Skip to content

fix(e2e): support distroless supervisor fixture - #3431

Merged
drew merged 2 commits into
mainfrom
docker-provider-readiness-distroless/pimlock
Sep 17, 2026
Merged

drew merged 2 commits into
mainfrom
docker-provider-readiness-distroless/pimlock

Conversation

@pimlock

@pimlock pimlock commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

Summary

Restore the Docker provider-readiness E2E after the supervisor image moved to a shell-free distroless base. The fixture now installs its synthetic CA with a Docker COPY instead of a shell-form RUN, and reports distinct labels for workload and supervisor fixture build failures.

Related Issue

No issue required: this is a localized compatibility fix for the interaction between #3391 and #3393.

Changes

  • Replace the fixture CA bundle without invoking a shell in the derived supervisor image.
  • Preserve the compiled Mozilla roots used by supervisor upstream TLS.
  • Distinguish workload and supervisor image-build errors.

Testing

  • mise run pre-commit passes
  • Existing provider-readiness E2E passes against the distroless supervisor image
  • Full mise run e2e:rust passes

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
@pimlock pimlock added the test:e2e Requires end-to-end coverage label Sep 17, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for 45bb948. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

drew
drew previously approved these changes Sep 17, 2026
@drew
drew enabled auto-merge September 17, 2026 21:25
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew disabled auto-merge September 17, 2026 21:34
@drew
drew merged commit cb93f62 into main Sep 17, 2026
56 of 58 checks passed
@drew
drew deleted the docker-provider-readiness-distroless/pimlock branch September 17, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants