Skip to content

fix: musl(Alpine)で静的ビルドし外部HTTPS通信を復旧 - #89

Merged
limit7412 merged 2 commits into
masterfrom
fix/static-build-dns-musl
Jun 28, 2026
Merged

limit7412 merged 2 commits into
masterfrom
fix/static-build-dns-musl

Conversation

@limit7412

@limit7412 limit7412 commented Jun 28, 2026 •

Copy link
Copy Markdown
Owner

概要

数日間 Slack への通知が止まっていた原因を調査し修正する。

停止のタイムライン(CloudWatch ログで特定)

  • 最後の成功(notifications body ログ): 2026-06-15 19:16:02 JST
  • 壊れた成果物のデプロイ(Lambda LastModified): 2026-06-15 19:20:42 JST
  • 以降、GitHub 取得成功ログは 0 件(デプロイ直後から完全停止)

ビルド方法の変更自体は 2026-06-01 ede2902 だが、実際に壊れたバイナリがデプロイされた 06-15 19:20 から停止している。

症状

  • Slack チャンネルに通知もエラーアラートも一切届かない
  • それでいて Lambda は毎分起動している(EventBridge rate(1 minute) は ENABLED)

根本原因

ビルド方法が glibc を静的リンクしていたこと(serverless.yml のビルドフック)。

  • ede2902 でコンテナイメージ配布 → 静的バイナリ配布へ変更された際、ベースイメージ crystallang/crystal:latest(glibc)で crystal build --link-flags -static していた。
  • glibc を静的リンクしたバイナリは provided.al2023 上で外部 HTTPS が失敗する(OpenSSL の STORE 初期化エラー unregistered scheme)。
  • 結果 api.github.com / hooks.slack.com の双方へ通信できず、通知が送れないだけでなくエラーアラートの Slack 投稿も同じ理由で失敗するため、無言で停止していた。

調査時の証拠

確認項目 結果
GitHub トークン 有効(/notifications 200, notifications スコープ有り)→ 失効ではない
未読通知 50 件蓄積(正常なら投稿後 PUT /notifications で既読化される)→ 処理が完遂していない
Lambda 実行時間 全実行 約 17〜26ms → 外部 HTTPS が成立していない
notifications body ログ 06-15 19:16 を最後に 0 件(それ以前は毎分出力)
アラート Slack へエラー通知も届かない → GitHub/Slack 両方不通

修正

ビルドのベースイメージを crystallang/crystal:latest → crystallang/crystal:latest-alpine(musl) に変更。musl は完全な静的バイナリでも外部通信が動く。

検証

amazonlinux:2023(= provided.al2023 相当, arm64)上で最小プログラムを実行し再現・確認済み:

  • glibc 静的バイナリ → FAIL OpenSSL::SSL::Error ... unregistered scheme ❌
  • musl 静的バイナリ → OK status=200(api.github.com への HTTPS 成功)✅

arm64 Alpine での crystal build --link-flags -static が通り、statically linked ARM aarch64 バイナリが生成されることも確認済み。

スコープ外(別 issue 化済み)

  1. env.yml に認証情報が平文でコミットされている(要ローテーション) #90 env.yml に GitHub トークン・Slack Webhook URL が平文でコミットされている(現在もトークン有効)。ローテーション推奨。
  2. 外部通信全断を検知できる監視がない #91 連続失敗を検知する監視がない(アラートも Slack 依存のため、今回のように外部通信全断だと機能しない)。

🤖 Generated with Claude Code

glibc を静的リンクしたバイナリは provided.al2023 上で外部 HTTPS が失敗し
(OpenSSL の STORE 初期化エラー)、api.github.com / hooks.slack.com への通信が
一切できず、通知もエラーアラートも送れず無言で停止していた。

ビルドのベースイメージを crystallang/crystal:latest から
crystallang/crystal:latest-alpine (musl) に変更する。amazonlinux:2023 上で
glibc 静的=失敗 / musl 静的=成功 を再現確認済み。

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Docker build environment in serverless.yml to use the Alpine-based Crystal image (crystallang/crystal:latest-alpine) to resolve external HTTPS communication issues on AWS Lambda (provided.al2023) when using static linking. The reviewer noted that building a fully static binary on Alpine may fail due to missing static libraries (such as OpenSSL, zlib, and libevent) and suggested installing these dependencies via apk add prior to compiling.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread serverless.yml Outdated
完全静的リンクに必要な OpenSSL/zlib/libevent の静的ライブラリ(.a)を
ビルド前に明示インストールし、将来イメージから外れてもリンクエラーに
ならないよう堅牢化する(PR #89 レビュー指摘対応)。

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@limit7412
limit7412 merged commit 9152cf2 into master Jun 28, 2026
2 checks passed
@limit7412
limit7412 deleted the fix/static-build-dns-musl branch June 28, 2026 05:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant