Dockerfile: cascade apk mirror fallback to HTTP (signature-verified) with diagnostics on total failure

This commit is contained in:
dev
2026-09-12 12:09:15 +03:00
parent 21b00a8e09
commit 1e38419f07
+16 -8
View File
@@ -7,14 +7,22 @@ COPY . .
RUN mkdir -p uploads certs
RUN set -e; \
V="v$(cut -d. -f1-2 /etc/alpine-release)"; \
i=1; \
until apk add --no-cache openssl; do \
echo "apk add failed on attempt $i, switching to backup mirror..."; \
printf "https://mirrors.edge.kernel.org/alpine/%s/main\nhttps://mirrors.edge.kernel.org/alpine/%s/community\n" "$V" "$V" > /etc/apk/repositories; \
i=$((i+1)); \
if [ $i -gt 6 ]; then echo "apk add failed after 6 attempts"; exit 1; fi; \
sleep 5; \
done && \
try_repo() { \
printf "%s/%s/main\n%s/%s/community\n" "$1" "$V" "$1" "$V" > /etc/apk/repositories; \
echo "Trying apk mirror: $1"; \
apk add --no-cache openssl; \
}; \
if ! try_repo "https://dl-cdn.alpinelinux.org/alpine" && \
! try_repo "https://mirrors.edge.kernel.org/alpine" && \
! try_repo "http://mirrors.edge.kernel.org/alpine"; then \
echo "apk failed on all mirrors (HTTPS and HTTP). Diagnostics:"; \
echo "-- date:"; date; \
echo "-- resolv.conf:"; cat /etc/resolv.conf; \
echo "-- proxy env:"; env | grep -i proxy || echo none; \
wget -qO- --timeout=15 https://mirrors.edge.kernel.org/alpine/$V/main/x86_64/APKINDEX.tar.gz >/dev/null && echo "https probe: ok" || echo "https probe: fail"; \
wget -qO- --timeout=15 http://mirrors.edge.kernel.org/alpine/$V/main/x86_64/APKINDEX.tar.gz >/dev/null && echo "http probe: ok" || echo "http probe: fail"; \
exit 1; \
fi && \
openssl req -x509 -nodes -newkey rsa:2048 -days 3650 \
-keyout certs/key.pem -out certs/cert.pem \
-subj "/CN=whatido.local" -addext "subjectAltName=DNS:localhost,IP:127.0.0.1"