add ca certificates to the OCI image

Without this, checking the authority of TLS certificates fails, making
Conduit (rightly) refuse to connect to anything.
This commit is contained in:
Charles Hall 2024-01-27 12:23:57 -08:00
parent 4da8c7e282
commit dffd771e7c
No known key found for this signature in database
GPG key ID: 7B8E0645816E07CF

View file

@ -167,6 +167,9 @@
pkgs.dockerTools.buildImage { pkgs.dockerTools.buildImage {
name = package.pname; name = package.pname;
tag = "next"; tag = "next";
copyToRoot = [
pkgs.dockerTools.caCertificates
];
config = { config = {
# Use the `tini` init system so that signals (e.g. ctrl+c/SIGINT) # Use the `tini` init system so that signals (e.g. ctrl+c/SIGINT)
# are handled as expected # are handled as expected