From fb8ed320e6bb6bd9c7ffc90bf4181650651d3691 Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 12:41:07 +0100 Subject: [PATCH 1/7] fix: apt failure masked in the base image build "a && b || true && c" binds left, so the "|| true" meant for mkdir also swallowed a failed package installation and let the build finish without sshd. --- images/Dockerfile.bread-22.04 | 2 +- images/Dockerfile.bread-24.04 | 2 +- images/Dockerfile.bread-25.10 | 2 +- images/Dockerfile.bread-26.04 | 2 +- images/Dockerfile.bread-26.10 | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index 4c6e109..729995e 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -9,7 +9,7 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ - mkdir /var/run/sshd || true && \ + mkdir -p /var/run/sshd && \ echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index 46b41d9..b88912a 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -9,7 +9,7 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ - mkdir /var/run/sshd || true && \ + mkdir -p /var/run/sshd && \ echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index 8d5df43..a82f50c 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -9,7 +9,7 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ - mkdir /var/run/sshd || true && \ + mkdir -p /var/run/sshd && \ echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index 3a16769..a1cc28e 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -9,7 +9,7 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ - mkdir /var/run/sshd || true && \ + mkdir -p /var/run/sshd && \ echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index 4a8efaf..0346305 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -9,7 +9,7 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ - mkdir /var/run/sshd || true && \ + mkdir -p /var/run/sshd && \ echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ From 4bf56c596374c3c2b9cd96bbefb562095b607935 Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 13:06:45 +0100 Subject: [PATCH 2/7] ci?: azure apt mirror for image builds archive.ubuntu.com served the amd64 indexes at 28 kB/s during the r22 release and the job timed out; the runner itself pulls from the azure mirror, so let docker build do the same. --- .github/workflows/build-and-test.yaml | 6 +++ .github/workflows/build-oci.yaml | 8 +++- hack/apt-mirror.sh | 37 +++++++++++++++++++ hack/build_image.sh | 3 ++ hack/hash_inputs.sh | 1 + images/Dockerfile.bread-22.04 | 12 +++++- images/Dockerfile.bread-24.04 | 12 +++++- images/Dockerfile.bread-25.10 | 12 +++++- images/Dockerfile.bread-26.04 | 12 +++++- images/Dockerfile.bread-26.10 | 12 +++++- images/Dockerfile.bread-chisel-releases-22.04 | 10 ++++- images/Dockerfile.bread-chisel-releases-24.04 | 10 ++++- images/Dockerfile.bread-chisel-releases-25.10 | 10 ++++- images/Dockerfile.bread-chisel-releases-26.04 | 10 ++++- images/Dockerfile.bread-chisel-releases-26.10 | 10 ++++- 15 files changed, 144 insertions(+), 21 deletions(-) create mode 100755 hack/apt-mirror.sh diff --git a/.github/workflows/build-and-test.yaml b/.github/workflows/build-and-test.yaml index 4ebef9f..9b583da 100644 --- a/.github/workflows/build-and-test.yaml +++ b/.github/workflows/build-and-test.yaml @@ -22,6 +22,12 @@ jobs: arch: arm64 runs-on: ${{ matrix.runner }} timeout-minutes: 30 + # apt inside `docker build` defaults to archive.ubuntu.com; the runner + # itself uses the azure mirror with archive as fallback. Same mirror, same + # failover, applied for the build only (hack/apt-mirror.sh): + # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh + env: + APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ steps: - name: Checkout repository diff --git a/.github/workflows/build-oci.yaml b/.github/workflows/build-oci.yaml index 9ebca8f..cbe5329 100644 --- a/.github/workflows/build-oci.yaml +++ b/.github/workflows/build-oci.yaml @@ -37,6 +37,12 @@ jobs: runs-on: ${{ matrix.runner }} # NOTE: 90 min covers the qemu lanes; native lanes finish well under 30. timeout-minutes: 90 + # apt inside `docker build` defaults to archive.ubuntu.com; the runner + # itself uses the azure mirror with archive as fallback. Same mirror, same + # failover, applied for the build only (hack/apt-mirror.sh): + # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh + env: + APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ steps: - name: Checkout repository @@ -58,7 +64,7 @@ jobs: uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: images-out/ - key: images-${{ matrix.arch }}-${{ hashFiles('images/Dockerfile.*', 'hack/bread-warning.sh', 'hack/banner.txt', 'hack/lazy-apt.sh', 'hack/build_image.sh', '.stamp/binaries') }} + key: images-${{ matrix.arch }}-${{ hashFiles('images/Dockerfile.*', 'hack/bread-warning.sh', 'hack/banner.txt', 'hack/lazy-apt.sh', 'hack/apt-mirror.sh', 'hack/build_image.sh', '.stamp/binaries') }} - name: Set up qemu (emulated arches only) if: matrix.qemu && steps.images-cache.outputs.cache-hit != 'true' diff --git a/hack/apt-mirror.sh b/hack/apt-mirror.sh new file mode 100755 index 0000000..5f05d59 --- /dev/null +++ b/hack/apt-mirror.sh @@ -0,0 +1,37 @@ +#!/bin/sh -e +# bread-apt-mirror: build-time apt mirror override. `on` points the archive +# sources at a mirrorlist that tries $APT_MIRROR first and archive.ubuntu.com +# second; `off` puts the original sources back so the shipped image keeps the +# defaults. No-op without APT_MIRROR. +# +# The mirrorlist shape (mirror+file: with priorities, failover to the main +# archive) follows what GitHub's hosted runners configure for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Semantics: https://manpages.ubuntu.com/manpages/noble/en/man1/apt-transport-mirror.1.html +# +# Usage: bread-apt-mirror on|off + +[ -n "${APT_MIRROR:-}" ] || exit 0 + +list=/etc/apt/apt-mirrors.txt +sources=$(find /etc/apt -maxdepth 2 -type f \( -name sources.list -o -name '*.sources' \)) + +case "${1:-}" in + on) + printf '%s\tpriority:1\nhttp://archive.ubuntu.com/ubuntu/\tpriority:2\n' "$APT_MIRROR" > "$list" + for f in $sources; do + cp -p "$f" "$f.bread-orig" + sed -i "s|http://archive\.ubuntu\.com/ubuntu/|mirror+file:$list|g" "$f" + done + ;; + off) + for f in $sources; do + mv "$f.bread-orig" "$f" + done + rm -f "$list" + ;; + *) + printf 'usage: bread-apt-mirror on|off\n' >&2 + exit 2 + ;; +esac diff --git a/hack/build_image.sh b/hack/build_image.sh index 7b890e5..5bb75b3 100755 --- a/hack/build_image.sh +++ b/hack/build_image.sh @@ -1,6 +1,7 @@ #!/usr/bin/env bash # Build one image if its input hash differs from the stamp. # Usage: build_image.sh +# Optional env: APT_MIRROR -- build-time apt mirror, see hack/apt-mirror.sh. # flavour-ver-arch examples: # bread-24.04-amd64 # bread-chisel-releases-25.10-arm64 @@ -30,6 +31,7 @@ case "$flavour" in bread) docker build \ --tag "bread:$ver-$arch" \ + --build-arg "APT_MIRROR=${APT_MIRROR:-}" \ --file "images/Dockerfile.bread-$ver" \ --platform "linux/$arch" \ . @@ -38,6 +40,7 @@ case "$flavour" in docker build \ --tag "bread-chisel-releases:$ver-$arch" \ --build-arg "BASE_TAG=$ver-$arch" \ + --build-arg "APT_MIRROR=${APT_MIRROR:-}" \ --build-arg "BUILD_ARCH=$arch" \ --file "images/Dockerfile.bread-chisel-releases-$ver" \ --platform "linux/$arch" \ diff --git a/hack/hash_inputs.sh b/hack/hash_inputs.sh index ad3edd4..e4c5d8f 100755 --- a/hack/hash_inputs.sh +++ b/hack/hash_inputs.sh @@ -40,6 +40,7 @@ case "$flavour" in "hack/bread-warning.sh" "hack/banner.txt" "hack/tar-shim.sh" + "hack/apt-mirror.sh" ) ;; bread-chisel-releases) diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index 729995e..cf5e39b 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -2,10 +2,17 @@ FROM docker.io/library/ubuntu:22.04@sha256:829f6df217bcbae2b371026e81711d1a787c61b2967ad09d015063663ebafbf7 +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= +COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror + # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ +RUN bread-apt-mirror on && \ + printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ @@ -13,7 +20,8 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index b88912a..e2004e8 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -2,10 +2,17 @@ FROM docker.io/library/ubuntu:24.04@sha256:224a1869083a311ef3f13648a154ba79832fbef6364d31493642ca03082da254 +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= +COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror + # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ +RUN bread-apt-mirror on && \ + printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ @@ -13,7 +20,8 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index a82f50c..c1683f5 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -2,10 +2,17 @@ FROM docker.io/library/ubuntu:25.10@sha256:7cc5e35f6567ee8c66d2abb4aab0fd866669e6207c237c3a8f0947a5c7f17092 +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= +COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror + # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ +RUN bread-apt-mirror on && \ + printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ @@ -13,7 +20,8 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index a1cc28e..adfac11 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -2,10 +2,17 @@ FROM docker.io/library/ubuntu:26.04@sha256:513c074113a871b51a8d16ab445c88779d6452d937a164fb5cc479f32668a41d +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= +COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror + # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ +RUN bread-apt-mirror on && \ + printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ @@ -13,7 +20,8 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index 0346305..4ec88f1 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -2,10 +2,17 @@ FROM docker.io/library/ubuntu:26.10@sha256:49077a16b772f8bc6e6f160ad2bfc218919f3455037387ed19a8309174328603 +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= +COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror + # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ +RUN bread-apt-mirror on && \ + printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \ @@ -13,7 +20,8 @@ RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-e echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-chisel-releases-22.04 b/images/Dockerfile.bread-chisel-releases-22.04 index c55d086..78546f7 100644 --- a/images/Dockerfile.bread-chisel-releases-22.04 +++ b/images/Dockerfile.bread-chisel-releases-22.04 @@ -9,12 +9,18 @@ ARG BASE_TAG=22.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= -RUN apt-get update && \ +RUN bread-apt-mirror on && \ + apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-24.04 b/images/Dockerfile.bread-chisel-releases-24.04 index 5a0b848..d9a9a73 100644 --- a/images/Dockerfile.bread-chisel-releases-24.04 +++ b/images/Dockerfile.bread-chisel-releases-24.04 @@ -9,12 +9,18 @@ ARG BASE_TAG=24.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= -RUN apt-get update && \ +RUN bread-apt-mirror on && \ + apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-25.10 b/images/Dockerfile.bread-chisel-releases-25.10 index cda0585..f74c83b 100644 --- a/images/Dockerfile.bread-chisel-releases-25.10 +++ b/images/Dockerfile.bread-chisel-releases-25.10 @@ -9,12 +9,18 @@ ARG BASE_TAG=25.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= -RUN apt-get update && \ +RUN bread-apt-mirror on && \ + apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-26.04 b/images/Dockerfile.bread-chisel-releases-26.04 index 8fc1544..f6a72fe 100644 --- a/images/Dockerfile.bread-chisel-releases-26.04 +++ b/images/Dockerfile.bread-chisel-releases-26.04 @@ -9,12 +9,18 @@ ARG BASE_TAG=26.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= -RUN apt-get update && \ +RUN bread-apt-mirror on && \ + apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-26.10 b/images/Dockerfile.bread-chisel-releases-26.10 index 541c279..8e95791 100644 --- a/images/Dockerfile.bread-chisel-releases-26.10 +++ b/images/Dockerfile.bread-chisel-releases-26.10 @@ -9,12 +9,18 @@ ARG BASE_TAG=26.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH +# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. +# Mirrors what the hosted runners do for themselves: +# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +ARG APT_MIRROR= -RUN apt-get update && \ +RUN bread-apt-mirror on && \ + apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* + apt-get clean && rm -rf /var/lib/apt/lists/* && \ + bread-apt-mirror off COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker From 9b2678174893b3281770dca7ac830cd50c316efd Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 13:06:46 +0100 Subject: [PATCH 3/7] docs: apt-mirror helper in the layout --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index da1355e..6447894 100644 --- a/README.md +++ b/README.md @@ -100,6 +100,7 @@ spread-bread/ check_base.sh # detect upstream ubuntu base digest drift; rewrite @sha256 pins inline_scripts.rb # splice scripts/*.sh into yaml templates tar-shim.sh # image /bin/tar; routes extraction to bsdtar where gnu tar is broken + apt-mirror.sh # build-time apt mirror override, bind-mounted into image builds by ci scripts/ # allocate / discard scripts, one pair per flavour images/ # one Dockerfile per (flavour, ubuntu version) templates/ # yaml templates with `source scripts/...` markers From e178d974f3db0ad2057a74ff2e5d25ab9a275a62 Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 13:37:41 +0100 Subject: [PATCH 4/7] chore?: apt mirror helper bind-mounted, not shipped A per-RUN bind mount leaves no layer behind, so published images are the same as before the mirror override. The chisel-releases stage now mounts the helper from its own build context, so it hashes it too. --- hack/hash_inputs.sh | 1 + images/Dockerfile.bread-22.04 | 4 ++-- images/Dockerfile.bread-24.04 | 4 ++-- images/Dockerfile.bread-25.10 | 4 ++-- images/Dockerfile.bread-26.04 | 4 ++-- images/Dockerfile.bread-26.10 | 4 ++-- images/Dockerfile.bread-chisel-releases-22.04 | 3 ++- images/Dockerfile.bread-chisel-releases-24.04 | 3 ++- images/Dockerfile.bread-chisel-releases-25.10 | 3 ++- images/Dockerfile.bread-chisel-releases-26.04 | 3 ++- images/Dockerfile.bread-chisel-releases-26.10 | 3 ++- 11 files