Skip to content

Commit ffb04c1

Browse files
authored
fix(DM01-6122): register SAP Root CA via update-ca-certificates for BuildKit (#639)
The DM01-5956 fix appended saprootca.pem directly to ca-certificates.crt, but this does not work for Docker 23's embedded BuildKit. BuildKit's Go TLS client uses the system CA bundle rebuilt by update-ca-certificates, which reads from /usr/local/share/ca-certificates/ — not from raw appends to the bundle file. Fix: copy the CA into /usr/local/share/ca-certificates/ and call update-ca-certificates before dockerd starts. This properly rebuilds ca-certificates.crt and creates the expected symlink in /etc/ssl/certs/, which Go's crypto/tls picks up when verifying InfraBox registry TLS certs during BuildKit --cache-from manifest imports. Verified locally: update-ca-certificates increases ca-certificates.crt size and creates ca-cert-saprootca.pem symlink in /etc/ssl/certs/.
1 parent 37f9fba commit ffb04c1

1 file changed

Lines changed: 9 additions & 5 deletions

File tree

‎src/job/entrypoint.sh‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -56,11 +56,15 @@ if [ ! -e /var/run/docker.sock ]; then
5656
done
5757
echo "SAP Root CA installed for $(ls /etc/docker/certs.d/ | wc -l) registries"
5858

59-
# BuildKit's cache registry client uses the system CA bundle, not /etc/docker/certs.d/.
60-
# Append the SAP Root CA to the Alpine system bundle so BuildKit can trust
61-
# InfraBox internal registries when importing --cache-from manifests via HTTPS.
62-
cat /etc/ssl/certs/saprootca.pem >> /etc/ssl/certs/ca-certificates.crt
63-
echo "SAP Root CA appended to system CA bundle for BuildKit"
59+
# DM01-6122: The previous fix (appending to ca-certificates.crt) did not work because
60+
# Docker 23's embedded BuildKit reads the system CA bundle that was compiled into the
61+
# dockerd binary, not the file on disk at runtime. The correct approach is to drop the
62+
# CA into /usr/local/share/ca-certificates/ and run update-ca-certificates, which
63+
# rebuilds ca-certificates.crt before dockerd starts and is the mechanism the Alpine
64+
# ca-certificates package officially supports for adding custom CAs.
65+
cp /etc/ssl/certs/saprootca.pem /usr/local/share/ca-certificates/saprootca.crt
66+
update-ca-certificates
67+
echo "SAP Root CA registered via update-ca-certificates for BuildKit"
6468
fi
6569

6670
echo "Waiting for docker daemon to start up"

0 commit comments

Comments
 (0)