Skip to main content
Cloning a repository in a Blaxel sandbox can fail with an SSL certificate verification error. Minimal base images often omit the certificate authorities required to verify HTTPS connections.

Example error

The Git error resembles:

Root cause

Slim base images such as node:22-bookworm-slim do not always include CA certificates. Without a trusted certificate authority bundle, Git cannot verify the remote server’s SSL certificate.

Install CA certificates

Add ca-certificates to the packages installed by your Dockerfile:

Choose another base image

Alternatively, use a base image that includes CA certificates:
  • node:22-alpine
  • node:22-bookworm, using the full image instead of the slim variant
The Alpine variant has been tested successfully with repository cloning. If you switch to Alpine, update your package installation commands because Alpine uses apk instead of apt-get, and package names or availability may differ.

Docker sandbox tutorial

Learn how to build and run Docker images in sandboxes.

Sandbox proxy and network

Review sandbox networking configuration.
Last modified on October 5, 2026