Skip to content

fix(docker): install ca-certificates in the runtime stage - #195

Merged
FAZuH merged 1 commit into
mainfrom
fix/docker-ca-certificates
Oct 5, 2026
Merged

FAZuH merged 1 commit into
mainfrom
fix/docker-ca-certificates

Conversation

@FAZuH

@FAZuH FAZuH commented Oct 5, 2026

Copy link
Copy Markdown
Owner

The bot panics on startup from the released image

INFO pwr_bot::bot: Initializing bot...
thread 'main' (1) panicked at serenity/.../http/client.rs:201:29:
Cannot build reqwest::Client: reqwest::Error { kind: Builder,
source: General("No CA certificates were loaded from the system") }

This is every production deploy of v0.4.1. The bot exits before it
connects, so no guild has a working bot.

Cause

Dockerfile:30 — the runtime stage installs libfontconfig1 libpq5 but
not ca-certificates, so /etc/ssl/certs is empty in
debian:bookworm-slim. serenity builds its HTTP client on the rustls
backend, which reads the system CA store; an empty store is a hard
reqwest builder failure, not a warning. Nothing about the bot's
configuration or the compose file is involved.

Fix

One package added to the existing apt-get install line. No restructure.

Validation

Not asserted, checked:

  • docker build of the full image: succeeds
  • /etc/ssl/certs/ca-certificates.crt inside the built image:
    224449 bytes, present

Note

Merging this must produce a new image, so this merges without [no ci].
The release will cut v0.4.2; the compose tag then moves to v0.4.2.

The released image panics on startup before it ever reaches Discord:

  Cannot build reqwest::Client: reqwest::Error { kind: Builder,
  source: General("No CA certificates were loaded from the system") }

The runtime stage installs libfontconfig1 and libpq5 but not
ca-certificates, so /etc/ssl/certs is empty in debian:bookworm-slim.
serenity builds its client on the rustls backend, which reads the system
CA store, and the empty store is a hard failure rather than a warning.

Verified: image builds, and /etc/ssl/certs/ca-certificates.crt is present
at 224449 bytes inside it.
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Release Preview

Next version: v0.4.2

Note: CHANGELOG.md has no ## [Unreleased] section. An empty one was created for this preview — add your entries under it to preview the release body.

0.4.2 (2026-10-05)

@FAZuH
FAZuH merged commit 93225a5 into main Oct 5, 2026
5 checks passed
@FAZuH
FAZuH deleted the fix/docker-ca-certificates branch October 11, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant