Operator hit "Git clone failed: ... server certificate verification failed. CAfile: none CRLfile: none" the moment they tried to add a project in the container. The runner stage installed git but not ca-certificates, and the slim base ships zero CA certificates (/etc/ssl/certs was empty). git verifies TLS against the SYSTEM trust store, so every HTTPS remote failed and project setup — the first thing anyone does after logging in — was impossible in Docker. It hid because Node carries its OWN bundled CA store: the dashboard, model API calls, and the OAuth token exchanges against platform.claude.com and OpenAI all worked fine, so the image looked healthy right up until the first clone. Nothing else in the image exercises the system trust store, so a guard is added rather than trusting someone to notice next time. Verified in the running container: installing ca-certificates took it from 0 to 301 certs and `git clone https://github.com/Runfusion/Fusion.git` then succeeded as the node user. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
603 B
603 B
@runfusion/fusion
| @runfusion/fusion |
|---|
| patch |
summary: Fix HTTPS git clones failing in Docker with "server certificate verification failed".
category: fix
dev: The runner stage installed git but not ca-certificates, and the slim base ships zero CA certificates. git verifies TLS against the SYSTEM trust store, so every HTTPS clone failed and project setup was impossible in a container. It stayed hidden because Node carries its own bundled CA store — the dashboard, model APIs, and OAuth token exchanges all worked. Guarded by a new assertion in scripts/tests/dockerfile-workspace-manifests.test.mjs.