Make ca-certificates dependency explicit

ca-certificates-bundle (which provides /etc/ssl/certs/ca-certificates.crt)
is already pulled in transitively by apache2 / php-apache2 on alpine:3.23,
so live HTTPS calls from PHP work today (verified with file_get_contents
against ipinfo.io). But the master image (FROM php:8-alpine) installs
the full ca-certificates package explicitly, and operators with
IPINFO_APIKEY configured rely on outbound HTTPS. Make the dependency
explicit to:

* Match master's package set rather than relying on a transitive pull
  that some future apk dep change could drop.
* Document the runtime TLS requirement at the Dockerfile level instead
  of leaving it implicit.

~50 KB image-size cost; the umbrella ca-certificates package adds the
update-ca-certificates CLI on top of the bundle. Per Qodo's review on
PR #800.
This commit is contained in:
Akira Yamamoto 2026-04-27 14:27:46 +10:00
parent 475cae5b0e
commit 8c22140ebb

View file

@ -2,6 +2,7 @@ FROM alpine:3.23
RUN apk add --quiet --no-cache \
bash \
apache2 \
ca-certificates \
php \
php-apache2 \
php-ctype \