Commit dc53ed7
authored
build(base-image): make apt install resilient to transient mirror failures (#42221)
## Description
**TL;DR:** Make the base-image `apt` install resilient to transient
Ubuntu-mirror connection failures, so a momentary network blip on the
build host doesn't red the whole `Docker Base Image` build.
### Background / root cause
The `Docker Base Image` workflow (`deploy/docker/base.dockerfile`)
intermittently fails at the apt dependency-install layer when the
builder briefly can't reach the Ubuntu mirrors. Most recent example:
appsmith-ee run
[34570186320](https://github.com/appsmithorg/appsmith-ee/actions/runs/34570186320)
failed twice with `connect (101: Network is unreachable)` (IPv6) and
`connection timed out` (IPv4) to `archive.ubuntu.com` /
`security.ubuntu.com`. The same base-image build has flaked on apt
before (a same-SHA run failed, then passed, on 2026-09-05).
Verified cause: `ubuntu:24.04` ships **no** apt retry configuration —
`apt-config dump` shows no `Acquire::Retries` and there is no drop-in in
`/etc/apt/apt.conf.d/`, so the compiled default of **0 retries**
applies. A single dropped connection fails the build. The two GPG-key
`curl` fetches also had no retry, and the PostgreSQL one lacked `--fail`
(so an HTTP error body could be piped into `apt-key`).
### Changes (`deploy/docker/base.dockerfile`, apt layer only)
- Add a **build-scoped** apt drop-in before the apt operations:
`Acquire::Retries "3"` + `Acquire::http(s)::Timeout "30"`. It is deleted
in the same layer's cleanup (`rm -rf`), so the **shipped image's apt
behavior is unchanged**.
- Add `--retry 3 --retry-connrefused --connect-timeout 15
--retry-max-time 60` to the MongoDB and PostgreSQL key-fetch curls; add
`--fail` to the PostgreSQL one.
- Deliberately **not** done: no `Acquire::ForceIPv4` (IPv4 also timed
out in the incident, so it wouldn't help), and no change to the
deprecated `apt-key` usage (out of scope).
This matches the retry pattern already used in this file (the Keycloak
jar overlay uses `curl --fail --retry 3 --connect-timeout 15`).
### Scope / honest limitation
This reduces flake frequency for **transient** mirror blips. It will
**not** rescue a sustained multi-minute total egress outage — retries
only help if egress recovers within the retry window. That class of
failure is infra, not the Dockerfile.
### Verification
- `ubuntu:24.04` default confirmed: no `Acquire::Retries`, no apt.conf.d
retry drop-in → default 0.
- Built the exact RUN structure (comment + `\`-continuation + `printf`
drop-in + cleanup) with `docker build`: `apt-config dump` reports
`Acquire::Retries "3"`; the drop-in is removed by cleanup (`test ! -f`
passes); build prints success. BuildKit strips the inline `#` comment
lines before the shell runs (same idiom already in this file).
- All new `curl` flags accepted by `ubuntu:24.04`'s curl (connect
failure exit 7 with 3 retries observed; no unknown-option error).
### Impact on existing instances
None. The drop-in is created and deleted within the same build layer, so
the produced image is byte-equivalent in apt configuration to before.
Fresh install, upgrade-from-default, upgrade-from-customized, and
rollback are all unaffected (this only changes how the base image is
*built*, not its contents).
### Reviewers / second opinion
Approach independently reviewed by GPT-5.6 sol and reconciled: retries
tuned to 3 (not 5), `Acquire::Retries::Delay` dropped as redundant,
drop-in build-scoped rather than persisted, `--fail` not duplicated on
the mongo curl (already has `-f`), curl retries bounded, IPv4 not
forced.
Linear: https://linear.app/appsmith/issue/APP-15960
## Automation
/ok-to-test tags="@tag.All"
> Note: this is a build/base-image change; the meaningful CI gate is the
`Docker Base Image` build itself. Full Cypress requires a base-image
rebuild + deploy preview.
## Communication
Should the DevRel and Marketing teams inform users about this change?
- [ ] Yes
- [x] No
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Chores
- Improved container build reliability with retry and timeout handling
for package, signing-key, and Java downloads.
- Added clearer failure handling when signing keys or Java archives
cannot be downloaded or processed.
- Ensured temporary download files and package-manager settings are
cleaned up after installation, keeping the final image free of
build-time artifacts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Fixes
https://linear.app/appsmith/issue/APP-15960/base-image-build-make-apt-install-resilient-to-transient-mirror
<!-- This is an auto-generated comment: Cypress test results -->
> [!WARNING]
> Tests have not run on the HEAD
1d82958 yet
> <hr>Wed, 16 Sep 2026 07:48:45 UTC
<!-- end of auto-generated comment: Cypress test results -->1 parent 172b7c1 commit dc53ed7
1 file changed
Lines changed: 14 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
55 | 61 | | |
56 | 62 | | |
57 | 63 | | |
| |||
64 | 70 | | |
65 | 71 | | |
66 | 72 | | |
67 | | - | |
| 73 | + | |
| 74 | + | |
68 | 75 | | |
69 | 76 | | |
70 | | - | |
| 77 | + | |
| 78 | + | |
71 | 79 | | |
72 | 80 | | |
73 | 81 | | |
| |||
87 | 95 | | |
88 | 96 | | |
89 | 97 | | |
| 98 | + | |
90 | 99 | | |
91 | 100 | | |
92 | 101 | | |
| |||
102 | 111 | | |
103 | 112 | | |
104 | 113 | | |
105 | | - | |
106 | | - | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
107 | 117 | | |
108 | 118 | | |
109 | 119 | | |
| |||
0 commit comments