From 3bfe43bc6caf4d39d4786fe46eaf850f54e85799 Mon Sep 17 00:00:00 2001 From: sneak Date: Sun, 4 Oct 2026 07:15:37 +0000 Subject: [PATCH] Give the image CA certificates so fetch works over HTTPS (closes #131) The final stage is scratch, which has no CA certificates, so fetch from an HTTPS URL failed to verify any server. Copy the CA bundle from the pinned builder image into the final stage. Model: opus-5-5 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index 3f24a9d..1879173 100644 --- a/Dockerfile +++ b/Dockerfile @@ -73,5 +73,7 @@ RUN version="${VERSION:-$(git describe --tags --always)}"; \ RUN ldd /mfer 2>&1 | grep -q 'not a dynamic executable' FROM scratch +# scratch has no CA certificates; fetch needs them to verify HTTPS servers. +COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ COPY --from=builder /mfer /mfer ENTRYPOINT ["/mfer"]