fix(deploy): pin backend Dockerfiles' builder/runtime base to the same Debian release

accounts-service crash-looped in production: GLIBC_2.38 not found. The
builder stage used the floating rust:1-slim tag (now Debian trixie,
glibc 2.38+) while the runtime stage used debian:bookworm-slim (glibc
2.36) — a base mismatch. Pin both stages to trixie so the runtime glibc
is always at least as new as what the binary was linked against.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
This commit is contained in:
loki5512344 2026-09-28 15:32:30 +02:00
parent 1998cdae24
commit 95186ad49c
Signed by: boba
GPG key ID: 253067914055423B
3 changed files with 6 additions and 6 deletions

View file

@ -1,5 +1,5 @@
# Build context must be backend/ (the workspace root).
FROM rust:1-slim AS builder
FROM rust:1-trixie AS builder
RUN apt-get update && apt-get install -y --no-install-recommends \
protobuf-compiler pkg-config libssl-dev ca-certificates \
&& rm -rf /var/lib/apt/lists/*
@ -11,7 +11,7 @@ COPY gateway ./gateway
COPY configs-service ./configs-service
RUN cargo build --release -p accounts-service
FROM debian:bookworm-slim
FROM debian:trixie-slim
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates libssl3 \
&& rm -rf /var/lib/apt/lists/*