Skip to content

Refresh apt package index before installing additional_packages - #185

Merged
SugatD merged 1 commit into
mainfrom
fix-additional-packages-apt-update
Aug 21, 2026
Merged

SugatD merged 1 commit into
mainfrom
fix-additional-packages-apt-update

Conversation

@SugatD

@SugatD SugatD commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

Summary

  • module_ci.yml's "Install additional packages" step runs sudo apt-get install -y ${{ inputs.additional_packages }} without an apt-get update first.
  • The runner image's baked-in apt package index can lag behind the live Ubuntu archive. When a package gets a security update, the old .deb is removed from the mirror pool — only the current version stays available.
  • Installing straight from the stale cached index then 404s on the now-evicted old version, even though a perfectly good current build exists on the mirror.

Observed failure

On puppetlabs-tomcat PR #587's Spec job, apt-get install -y libcurl4-openssl-dev failed:

Err:2 mirror+file:/etc/apt/apt-mirrors.txt noble-updates/main amd64 libcurl4-openssl-dev amd64 8.5.0-2ubuntu10.11
  404  Not Found

At the same time, libcurl4-openssl-dev_8.5.0-2ubuntu10.12_amd64.deb was live on azure.archive.ubuntu.com. The .11 build had been superseded and removed from the pool; the runner's cached index just hadn't caught up.

This affects any module using the additional_packages input (confirmed both puppetlabs-tomcat and puppetlabs-service use it), and will recur any time a package referenced there gets a point-release update between runner-image builds.

Fix

Run sudo apt-get update immediately before the install, in both places this step appears (setup_matrix and spec jobs).

Test plan

  • Once merged, re-run the affected puppetlabs-tomcat PR (#587) and confirm the Install additional packages step succeeds

🤖 Generated with Claude Code

The runner image's baked-in apt package lists can lag behind the live
Ubuntu archive. When a package gets a security update, the old .deb is
removed from the mirror pool -- only the current version stays
available. Installing straight from the stale cached index (without an
apt-get update first) then 404s on the now-evicted old version, even
though a perfectly good current build exists.

Observed on puppetlabs-tomcat's Spec job: apt-get install -y
libcurl4-openssl-dev failed fetching
libcurl4-openssl-dev_8.5.0-2ubuntu10.11_amd64.deb (404), while
libcurl4-openssl-dev_8.5.0-2ubuntu10.12_amd64.deb was live on the
mirror at the same time. This affects any module using the
additional_packages input, not just tomcat.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@SugatD
SugatD requested review from a team as code owners August 21, 2026 10:45
@SugatD

SugatD commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

@SugatD
SugatD merged commit 7699e0b into main Aug 21, 2026
2 checks passed
@SugatD
SugatD deleted the fix-additional-packages-apt-update branch August 21, 2026 11:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants