fix(docker): bump wolfi-base for glibc 2.44 in migrations image (cherry-pick #38973)

The migrations image fails for a different reason than the other five: its
base is pinned at 42df77a9 (glibc 2.43-r13), but Wolfi's current python-3.13
needs 2.44, so `uv sync` dies before it ever reaches the Python pin:

  ImportError: /usr/lib/libm.so.6: version `GLIBC_2.44' not found
    (required by .../math.cpython-313-aarch64-linux-gnu.so)

Cherry-picks #38973 (merge 0f84a7053a) onto stable/1.97.x: bumps the base to
e624c5d5 and applies the same python-3.13 pin the sibling images got in the
previous commit.

The wolfi-base digest hunk conflicted the same way as #38917's and was
resolved identically, to e624c5d5.

Without this the componentized leg cannot publish: a failed build-amd64 or
build-arm64 matrix leg skips merge and sign-images, and package-and-push-chart
accepts `merge.result == 'skipped'` -- so the chart would publish pointing at
component images that were never built.

(cherry picked from commit 0f84a7053a)
This commit is contained in:
Mateo Wang 2026-08-31 14:41:26 -07:00 committed by Yuneng Jiang
parent 525ea5d27c
commit 785695ea9a
No known key found for this signature in database

View file

@ -1,5 +1,5 @@
ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:42df77a9974d6ec8b17a5ee8bc23b532600a44d705acef2409e0933c1251b45f
ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:42df77a9974d6ec8b17a5ee8bc23b532600a44d705acef2409e0933c1251b45f
ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:e624c5d5e42382ce7165ddafcbbf8e6769a24cbd02ea6114b880b05ae5ba2a8d
ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:e624c5d5e42382ce7165ddafcbbf8e6769a24cbd02ea6114b880b05ae5ba2a8d
ARG UV_IMAGE=ghcr.io/astral-sh/uv:0.11.7@sha256:240fb85ab0f263ef12f492d8476aa3a2e4e1e333f7d67fbdd923d00a506a516a
FROM $UV_IMAGE AS uvbin
@ -35,7 +35,7 @@ COPY --from=uvbin /uv /uvx /usr/local/bin/
# instead of nodeenv downloading one whose dynamic deps may not be in Wolfi
# (e.g. Node 26.2.0 needs libatomic). Retry for transient apk.cgr.dev flakes.
RUN for i in 1 2 3; do \
apk add --no-cache bash gcc python3 python3-dev openssl openssl-dev libsndfile nodejs npm && break; \
apk add --no-cache bash gcc python-3.13 python-3.13-dev openssl openssl-dev libsndfile nodejs npm && break; \
[ $i = 3 ] && { echo "apk add failed after 3 retries" >&2; exit 1; }; \
sleep 5; \
done
@ -56,7 +56,7 @@ RUN --mount=type=cache,target=/root/.cache/uv \
uv sync --frozen --no-install-project --no-install-workspace --no-default-groups --no-editable \
--extra proxy \
--extra extra_proxy \
--python python3
--python python3.13
# Stage 2 — copy source and install the project + workspace members.
COPY . .
@ -65,7 +65,7 @@ RUN --mount=type=cache,target=/root/.cache/uv \
uv sync --frozen --no-default-groups --no-editable \
--extra proxy \
--extra extra_proxy \
--python python3
--python python3.13
COPY migrations/run.py /app/run.py
@ -87,7 +87,7 @@ FROM $LITELLM_RUNTIME_IMAGE AS runtime
USER root
RUN for i in 1 2 3; do \
apk add --no-cache bash openssl tzdata python3 nodejs libsndfile libatomic && break; \
apk add --no-cache bash openssl tzdata python-3.13 nodejs libsndfile libatomic && break; \
[ $i = 3 ] && { echo "apk add failed after 3 retries" >&2; exit 1; }; \
sleep 5; \
done