@@ -55,8 +55,8 @@ ARG NODE_VERSION=22.21.1
5555ARG CODESERVER_VERSION=v4.106.3
5656
5757# [HERMETIC] Import GPG keys for prefetched RPM verification.
58- # CentOS key needed because libX11-devel comes from CentOS Stream repos .
59- RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official
58+ # CentOS key imported only if prefetched (present in Dockerfile.cpu; may be absent in Konflux) .
59+ RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official || true
6060RUN rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
6161
6262# [HERMETIC] Configure package repos: local hermeto repos for testing, or enable nodejs:22 module for Konflux.
@@ -94,6 +94,8 @@ COPY ${CODESERVER_CONTEXT}/prefetch-input/patches/setup-offline-binaries.sh ${CO
9494COPY ${CODESERVER_CONTEXT}/prefetch-input/patches/codeserver-offline-env.sh ${CODESERVER_SOURCE_CODE}/patches/
9595COPY ${CODESERVER_CONTEXT}/prefetch-input/patches/tweak-gha.sh ${CODESERVER_SOURCE_CODE}/patches/
9696COPY ${CODESERVER_CONTEXT}/prefetch-input/patches/apply-patch.sh ${CODESERVER_SOURCE_CODE}/
97+ # [HERMETIC] utils/ contains git-tracked .vsix (built-in extensions + Python/Jupyter); used by setup-offline-binaries.sh and final stage.
98+ COPY ${CODESERVER_CONTEXT}/utils/ ${CODESERVER_SOURCE_CODE}/utils/
9799
98100# [HERMETIC] apply-patch.sh enables gcc-toolset-14 and applies patches (ripgrep, vsce-sign,
99101# patches/series). npm ci, build, and release run in separate RUN steps below for caching.
@@ -103,7 +105,7 @@ RUN cd ${CODESERVER_SOURCE_CODE} && GHA_BUILD="${GHA_BUILD}" ./apply-patch.sh
103105# setup-offline-binaries.sh does all offline preparation in one shot:
104106# - sources codeserver-offline-env.sh (ELECTRON_SKIP_BINARY_DOWNLOAD, NPM_CONFIG_NODEDIR, etc.)
105107# - node-gyp uses system headers (NPM_CONFIG_NODEDIR=/usr from nodejs-devel RPM)
106- # - ripgrep, .vsix extensions from cachi2 generic; .build/node/ = system /usr/bin/node (per-arch)
108+ # - ripgrep from cachi2 generic; .vsix from utils/ ; .build/node/ = system /usr/bin/node (per-arch)
107109# - pre-populates .build/builtInExtensions/ so gulp skips network downloads
108110# - rewrites package-lock.json "resolved" URLs to file:///cachi2/...
109111# CI=1 makes ci/dev/postinstall.sh run "npm ci" (not "npm install") in subdirs,
@@ -158,9 +160,8 @@ ARG PYLOCK_FLAVOR
158160
159161# [HERMETIC] Import GPG keys for Red Hat and CentOS repos (needed for dnf to verify prefetched RPMs).
160162# CentOS key is prefetched as a generic artifact (see artifacts.in.yaml).
161- # UBI9 images only ship the Red Hat key; CentOS key is needed for ppc64le/s390x packages
162- # from CentOS Stream repos (mesa-libGL, etc.).
163- RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official
163+ # UBI9 images only ship the Red Hat key; CentOS key imported only if prefetched (Dockerfile.cpu; may be absent in Konflux).
164+ RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official || true
164165RUN rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
165166
166167# [HERMETIC] Configure package repos: local hermeto repos for testing.
@@ -238,8 +239,8 @@ WORKDIR /opt/app-root/bin
238239USER 0
239240
240241# [HERMETIC] Import GPG keys for prefetched RPM verification.
241- # CentOS key needed because mesa-libGL comes from CentOS Stream repos .
242- RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official
242+ # CentOS key imported only if prefetched (present in Dockerfile.cpu; may be absent in Konflux) .
243+ RUN rpm --import /cachi2/output/deps/generic/RPM-GPG-KEY-CentOS-Official || true
243244RUN rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
244245
245246# [HERMETIC] Configure package repos: local hermeto repos for testing, or enable nodejs:22 module for Konflux.
0 commit comments