fix(docker): install the MySQL 8.4 auth plugin; report why a dump fails
Build and Push Images / Build jorgecuadros-web (push) Successful in 1m56s
Build and Push Images / Build jorgecuadros-api (push) Successful in 3m3s

The pre-migrate backup failed with "mysqldump exited 2" and nothing else.
Reproduced on the host with stderr captured:

  ERROR 1045: Plugin caching_sha2_password could not be loaded:
    /usr/lib/mariadb/plugin/caching_sha2_password.so: No such file or directory

Alpine's `mysql-client` is MariaDB's client and ships an EMPTY plugin
directory, so it cannot perform caching_sha2_password — MySQL 8.4's default and
effectively only auth method. `mariadb-connector-c` provides the plugin.

This was never about the deploy backup alone. Every mysqldump/mysql call from
the API container was broken, which means the whole Operaciones panel — backup,
restore, sync, re-import — could not work in a container. It went unnoticed
because that feature had only ever been run with the API on a developer
machine, where the Oracle client is installed. Verified after the fix: dump
exits 0, gzip valid, 31 CREATE TABLEs.

Also fixed, both found while chasing the above:

- The backup script reported an exit code and nothing else, because a detached
  exec captures no output — which is precisely why this needed a manual
  reproduction. mysqldump's stderr is now redirected to a file and read back
  through a short attached exec on failure, so the deploy log states the cause.
  Verified against live prod: the log now carries the 1045 line itself.

- Listing ONLY 100.100.100.100 as the containers' resolver costs them public
  DNS, since MagicDNS does not forward upstream unless the tailnet defines
  global nameservers. Nothing at runtime needed it, but `apk` inside the
  container stopped resolving, and anything outbound would have too. A public
  fallback resolver is now listed after MagicDNS.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-30 15:52:03 -07:00
co-authored by Claude Opus 5
parent b2cdcbe2cd
commit 19f03198d6
4 changed files with 82 additions and 5 deletions
@@ -38,7 +38,12 @@ services:
labels:
io.jorgecuadros.role: "api"
dns:
# MagicDNS first, then a public resolver. Listing ONLY 100.100.100.100
# costs the container public name resolution — apk/npm/any outbound
# hostname stops resolving — because MagicDNS does not forward to an
# upstream unless the tailnet is configured with global nameservers.
- ${TAILSCALE_DNS:-100.100.100.100}
- ${FALLBACK_DNS:-1.1.1.1}
dns_search:
- ${TAILNET_SUFFIX:-tail01aa2.ts.net}
environment:
@@ -83,7 +88,12 @@ services:
# Next server-side rendering can call the API by API_ORIGIN, which is the
# same MagicDNS name — so the web container needs the resolver too.
dns:
# MagicDNS first, then a public resolver. Listing ONLY 100.100.100.100
# costs the container public name resolution — apk/npm/any outbound
# hostname stops resolving — because MagicDNS does not forward to an
# upstream unless the tailnet is configured with global nameservers.
- ${TAILSCALE_DNS:-100.100.100.100}
- ${FALLBACK_DNS:-1.1.1.1}
dns_search:
- ${TAILNET_SUFFIX:-tail01aa2.ts.net}
environment: