Skip to content

Update the pinned Amazon RDS CA bundle checksum - #87

Open
josipmrsic wants to merge 1 commit into
plannotator:mainfrom
josipmrsic:DEVPLAT-1369-fix-rds-bundle-checksum
Open

josipmrsic wants to merge 1 commit into
plannotator:mainfrom
josipmrsic:DEVPLAT-1369-fix-rds-bundle-checksum

Conversation

@josipmrsic

Copy link
Copy Markdown

Hi again! While running the full gate for #86 on our fork, the OCI image build stopped at the Amazon RDS CA bundle:

ADD https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
ERROR: digest mismatch

AWS replaced global-bundle.pem on 2026-09-29, so the pinned checksum in packaging/oci/Dockerfile no longer matches, and every image build fails. That's also why the nightly full gate on main has been red since then.

This PR only updates the pin to the current file (sha256:fe45bbeb…, verified again today against the live URL). The old value appears nowhere else in the repo.

Verification: the full verify:iteration tier on our fork, with this change on top of #86, built and tested the image successfully: https://github.com/josipmrsic/artifact-server/actions/runs/37789296735

Since AWS rotates this bundle from time to time, the pin will need the same update again at some point. Happy to look into a sturdier approach in a separate PR if you'd like one.

AWS replaced global-bundle.pem on 2026-09-29, so every OCI image build failed with a digest mismatch.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant