fix: pin CLI image dependencies and OTel exporters - #804
plural-copilot[bot] wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:
| Name | Details |
|---|---|
| 💬 Prompt | Implement PROD-5210 in one focused PR. You have an earlier analysis: production image is Dockerfile, published multi-arch by .github/workflows/ci.yaml to ghcr.io/pluralsh/plural-cli; current stages use golang:1.26.6-alpine3.24 and an unpinned apk update && apk add --no-cache git build-base; Go MVS currently leaves OTLP trace exporter modules at 1.43.0. The authoritative requirements are non-negotiable.... |
| 🔗 Run history | View run history |
|
| RUN printf '%s\n' 'https://dl-cdn.alpinelinux.org/alpine/v3.24/main' > /etc/apk/repositories \ | ||
| && apk add --no-cache \ | ||
| binutils=2.45.1-r1 \ |
There was a problem hiding this comment.
Mutable repository breaks pins
The exact APK versions are resolved from the mutable v3.24/main repository. When Alpine publishes newer revisions and removes these revisions from its APK index, a cache-miss rebuild will fail at apk add, blocking the amd64 and arm64 image builds and subsequent CLI image publication. Use a durable snapshot or preserved APK artifacts if historical rebuilds must remain reproducible.
Summary
golang@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83index (verified linux/amd64 and linux/arm64 manifests).apk updateand unpinned installation with the v3.24/main source, explicit pins for git, build-base, their complete observed closure, andlibssl3/libcrypto3=3.5.8-r0; assert the two required exact package versions during the image build.v1.45.0, then rungo mod tidywith Go 1.26.6.Fixes PROD-5210
Evidence
libssl3=3.5.8-r0andlibcrypto3=3.5.8-r0for x86_64 and aarch64; the complete git/build-base closure versions matched across both indexes. The exact pinned APK install/assertions completed for amd64.go list -m allresolves both exporter modules tov1.45.0;go mod graphhas root edges atv1.45.0.git diff --checkpassed.make testandmake lintwere attempted but fail before running because the host has nogo(both exit 127); lint also lacksgolangci-lint.buildx, arm64 execution returnsExec format error, and the bounded legacy amd64 build remained ingo mod download. CI's existing native Buildx matrix remains unchanged and should validate both final platforms andplural --help.Artifact and risk
CI publishes
ghcr.io/pluralsh/plural-cli; this PR does not publish or change apluralsh/plural-cliartifact/tag despite the ticket wording. Residual risk is limited to local final-image validation and continued availability of explicitly pinned v3.24 artifacts; pins and build-time assertions fail rather than silently selecting newer packages. Git and build-base are intentionally retained to avoid gratuitous runtime behavior changes.