Skip to content

Point the RHEL upgrade-matrix legs at images that exist

Placeholder ppxd requested to merge fix/upgrade-matrix-rhel-images into main

Summary

  • rockylinux-9 and almalinux-9 had never started a container: jrei publishes no systemd-rockylinux or systemd-almalinux repository at all, so docker run failed with pull access denied ... repository does not exist (exit 125) before the installer was ever copied. Point them at each distro's own systemd-enabled init image instead, which also removes the dependency on a third-party account that prunes tags.
  • jrei/systemd-fedora:40 fails separately with manifest unknown — that tag was pruned upstream (41, 42, 43, 44, latest remain). Bumped to 41.
  • Two further fixes were needed for the new images to get past steps the old ones never reached:
    • The UBI-based Rocky/Alma images ship curl-minimal, which conflicts with the curl package (conflicting requests, dnf exits non-zero) even though it already provides /usr/bin/curl. Added --allowerasing.
    • Fedora 41's systemd (256) activates tmp.mount, so /tmp is a tmpfs that shadows whatever docker cp wrote into the image layer — the copy reports success and the file is then invisible to bash. Staged under /root instead. el9's systemd 252 leaves /tmp alone, which is why only the newer distro hit it.

Why this matters more than three red checks

Those three legs were exactly the pkg_mgr: dnf legs, so the installer's RPM branch has never executed once — including the test -f /etc/yum.repos.d/squid-tentacle.repo assertion. Every passing leg was apt. The RPM install path was shipping with zero verified coverage behind a check that had been red on every run since 2026-05-03.

Test plan

Verified locally against real containers (--platform linux/amd64, the workflow's exact docker run flags) on all three distros:

  • systemd reaches degraded — Rocky/Alma systemd 252, Fedora 41 systemd 256
  • prerequisite dnf install exits 0 on all three
  • install-tentacle.sh completes (installed squid-tentacle-1.9.4-1.x86_64 from the real RPM repo)
  • Assertion 1 — squid-tentacle version runnable
  • Assertion 2 — /etc/yum.repos.d/squid-tentacle.repo written
  • Assertion 3 — sudoers rule present and visudo -c valid
  • Assertion 4 — sudo -U squid-tentacle -nl enumerates the package-manager rule
  • CI confirmation on ubuntu-latest runners

The RPM path turned out not to be broken — only never run.

Notes

  • The fedora-40 → fedora-41 rename changes that leg's check name. Only Windows Lifecycle Smoke (PR gate) and Linux Lifecycle Smoke (PR gate) are required checks, so nothing in branch protection references it.
  • The Alpine leg still stages under /tmp; Alpine runs no systemd, so tmp.mount cannot shadow it. Left unchanged.

Merge request reports

Loading