sleep 10); \ @@ -88,7 +82,7 @@ RUN for i in 1 2 3; do \ RUN for i in 1 2 3; do \ echo "Attempt $i: Installing Python 3.14..." && \ - timeout 300 apt-fast install -y \ + timeout 300 apt-get install -y --no-install-recommends \ python3.14 \ python3.14-venv \ python3.14-dev && \ @@ -102,8 +96,9 @@ RUN for i in 1 2 3; do \ echo "Attempt $i: Installing Node.js 24..." && \ curl -fsSL --connect-timeout 30 --max-time 300 \ https://deb.nodesource.com/setup_24.x | bash - && \ - apt-fast update && \ - timeout 300 apt-fast install -y nodejs && \ + find /etc/apt -type f \( -name 'sources.list' -o -name '*.sources' -o -name '*.list' \) -print0 | xargs -0 sed -i 's|http://|https://|g' && \ + apt-get update && \ + timeout 300 apt-get install -y --no-install-recommends nodejs && \ break || \ (echo "Attempt $i failed, retrying in 15s..." && sleep 15); \ done && \