Files
fips/testing/deb-install
Johnathan Corgan 0c3c0c79c0 Retry test, package and NAT lab image builds across transient registry failures
Image builds in CI pull base images from Docker Hub and ghcr.io and fetch
packages from distribution mirrors, and each has failed a leg for a few
seconds at a time: a registry dial timeout, a 502, an apt file truncated
mid-fetch. A single failed build failed the leg, and a rerun of the whole
workflow was the only recovery.

Add retry_build to testing/lib/image-build.sh: up to three attempts with
10 s and then 20 s between them, whole-build so the base is resolved
again and every package-fetching RUN step runs again. It is quiet on a
first-attempt success, prints each failed attempt and a recovery to
stderr, and on GitHub Actions also raises a warning on the run summary
when a build recovered, so recovered failures remain countable. It never
wraps a test or a container start.

Use it for the shared test images in the integration job, the
deb-install and dns-resolver runtime images, and the package builder
image. Each deb-install and dns-resolver attempt prints its captured
output on failure, so a recovered failure still shows its cause.

The NAT, nostr publish-consume and STUN fault suites built their lab
images inside `docker compose up --build`: the relay image from ghcr.io
and Alpine, the STUN server from the Python image, and the routers from
Debian with apt. Build the profile's images first through retry_build,
then bring the lab up with --no-build. The start is not retried, since a
container that fails to start is a test result; only the build is.
2026-09-19 15:43:27 +00:00
..