changed, 21 insertions(+), 15 deletions(-) diff --git a/hack/hash_inputs.sh b/hack/hash_inputs.sh index e4c5d8f..262b0c6 100755 --- a/hack/hash_inputs.sh +++ b/hack/hash_inputs.sh @@ -47,6 +47,7 @@ case "$flavour" in inputs=( "images/Dockerfile.bread-chisel-releases-$ver" "hack/lazy-apt.sh" + "hack/apt-mirror.sh" ".stamp/bread-$ver-$arch" ".stamp/binaries" ) diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index cf5e39b..ae5d4c0 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -6,12 +6,12 @@ FROM docker.io/library/ubuntu:22.04@sha256:829f6df217bcbae2b371026e81711d1a787c6 # Mirrors what the hosted runners do for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index e2004e8..4f16696 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -6,12 +6,12 @@ FROM docker.io/library/ubuntu:24.04@sha256:224a1869083a311ef3f13648a154ba79832fb # Mirrors what the hosted runners do for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index c1683f5..d7a1673 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -6,12 +6,12 @@ FROM docker.io/library/ubuntu:25.10@sha256:7cc5e35f6567ee8c66d2abb4aab0fd866669e # Mirrors what the hosted runners do for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index adfac11..1755703 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -6,12 +6,12 @@ FROM docker.io/library/ubuntu:26.04@sha256:513c074113a871b51a8d16ab445c88779d645 # Mirrors what the hosted runners do for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index 4ec88f1..8e2f873 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -6,12 +6,12 @@ FROM docker.io/library/ubuntu:26.10@sha256:49077a16b772f8bc6e6f160ad2bfc218919f3 # Mirrors what the hosted runners do for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -COPY hack/apt-mirror.sh /usr/local/bin/bread-apt-mirror # Skip man/doc/info install for every subsequent package -- dpkg's man-db # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ diff --git a/images/Dockerfile.bread-chisel-releases-22.04 b/images/Dockerfile.bread-chisel-releases-22.04 index 78546f7..ec5b40d 100644 --- a/images/Dockerfile.bread-chisel-releases-22.04 +++ b/images/Dockerfile.bread-chisel-releases-22.04 @@ -14,7 +14,8 @@ ARG BUILD_ARCH # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ diff --git a/images/Dockerfile.bread-chisel-releases-24.04 b/images/Dockerfile.bread-chisel-releases-24.04 index d9a9a73..9c0dfe6 100644 --- a/images/Dockerfile.bread-chisel-releases-24.04 +++ b/images/Dockerfile.bread-chisel-releases-24.04 @@ -14,7 +14,8 @@ ARG BUILD_ARCH # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ diff --git a/images/Dockerfile.bread-chisel-releases-25.10 b/images/Dockerfile.bread-chisel-releases-25.10 index f74c83b..d40172c 100644 --- a/images/Dockerfile.bread-chisel-releases-25.10 +++ b/images/Dockerfile.bread-chisel-releases-25.10 @@ -14,7 +14,8 @@ ARG BUILD_ARCH # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ diff --git a/images/Dockerfile.bread-chisel-releases-26.04 b/images/Dockerfile.bread-chisel-releases-26.04 index f6a72fe..af8bbe2 100644 --- a/images/Dockerfile.bread-chisel-releases-26.04 +++ b/images/Dockerfile.bread-chisel-releases-26.04 @@ -14,7 +14,8 @@ ARG BUILD_ARCH # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ diff --git a/images/Dockerfile.bread-chisel-releases-26.10 b/images/Dockerfile.bread-chisel-releases-26.10 index 8e95791..e25fb00 100644 --- a/images/Dockerfile.bread-chisel-releases-26.10 +++ b/images/Dockerfile.bread-chisel-releases-26.10 @@ -14,7 +14,8 @@ ARG BUILD_ARCH # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh ARG APT_MIRROR= -RUN bread-apt-mirror on && \ +RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ + bread-apt-mirror on && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ From 4e03813cf2a486268414e503c2816717b87085b9 Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 14:13:34 +0100 Subject: [PATCH 5/7] chore?: apt mirror via APT_CONFIG, image apt files untouched The helper now writes rewritten copies of the sources and an apt.conf into a tmpfs mount and the RUN points APT_CONFIG at it, so the image's own /etc/apt is never modified and there is nothing to restore afterwards. --- hack/apt-mirror.sh | 45 ++++++++----------- images/Dockerfile.bread-22.04 | 6 +-- images/Dockerfile.bread-24.04 | 6 +-- images/Dockerfile.bread-25.10 | 6 +-- images/Dockerfile.bread-26.04 | 6 +-- images/Dockerfile.bread-26.10 | 6 +-- images/Dockerfile.bread-chisel-releases-22.04 | 6 +-- images/Dockerfile.bread-chisel-releases-24.04 | 6 +-- images/Dockerfile.bread-chisel-releases-25.10 | 6 +-- images/Dockerfile.bread-chisel-releases-26.04 | 6 +-- images/Dockerfile.bread-chisel-releases-26.10 | 6 +-- 11 files changed, 49 insertions(+), 56 deletions(-) diff --git a/hack/apt-mirror.sh b/hack/apt-mirror.sh index 5f05d59..d0aa51b 100755 --- a/hack/apt-mirror.sh +++ b/hack/apt-mirror.sh @@ -1,37 +1,30 @@ #!/bin/sh -e -# bread-apt-mirror: build-time apt mirror override. `on` points the archive -# sources at a mirrorlist that tries $APT_MIRROR first and archive.ubuntu.com -# second; `off` puts the original sources back so the shipped image keeps the -# defaults. No-op without APT_MIRROR. +# bread-apt-mirror: build-time apt mirror override that leaves the image's own +# apt files alone. Into the scratch dir given as $1 it writes copies of the apt +# sources with the archive uris pointed at a mirrorlist ($APT_MIRROR first, +# archive.ubuntu.com second) and an apt.conf that makes apt read those copies; +# the build exports APT_CONFIG=/apt.conf. Without APT_MIRROR the apt.conf +# is empty and apt behaves as stock. # # The mirrorlist shape (mirror+file: with priorities, failover to the main # archive) follows what GitHub's hosted runners configure for themselves: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh # Semantics: https://manpages.ubuntu.com/manpages/noble/en/man1/apt-transport-mirror.1.html # -# Usage: bread-apt-mirror on|off +# Usage: bread-apt-mirror +dir="${1:?scratch dir required}" +mkdir -p "$dir/sources.list.d" +: > "$dir/apt.conf" [ -n "${APT_MIRROR:-}" ] || exit 0 -list=/etc/apt/apt-mirrors.txt -sources=$(find /etc/apt -maxdepth 2 -type f \( -name sources.list -o -name '*.sources' \)) +list="$dir/mirrors.txt" +printf '%s\tpriority:1\nhttp://archive.ubuntu.com/ubuntu/\tpriority:2\n' "$APT_MIRROR" > "$list" -case "${1:-}" in - on) - printf '%s\tpriority:1\nhttp://archive.ubuntu.com/ubuntu/\tpriority:2\n' "$APT_MIRROR" > "$list" - for f in $sources; do - cp -p "$f" "$f.bread-orig" - sed -i "s|http://archive\.ubuntu\.com/ubuntu/|mirror+file:$list|g" "$f" - done - ;; - off) - for f in $sources; do - mv "$f.bread-orig" "$f" - done - rm -f "$list" - ;; - *) - printf 'usage: bread-apt-mirror on|off\n' >&2 - exit 2 - ;; -esac +: > "$dir/sources.list" +for f in /etc/apt/sources.list /etc/apt/sources.list.d/*.list /etc/apt/sources.list.d/*.sources; do + [ -f "$f" ] || continue + sed "s|http://archive\.ubuntu\.com/ubuntu/|mirror+file:$list|g" "$f" > "$dir/${f#/etc/apt/}" +done + +printf 'Dir::Etc::sourcelist "%s/sources.list";\nDir::Etc::sourceparts "%s/sources.list.d";\n' "$dir" "$dir" > "$dir/apt.conf" diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index ae5d4c0..9558037 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -11,7 +11,8 @@ ARG APT_MIRROR= # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ @@ -20,8 +21,7 @@ RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt- echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index 4f16696..6590896 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -11,7 +11,8 @@ ARG APT_MIRROR= # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ @@ -20,8 +21,7 @@ RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt- echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index d7a1673..2e6377e 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -11,7 +11,8 @@ ARG APT_MIRROR= # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ @@ -20,8 +21,7 @@ RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt- echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index 1755703..76fb3e4 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -11,7 +11,8 @@ ARG APT_MIRROR= # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ @@ -20,8 +21,7 @@ RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt- echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index 8e2f873..d7a03be 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -11,7 +11,8 @@ ARG APT_MIRROR= # trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in # the image fs, so the bread-chisel-releases install inherits the exclusion. RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \ > /etc/dpkg/dpkg.cfg.d/01-nodoc && \ apt-get update && \ @@ -20,8 +21,7 @@ RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt- echo 'root:bread' | chpasswd && \ echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \ echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* # Replace /etc/pam.d/sshd with a pam_permit-only stack. These images are # throwaway test containers; we don't care about password validity, and the diff --git a/images/Dockerfile.bread-chisel-releases-22.04 b/images/Dockerfile.bread-chisel-releases-22.04 index ec5b40d..72777ea 100644 --- a/images/Dockerfile.bread-chisel-releases-22.04 +++ b/images/Dockerfile.bread-chisel-releases-22.04 @@ -15,13 +15,13 @@ ARG BUILD_ARCH ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-24.04 b/images/Dockerfile.bread-chisel-releases-24.04 index 9c0dfe6..81fba8b 100644 --- a/images/Dockerfile.bread-chisel-releases-24.04 +++ b/images/Dockerfile.bread-chisel-releases-24.04 @@ -15,13 +15,13 @@ ARG BUILD_ARCH ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-25.10 b/images/Dockerfile.bread-chisel-releases-25.10 index d40172c..d0a50c3 100644 --- a/images/Dockerfile.bread-chisel-releases-25.10 +++ b/images/Dockerfile.bread-chisel-releases-25.10 @@ -15,13 +15,13 @@ ARG BUILD_ARCH ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-26.04 b/images/Dockerfile.bread-chisel-releases-26.04 index af8bbe2..f5dd032 100644 --- a/images/Dockerfile.bread-chisel-releases-26.04 +++ b/images/Dockerfile.bread-chisel-releases-26.04 @@ -15,13 +15,13 @@ ARG BUILD_ARCH ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker diff --git a/images/Dockerfile.bread-chisel-releases-26.10 b/images/Dockerfile.bread-chisel-releases-26.10 index e25fb00..a0e19ab 100644 --- a/images/Dockerfile.bread-chisel-releases-26.10 +++ b/images/Dockerfile.bread-chisel-releases-26.10 @@ -15,13 +15,13 @@ ARG BUILD_ARCH ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ - bread-apt-mirror on && \ + --mount=type=tmpfs,target=/run/apt-mirror \ + export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \ apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ curl wget git jq file sudo tree \ skopeo iproute2 && \ - apt-get clean && rm -rf /var/lib/apt/lists/* && \ - bread-apt-mirror off + apt-get clean && rm -rf /var/lib/apt/lists/* COPY cache/binaries/chisel-hacked-${BUILD_ARCH} /usr/local/bin/chisel-hacked COPY cache/binaries/docker-${BUILD_ARCH} /usr/local/bin/docker From 01b0e4946b1395fd2893353bda9193ef21b2b000 Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 14:18:08 +0100 Subject: [PATCH 6/7] chore: apt mirror comments deduplicated --- .github/workflows/build-and-test.yaml | 5 +---- .github/workflows/build-oci.yaml | 5 +---- hack/apt-mirror.sh | 20 +++++++++---------- hack/build_image.sh | 2 +- images/Dockerfile.bread-22.04 | 4 +--- images/Dockerfile.bread-24.04 | 4 +--- images/Dockerfile.bread-25.10 | 4 +--- images/Dockerfile.bread-26.04 | 4 +--- images/Dockerfile.bread-26.10 | 4 +--- images/Dockerfile.bread-chisel-releases-22.04 | 4 +--- images/Dockerfile.bread-chisel-releases-24.04 | 4 +--- images/Dockerfile.bread-chisel-releases-25.10 | 4 +--- images/Dockerfile.bread-chisel-releases-26.04 | 4 +--- images/Dockerfile.bread-chisel-releases-26.10 | 4 +--- 14 files changed, 23 insertions(+), 49 deletions(-) diff --git a/.github/workflows/build-and-test.yaml b/.github/workflows/build-and-test.yaml index 9b583da..11d5fd3 100644 --- a/.github/workflows/build-and-test.yaml +++ b/.github/workflows/build-and-test.yaml @@ -22,10 +22,7 @@ jobs: arch: arm64 runs-on: ${{ matrix.runner }} timeout-minutes: 30 - # apt inside `docker build` defaults to archive.ubuntu.com; the runner - # itself uses the azure mirror with archive as fallback. Same mirror, same - # failover, applied for the build only (hack/apt-mirror.sh): - # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh + # Build-time apt mirror for docker build; see hack/apt-mirror.sh. env: APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ diff --git a/.github/workflows/build-oci.yaml b/.github/workflows/build-oci.yaml index cbe5329..f635a87 100644 --- a/.github/workflows/build-oci.yaml +++ b/.github/workflows/build-oci.yaml @@ -37,10 +37,7 @@ jobs: runs-on: ${{ matrix.runner }} # NOTE: 90 min covers the qemu lanes; native lanes finish well under 30. timeout-minutes: 90 - # apt inside `docker build` defaults to archive.ubuntu.com; the runner - # itself uses the azure mirror with archive as fallback. Same mirror, same - # failover, applied for the build only (hack/apt-mirror.sh): - # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh + # Build-time apt mirror for docker build; see hack/apt-mirror.sh. env: APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ diff --git a/hack/apt-mirror.sh b/hack/apt-mirror.sh index d0aa51b..a017804 100755 --- a/hack/apt-mirror.sh +++ b/hack/apt-mirror.sh @@ -1,15 +1,15 @@ #!/bin/sh -e -# bread-apt-mirror: build-time apt mirror override that leaves the image's own -# apt files alone. Into the scratch dir given as $1 it writes copies of the apt -# sources with the archive uris pointed at a mirrorlist ($APT_MIRROR first, -# archive.ubuntu.com second) and an apt.conf that makes apt read those copies; -# the build exports APT_CONFIG=/apt.conf. Without APT_MIRROR the apt.conf -# is empty and apt behaves as stock. -# -# The mirrorlist shape (mirror+file: with priorities, failover to the main -# archive) follows what GitHub's hosted runners configure for themselves: +# bread-apt-mirror: build-time apt mirror override for docker build, which +# otherwise pulls from archive.ubuntu.com; on ci that is the slow path, while +# the runner itself uses the azure mirror. Same mirror, same failover shape: # https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh -# Semantics: https://manpages.ubuntu.com/manpages/noble/en/man1/apt-transport-mirror.1.html +# https://manpages.ubuntu.com/manpages/noble/en/man1/apt-transport-mirror.1.html +# +# Writes into the scratch dir $1 copies of the apt sources with the archive +# uris pointed at a mirrorlist ($APT_MIRROR first, archive.ubuntu.com second) +# plus an apt.conf that makes apt read those copies; the build exports +# APT_CONFIG=/apt.conf. The image's own /etc/apt is never touched. +# Without APT_MIRROR the apt.conf is empty and apt behaves as stock. # # Usage: bread-apt-mirror diff --git a/hack/build_image.sh b/hack/build_image.sh index 5bb75b3..d1c4f82 100755 --- a/hack/build_image.sh +++ b/hack/build_image.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash # Build one image if its input hash differs from the stamp. # Usage: build_image.sh -# Optional env: APT_MIRROR -- build-time apt mirror, see hack/apt-mirror.sh. +# Optional env: APT_MIRROR (see hack/apt-mirror.sh). # flavour-ver-arch examples: # bread-24.04-amd64 # bread-chisel-releases-25.10-arm64 diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index 9558037..7a0525a 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -2,9 +2,7 @@ FROM docker.io/library/ubuntu:22.04@sha256:829f6df217bcbae2b371026e81711d1a787c61b2967ad09d015063663ebafbf7 -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index 6590896..1affba5 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -2,9 +2,7 @@ FROM docker.io/library/ubuntu:24.04@sha256:224a1869083a311ef3f13648a154ba79832fbef6364d31493642ca03082da254 -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index 2e6377e..8b5b276 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -2,9 +2,7 @@ FROM docker.io/library/ubuntu:25.10@sha256:7cc5e35f6567ee8c66d2abb4aab0fd866669e6207c237c3a8f0947a5c7f17092 -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index 76fb3e4..5ac1e02 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -2,9 +2,7 @@ FROM docker.io/library/ubuntu:26.04@sha256:513c074113a871b51a8d16ab445c88779d6452d937a164fb5cc479f32668a41d -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index d7a03be..545d920 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -2,9 +2,7 @@ FROM docker.io/library/ubuntu:26.10@sha256:49077a16b772f8bc6e6f160ad2bfc218919f3455037387ed19a8309174328603 -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-chisel-releases-22.04 b/images/Dockerfile.bread-chisel-releases-22.04 index 72777ea..72bcfa4 100644 --- a/images/Dockerfile.bread-chisel-releases-22.04 +++ b/images/Dockerfile.bread-chisel-releases-22.04 @@ -9,9 +9,7 @@ ARG BASE_TAG=22.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-24.04 b/images/Dockerfile.bread-chisel-releases-24.04 index 81fba8b..1b4659f 100644 --- a/images/Dockerfile.bread-chisel-releases-24.04 +++ b/images/Dockerfile.bread-chisel-releases-24.04 @@ -9,9 +9,7 @@ ARG BASE_TAG=24.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-25.10 b/images/Dockerfile.bread-chisel-releases-25.10 index d0a50c3..6bc205b 100644 --- a/images/Dockerfile.bread-chisel-releases-25.10 +++ b/images/Dockerfile.bread-chisel-releases-25.10 @@ -9,9 +9,7 @@ ARG BASE_TAG=25.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-26.04 b/images/Dockerfile.bread-chisel-releases-26.04 index f5dd032..f88ce6c 100644 --- a/images/Dockerfile.bread-chisel-releases-26.04 +++ b/images/Dockerfile.bread-chisel-releases-26.04 @@ -9,9 +9,7 @@ ARG BASE_TAG=26.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-26.10 b/images/Dockerfile.bread-chisel-releases-26.10 index a0e19ab..1e0c7b1 100644 --- a/images/Dockerfile.bread-chisel-releases-26.10 +++ b/images/Dockerfile.bread-chisel-releases-26.10 @@ -9,9 +9,7 @@ ARG BASE_TAG=26.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror override (ci passes APT_MIRROR); see hack/apt-mirror.sh. -# Mirrors what the hosted runners do for themselves: -# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh +# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ From 0665fca211896f3a1d25c59a692b2b7f6a70ae6c Mon Sep 17 00:00:00 2001 From: lczyk Date: Fri, 11 Sep 2026 14:20:41 +0100 Subject: [PATCH 7/7] chore: drop apt mirror pointer comments --- .github/workflows/build-and-test.yaml | 1 - .github/workflows/build-oci.yaml | 1 - hack/build_image.sh | 1 - images/Dockerfile.bread-22.04 | 1 - images/Dockerfile.bread-24.04 | 1 - images/Dockerfile.bread-25.10 | 1 - images/Dockerfile.bread-26.04 | 1 - images/Dockerfile.bread-26.10 | 1 - images/Dockerfile.bread-chisel-releases-22.04 | 1 - images/Dockerfile.bread-chisel-releases-24.04 | 1 - images/Dockerfile.bread-chisel-releases-25.10 | 1 - images/Dockerfile.bread-chisel-releases-26.04 | 1 - images/Dockerfile.bread-chisel-releases-26.10 | 1 - 13 files changed, 13 deletions(-) diff --git a/.github/workflows/build-and-test.yaml b/.github/workflows/build-and-test.yaml index 11d5fd3..2a653f1 100644 --- a/.github/workflows/build-and-test.yaml +++ b/.github/workflows/build-and-test.yaml @@ -22,7 +22,6 @@ jobs: arch: arm64 runs-on: ${{ matrix.runner }} timeout-minutes: 30 - # Build-time apt mirror for docker build; see hack/apt-mirror.sh. env: APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ diff --git a/.github/workflows/build-oci.yaml b/.github/workflows/build-oci.yaml index f635a87..96b3343 100644 --- a/.github/workflows/build-oci.yaml +++ b/.github/workflows/build-oci.yaml @@ -37,7 +37,6 @@ jobs: runs-on: ${{ matrix.runner }} # NOTE: 90 min covers the qemu lanes; native lanes finish well under 30. timeout-minutes: 90 - # Build-time apt mirror for docker build; see hack/apt-mirror.sh. env: APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/ diff --git a/hack/build_image.sh b/hack/build_image.sh index d1c4f82..aea3222 100755 --- a/hack/build_image.sh +++ b/hack/build_image.sh @@ -1,7 +1,6 @@ #!/usr/bin/env bash # Build one image if its input hash differs from the stamp. # Usage: build_image.sh -# Optional env: APT_MIRROR (see hack/apt-mirror.sh). # flavour-ver-arch examples: # bread-24.04-amd64 # bread-chisel-releases-25.10-arm64 diff --git a/images/Dockerfile.bread-22.04 b/images/Dockerfile.bread-22.04 index 7a0525a..972b72a 100644 --- a/images/Dockerfile.bread-22.04 +++ b/images/Dockerfile.bread-22.04 @@ -2,7 +2,6 @@ FROM docker.io/library/ubuntu:22.04@sha256:829f6df217bcbae2b371026e81711d1a787c61b2967ad09d015063663ebafbf7 -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-24.04 b/images/Dockerfile.bread-24.04 index 1affba5..7553b4f 100644 --- a/images/Dockerfile.bread-24.04 +++ b/images/Dockerfile.bread-24.04 @@ -2,7 +2,6 @@ FROM docker.io/library/ubuntu:24.04@sha256:224a1869083a311ef3f13648a154ba79832fbef6364d31493642ca03082da254 -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-25.10 b/images/Dockerfile.bread-25.10 index 8b5b276..0ec91ed 100644 --- a/images/Dockerfile.bread-25.10 +++ b/images/Dockerfile.bread-25.10 @@ -2,7 +2,6 @@ FROM docker.io/library/ubuntu:25.10@sha256:7cc5e35f6567ee8c66d2abb4aab0fd866669e6207c237c3a8f0947a5c7f17092 -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-26.04 b/images/Dockerfile.bread-26.04 index 5ac1e02..8db13b3 100644 --- a/images/Dockerfile.bread-26.04 +++ b/images/Dockerfile.bread-26.04 @@ -2,7 +2,6 @@ FROM docker.io/library/ubuntu:26.04@sha256:513c074113a871b51a8d16ab445c88779d6452d937a164fb5cc479f32668a41d -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-26.10 b/images/Dockerfile.bread-26.10 index 545d920..b6521fe 100644 --- a/images/Dockerfile.bread-26.10 +++ b/images/Dockerfile.bread-26.10 @@ -2,7 +2,6 @@ FROM docker.io/library/ubuntu:26.10@sha256:49077a16b772f8bc6e6f160ad2bfc218919f3455037387ed19a8309174328603 -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= # Skip man/doc/info install for every subsequent package -- dpkg's man-db diff --git a/images/Dockerfile.bread-chisel-releases-22.04 b/images/Dockerfile.bread-chisel-releases-22.04 index 72bcfa4..0f76c7c 100644 --- a/images/Dockerfile.bread-chisel-releases-22.04 +++ b/images/Dockerfile.bread-chisel-releases-22.04 @@ -9,7 +9,6 @@ ARG BASE_TAG=22.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-24.04 b/images/Dockerfile.bread-chisel-releases-24.04 index 1b4659f..0db0b3b 100644 --- a/images/Dockerfile.bread-chisel-releases-24.04 +++ b/images/Dockerfile.bread-chisel-releases-24.04 @@ -9,7 +9,6 @@ ARG BASE_TAG=24.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-25.10 b/images/Dockerfile.bread-chisel-releases-25.10 index 6bc205b..c85c322 100644 --- a/images/Dockerfile.bread-chisel-releases-25.10 +++ b/images/Dockerfile.bread-chisel-releases-25.10 @@ -9,7 +9,6 @@ ARG BASE_TAG=25.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-26.04 b/images/Dockerfile.bread-chisel-releases-26.04 index f88ce6c..1c979f6 100644 --- a/images/Dockerfile.bread-chisel-releases-26.04 +++ b/images/Dockerfile.bread-chisel-releases-26.04 @@ -9,7 +9,6 @@ ARG BASE_TAG=26.04-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \ diff --git a/images/Dockerfile.bread-chisel-releases-26.10 b/images/Dockerfile.bread-chisel-releases-26.10 index 1e0c7b1..a26f87b 100644 --- a/images/Dockerfile.bread-chisel-releases-26.10 +++ b/images/Dockerfile.bread-chisel-releases-26.10 @@ -9,7 +9,6 @@ ARG BASE_TAG=26.10-amd64 ARG BUILD_ARCH=amd64 FROM bread:${BASE_TAG} ARG BUILD_ARCH -# Build-time apt mirror; see hack/apt-mirror.sh. ARG APT_MIRROR= RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \