fix: musl(Alpine)で静的ビルドし外部HTTPS通信を復旧 - #89
Conversation
glibc を静的リンクしたバイナリは provided.al2023 上で外部 HTTPS が失敗し (OpenSSL の STORE 初期化エラー)、api.github.com / hooks.slack.com への通信が 一切できず、通知もエラーアラートも送れず無言で停止していた。 ビルドのベースイメージを crystallang/crystal:latest から crystallang/crystal:latest-alpine (musl) に変更する。amazonlinux:2023 上で glibc 静的=失敗 / musl 静的=成功 を再現確認済み。 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Code Review
This pull request updates the Docker build environment in serverless.yml to use the Alpine-based Crystal image (crystallang/crystal:latest-alpine) to resolve external HTTPS communication issues on AWS Lambda (provided.al2023) when using static linking. The reviewer noted that building a fully static binary on Alpine may fail due to missing static libraries (such as OpenSSL, zlib, and libevent) and suggested installing these dependencies via apk add prior to compiling.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
完全静的リンクに必要な OpenSSL/zlib/libevent の静的ライブラリ(.a)を ビルド前に明示インストールし、将来イメージから外れてもリンクエラーに ならないよう堅牢化する(PR #89 レビュー指摘対応)。 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
概要
数日間 Slack への通知が止まっていた原因を調査し修正する。
停止のタイムライン(CloudWatch ログで特定)
notifications bodyログ): 2026-06-15 19:16:02 JSTビルド方法の変更自体は 2026-06-01
ede2902だが、実際に壊れたバイナリがデプロイされた 06-15 19:20 から停止している。症状
rate(1 minute)は ENABLED)根本原因
ビルド方法が glibc を静的リンクしていたこと(serverless.yml のビルドフック)。
ede2902でコンテナイメージ配布 → 静的バイナリ配布へ変更された際、ベースイメージcrystallang/crystal:latest(glibc)でcrystal build --link-flags -staticしていた。provided.al2023上で外部 HTTPS が失敗する(OpenSSL の STORE 初期化エラーunregistered scheme)。api.github.com/hooks.slack.comの双方へ通信できず、通知が送れないだけでなくエラーアラートの Slack 投稿も同じ理由で失敗するため、無言で停止していた。調査時の証拠
/notifications200,notificationsスコープ有り)→ 失効ではないPUT /notificationsで既読化される)→ 処理が完遂していないnotifications bodyログ修正
ビルドのベースイメージを
crystallang/crystal:latest→crystallang/crystal:latest-alpine(musl) に変更。musl は完全な静的バイナリでも外部通信が動く。検証
amazonlinux:2023(=provided.al2023相当, arm64)上で最小プログラムを実行し再現・確認済み:FAIL OpenSSL::SSL::Error ... unregistered scheme❌OK status=200(api.github.com への HTTPS 成功)✅arm64 Alpine での
crystal build --link-flags -staticが通り、statically linked ARM aarch64バイナリが生成されることも確認済み。スコープ外(別 issue 化済み)
env.ymlに GitHub トークン・Slack Webhook URL が平文でコミットされている(現在もトークン有効)。ローテーション推奨。🤖 Generated with Claude Code