TL;DR: apt failed inside the build, almost always because the base image package lists are stale or a mirror flaked. Re-run the build (transient mirror errors are common), and if it persists, pull a fresh base image with `docker pull [image]` or pin a newer tag. Exit code 100 is apt's generic 'something failed' code, not a Dockerfile bug.

## The error

```text
The command '/bin/sh -c apt-get update && apt-get install -y python3' returned a non-zero code: 100
```

## Fix it

1. Retry the build once; mirror hiccups are transient:
   `docker build .`
   Expected: often passes on the second try.
2. If it fails the same way, refresh the base image:
   `docker pull ubuntu:22.04`
   Expected: downloads a newer image with current package lists.
3. Rebuild with no cache so the RUN step re-executes:
   `docker build --no-cache .`
   Expected: the apt step completes.
4. If the package name is wrong (e.g. renamed), the apt output above the error names it; fix the package name in the Dockerfile.

## When this applies
- RUN apt-get/apt steps failing with code 100
- Old cached base images with expired Release files

## When this does NOT apply
- Exit code 127 (the command itself is missing, e.g. apt not installed in alpine)
- "Could not resolve" / DNS errors (container network problem instead)
- apk (Alpine) or yum/dnf failures (different package managers, different codes)

## Versions
Any Debian/Ubuntu-based image. Code 100 is apt-specific.

## Why it happens
Base images ship with a snapshot of package lists. When Debian/Ubuntu rotates Release files, `apt-get update` against the stale snapshot fails signature validation, and every subsequent install fails. Cached layers make this sticky: the failing layer is reused until you --no-cache or pull a fresh base.

## Edge cases
- Combine update and install in ONE RUN and clean up in the same layer (`rm -rf /var/lib/apt/lists/*`); splitting them across layers is what makes staleness bite.
- Corporate proxies break apt inside builds; check that http_proxy is passed as build-arg if the host needs one.
- `apt-get install -y --no-install-recommends` avoids pulling half the archive and reduces mirror-flake surface.
