From 93858978783de1a821e872b199d2b2f5f9f140d7 Mon Sep 17 00:00:00 2001 From: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Date: Thu, 28 May 2026 04:01:26 +0000 Subject: [PATCH] fix(image-spec): set NIX_SSL_CERT_FILE so nix can verify TLS in Docker builds The nix daemon inside the Docker builder could not verify SSL certificates when downloading fixed-output derivations (e.g., crate tarballs for importCargoLock). Although ca-certificates is installed via apt, nix does not automatically discover system CA bundles. Two changes: 1. Add ssl-cert-file to nix --extra-conf during install so the daemon configuration permanently knows where to find CA certificates. 2. Export NIX_SSL_CERT_FILE before sourcing nix-daemon.sh so the nix client also picks up the cert bundle for substituter access. Fixes minos2_rust build failure on depot remote builders: curl: (22) SSL certificate OpenSSL verify result: unable to get local issuer certificate (20) error: cannot download crate-async-compression-0.4.34.tar.gz Co-Authored-By: Felix Zeller --- flytekit/image_spec/default_builder.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/flytekit/image_spec/default_builder.py b/flytekit/image_spec/default_builder.py index 2d0e513249..a1e3ae5495 100644 --- a/flytekit/image_spec/default_builder.py +++ b/flytekit/image_spec/default_builder.py @@ -182,6 +182,7 @@ --extra-conf "max-substitution-jobs = 256" \ --extra-conf "http-connections = 256" \ --extra-conf "download-buffer-size = 1073741824" \ + --extra-conf "ssl-cert-file = /etc/ssl/certs/ca-certificates.crt" \ --init none \ --no-confirm @@ -189,10 +190,14 @@ WORKDIR /build # Build with cache mount - reuses the same cache across builds +# NIX_SSL_CERT_FILE tells the nix daemon's fetcher where to find CA +# certificates so fetchurl/FOD downloads can verify TLS. The +# ca-certificates package (installed above via apt) provides the bundle. RUN --mount=type=bind,source=.,target=/build/ \ --mount=type=cache,target=/nix,id=nix-determinate \ --mount=type=cache,target=/root/.cache/nix,id=nix-git-cache \ --mount=type=cache,target=/var/lib/containers/cache,id=container-cache \ + export NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt && \ . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && \ nix run .#docker.copyTo -- docker://$IMAGE_NAME --dest-creds "AWS:$ECR_TOKEN" \ --image-parallel-copies 32 \