Summary
Extend the existing Debian 12 (bookworm) compatibility in the vendored community cookbooks to Debian 13 (trixie), as part of the Debian 13 migration.
Debian 11 (bullseye) / Debian 12 (bookworm) behaviour is preserved; only trixie takes the new code paths (guarded by platform_version / codename checks).
Scope
supervisor (cookbooks/supervisor/recipes/default.rb)
- The recipe used a bare
pip install supervisor on the non-bookworm branch. Debian 12 and 13 mark the system Python as externally managed (PEP 668), so bare pip install fails with error: externally-managed-environment.
- Fix: broaden the
pipx install condition to cover trixie (platform_version >= 12, or codename bookworm/trixie). bullseye and older keep pip.
docker (cookbooks/docker/libraries/docker_installation_package.rb)
version_string mapped codenames only up to bullseye → codename was nil for Debian 12/13, producing malformed docker-ce versions like 5:<v>~3-0~debian- on trixie. Add bookworm? / trixie? helpers and map their codenames.
- The Docker apt repo used
apt_repository ... key, which shells out to apt-key add — removed in Debian 13, aborting convergence (Errno::ENOENT: No such file or directory - apt-key). On trixie, use a dearmored keyring + signed-by=; other releases keep the original path.
- The dearmored keyring is regenerated on key rotation: the
remote_file notifies the dearmor execute (dropped the creates guard that would leave a stale key when docker.asc changes).
- Version-string trixie format: even with a codename, the generic branch builds
5:<v>~3-0~debian-<codename>, but the trixie docker-ce repo publishes 5:<v>-1~debian.13~trixie. The mismatch made a pinned docker version silently fall back to latest on trixie. Add a trixie-specific return emitting 5:<v>-1~debian.13~trixie so the pin resolves (the consuming chef repo pins docker to 29.8.1 on trixie).
Acceptance
Summary
Extend the existing Debian 12 (bookworm) compatibility in the vendored community cookbooks to Debian 13 (trixie), as part of the Debian 13 migration.
Debian 11 (bullseye) / Debian 12 (bookworm) behaviour is preserved; only trixie takes the new code paths (guarded by
platform_version/ codename checks).Scope
supervisor (
cookbooks/supervisor/recipes/default.rb)pip install supervisoron the non-bookworm branch. Debian 12 and 13 mark the system Python as externally managed (PEP 668), so barepip installfails witherror: externally-managed-environment.pipxinstall condition to cover trixie (platform_version >= 12, or codenamebookworm/trixie). bullseye and older keeppip.docker (
cookbooks/docker/libraries/docker_installation_package.rb)version_stringmapped codenames only up to bullseye →codenamewasnilfor Debian 12/13, producing malformed docker-ce versions like5:<v>~3-0~debian-on trixie. Addbookworm?/trixie?helpers and map their codenames.apt_repository ... key, which shells out toapt-key add— removed in Debian 13, aborting convergence (Errno::ENOENT: No such file or directory - apt-key). On trixie, use a dearmored keyring +signed-by=; other releases keep the original path.remote_filenotifies the dearmorexecute(dropped thecreatesguard that would leave a stale key whendocker.ascchanges).5:<v>~3-0~debian-<codename>, but the trixie docker-ce repo publishes5:<v>-1~debian.13~trixie. The mismatch made a pinned docker version silently fall back to latest on trixie. Add a trixie-specific return emitting5:<v>-1~debian.13~trixieso the pin resolves (the consuming chef repo pins docker to 29.8.1 on trixie).Acceptance
apt-key(signed-by), keyring refreshes on key rotation, and a pinned docker version resolves to the trixie repo format (no fall-back to latest).cookstyleclean.