Repository navigation
Run the NodeSource setup script as root so the image ships Node 24 and npm - #18
Open
eastagiletracker wants to merge 1 commit into
Open
eastagiletracker wants to merge 1 commit into
eastagiletracker wants to merge 1 commit into
Conversation
The image is meant to ship the Node version the Dockerfile names, but it ships
Ubuntu's nodejs 18.19.1 and no npm at all. The setup script is piped into bash as
the unprivileged runner user, so it cannot write apt's lists:
E: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied)
E: Unable to lock directory /var/lib/apt/lists/
Error: Failed to run 'apt update' (Exit Code: 0)
The script still exits 0, so the && chain continues and apt-get install -y nodejs
is satisfied by the distro package instead. The NodeSource repo has therefore
never been configured, and 70b05ff bumping setup_20.x to setup_24.x changed
nothing about the image.
Pipe to sudo -E bash - per NodeSource's documented install, and assert node and
npm afterwards so the layer fails loudly instead of silently installing the wrong
runtime, matching the version checks the other install layers already run.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR proposes running the NodeSource setup script with root privileges so the image ships the Node 24 the Dockerfile asks for, together with npm. We include this PR work along with a full history of your repo at https://eastagiletracker.com/projects/423. You can sign in with your GitHub ID to claim ownership of the project.
The defect
The published image ships Ubuntu's
nodejs18.19.1 and nonpmat all, rather than the Node 24 the Dockerfile names. Node 18 reached end of life on 2025-04-30.The OS-packages layer pipes NodeSource's installer straight into
bashas the unprivilegedrunneruser:Without root the script cannot write apt's lists. Building the current
mainprints its complaint and then exits 0 anyway:Because the script exits 0 the
&&chain continues, andsudo apt-get install -y nodejsis satisfied by Ubuntu 24.04's own package instead. Ubuntu packages npm separately — apt lists it only underSuggested packages— so npm never lands either. The build stays green throughout, which is why this has gone unnoticed: the NodeSource repository has never actually been configured, so 70b05ff ("updated version on nodejs") bumpingsetup_20.xtosetup_24.xchanged nothing about the image.Reproduced at HEAD (e403be3)
The change
Pipe the setup script to
sudo -E bash -, which is NodeSource's documented invocation, and then assertnode --version && npm --versionso the layer fails loudly instead of silently installing the wrong runtime. That assertion follows the idiom the Atmos, Terraform, Helm and kubectl layers already use, where each install ends in a version check.Verification
Rebuilt from this branch, the image is what the Dockerfile asked for:
The ten tool checks in
.github/workflows/test-docker-image.yamlwere run against both the HEAD image and this branch's image: ten pass and none fail, identically on both, so atmos, terraform, tfcmt, terraform-docs, infracost, helm, helmfile, kubectl, helm diff and aws are unaffected. git, jq, ssh, unzip, zip, curl, perl and python3 are all still present too.Those checks were run locally rather than through that workflow, because it pushes the built image to the registry before verifying it and a pull request from a fork has no token to push with — so expect that check to stop at the push step here regardless of this change.
The added assertion is not decorative — putting it on the current unprivileged line turns this silent substitution into a build failure:
One point for your judgement
This moves the runner image from Node 18 to Node 24, which is what the Dockerfile has requested since 70b05ff, but it is still a real change for jobs that have been running on 18, and
npmappears where there was none. The defect being fixed is that the setup script has to run as root; which major version you land on is a separate one-character decision on the same line, so please pin it to whatever suits your fleet.How this was managed
We tracked this change on a board imported from this repository's pull request history (17 stories), and this work is the story Run the NodeSource setup script as root so the image ships Node 24 and npm, which carries the reproduction and the verification above. The full board is at https://eastagiletracker.com/projects/423.
If you'd rather not receive contributions like this, reply
no-more-prson this pull request and we won't open any further ones on your repositories.Lawrence W. Sinclair
CEO / East Agile
linkedin.com/in/lwsinclair/
eastagile.com