Repository navigation
Dockerfile with hardened image and GitHub Action #73
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| name: Docker Image Build on tag or release | ||
|
|
||
| on: | ||
| push: | ||
| tags: | ||
| - '*' | ||
| release: | ||
| types: [published] | ||
|
|
||
| env: | ||
| ORG: opentelekomcloud | ||
| PROJECT: apimon | ||
|
|
||
| jobs: | ||
| push_if_tag: | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - name: Docker meta | ||
| id: meta | ||
| uses: docker/metadata-action@v5 | ||
| with: | ||
| images: | | ||
| "${{ secrets.SWR_URL }}/t-cloud-public/${{ env.PROJECT }}" | ||
| tags: | | ||
| type=schedule | ||
| type=ref,event=branch | ||
| type=ref,event=pr | ||
| type=semver,pattern={{version}} | ||
| type=semver,pattern={{major}}.{{minor}} | ||
| type=semver,pattern={{major}} | ||
| type=sha | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v3 | ||
|
|
||
| - name: Login to SWR Registry | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ${{ secrets.SWR_URL }} | ||
| username: ${{ secrets.SWR_USERNAME }} | ||
| password: ${{ secrets.SWR_PASSWORD }} | ||
|
|
||
| - name: Login to Artifactory DHI | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ${{ secrets.ARTIFACTORY_URL }} | ||
| username: ${{ secrets.ARTIFACTORY_AUTH_USERNAME }} | ||
| password: ${{ secrets.ARTIFACTORY_AUTH_PASSWORD }} | ||
|
|
||
| - name: Build and push | ||
| id: build | ||
| uses: docker/build-push-action@v5 | ||
| with: | ||
| context: . | ||
| tags: ${{ steps.meta.outputs.tags }} | ||
| labels: ${{ steps.meta.outputs.labels }} | ||
| push: true | ||
| provenance: false | ||
| sbom: false | ||
| build-args: | | ||
| ARTIFACTORY_URL=${{ secrets.ARTIFACTORY_URL }} |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,109 @@ | ||
| name: Docker Image Build | ||
|
|
||
| on: | ||
| pull_request: | ||
| types: | ||
| - opened | ||
| - closed | ||
| - edited | ||
| - reopened | ||
| - synchronize | ||
|
|
||
| env: | ||
| ORG: opentelekomcloud | ||
| PROJECT: apimon | ||
|
|
||
| jobs: | ||
|
|
||
| build: | ||
| if: github.event.pull_request.merged == false | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - name: Login to Artifactory DHI | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ${{ secrets.ARTIFACTORY_URL }} | ||
| username: ${{ secrets.ARTIFACTORY_AUTH_USERNAME }} | ||
| password: ${{ secrets.ARTIFACTORY_AUTH_PASSWORD }} | ||
|
|
||
| - name: Docker meta | ||
| id: meta | ||
| uses: docker/metadata-action@v5 | ||
| with: | ||
| images: | | ||
| "${{ secrets.SWR_URL }}/${{ env.PROJECT }}" | ||
| tags: | | ||
| type=schedule | ||
| type=ref,event=branch | ||
| type=ref,event=pr | ||
| type=semver,pattern={{version}} | ||
| type=semver,pattern={{major}}.{{minor}} | ||
| type=semver,pattern={{major}} | ||
| type=sha | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v3 | ||
|
|
||
| - name: Build | ||
| uses: docker/build-push-action@v5 | ||
| with: | ||
| context: . | ||
| tags: ${{ steps.meta.outputs.tags }} | ||
| labels: ${{ steps.meta.outputs.labels }} | ||
| push: false | ||
| build-args: | | ||
| ARTIFACTORY_URL=${{ secrets.ARTIFACTORY_URL }} | ||
|
|
||
| push_if_merged: | ||
| if: github.event.pull_request.merged == true | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - name: Login to SWR Registry | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ${{ secrets.SWR_URL }} | ||
| username: ${{ secrets.SWR_USERNAME }} | ||
| password: ${{ secrets.SWR_PASSWORD }} | ||
|
|
||
| - name: Login to Artifactory DHI | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ${{ secrets.ARTIFACTORY_URL }} | ||
| username: ${{ secrets.ARTIFACTORY_AUTH_USERNAME }} | ||
| password: ${{ secrets.ARTIFACTORY_AUTH_PASSWORD }} | ||
|
|
||
| - name: Docker meta | ||
| id: meta | ||
| uses: docker/metadata-action@v5 | ||
| with: | ||
| images: | | ||
| "${{ secrets.SWR_URL }}/t-cloud-public/${{ env.PROJECT }}" | ||
| tags: | | ||
| type=schedule | ||
| type=ref,event=branch | ||
| type=ref,event=pr | ||
| type=semver,pattern={{version}} | ||
| type=semver,pattern={{major}}.{{minor}} | ||
| type=semver,pattern={{major}} | ||
| type=sha | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v3 | ||
|
|
||
| - name: Build and push | ||
| uses: docker/build-push-action@v5 | ||
| with: | ||
| context: . | ||
| tags: ${{ steps.meta.outputs.tags }} | ||
| labels: ${{ steps.meta.outputs.labels }} | ||
| push: true | ||
| provenance: false | ||
| sbom: false | ||
| build-args: | | ||
| ARTIFACTORY_URL=${{ secrets.ARTIFACTORY_URL }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -10,53 +10,60 @@ | |
| # implied. | ||
| # See the License for the specific language governing permissions and | ||
| # limitations under the License. | ||
| FROM quay.io/fedora/fedora:38 | ||
|
|
||
| # Base image is pulled from the DHI Artifactory mirror (hardened, non-root | ||
| # capable) rather than the public upstream. The mirror host is passed in as a | ||
| # build arg (ARTIFACTORY_URL) so the build works both locally and in CI where | ||
| # the secret is injected. | ||
| ARG ARTIFACTORY_URL=artifactory.devops.telekom.de | ||
| FROM ${ARTIFACTORY_URL}/dhi.io/python:3.11-debian13-dev | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The final image is the -dev base with gcc, python3-dev and git left installed, so the runtime ships the full build toolchain; use a multi-stage build and copy the installed app into a minimal runtime stage. |
||
|
|
||
| LABEL description="StackMon component: APImon (OpenStack API monitoring) container" | ||
| LABEL maintainer="StackMon members" | ||
|
|
||
| RUN dnf --disablerepo updates-modular --disablerepo fedora-modular \ | ||
| install -y git gcc nmap-ncat procps-ng net-tools xz \ | ||
| python3-devel python3-setuptools python3-pip \ | ||
| python3-sqlalchemy \ | ||
| python3-dns && dnf clean all | ||
| ENV DEBIAN_FRONTEND=noninteractive | ||
| # PEP 668: Debian 13 marks the system Python as externally managed, so pip | ||
| # refuses to install into it without this. | ||
| ENV PIP_BREAK_SYSTEM_PACKAGES=1 | ||
|
|
||
| # Runtime + build dependencies (Debian 13 / trixie package names). | ||
| RUN apt-get update && \ | ||
| apt-get install -y --no-install-recommends \ | ||
| git \ | ||
| gcc \ | ||
| ncat \ | ||
| procps \ | ||
| iproute2 \ | ||
| xz-utils \ | ||
| python3-dev \ | ||
| python3-pip \ | ||
| python3-setuptools \ | ||
| python3-sqlalchemy \ | ||
| python3-dnspython \ | ||
| python3-psycopg2 \ | ||
| passwd && \ | ||
| apt-get clean && \ | ||
| rm -rf /var/lib/apt/lists/* | ||
|
|
||
| RUN git config --global user.email "apimon@test.com" | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. git config --global runs as root so it lands in /root/.gitconfig, which the apimon runtime user (HOME=/home/apimon) will not read; set it after USER apimon or write to /etc/gitconfig. |
||
| RUN git config --global user.name "apimon" | ||
|
|
||
| RUN useradd apimon | ||
|
|
||
| RUN mkdir -p /var/{lib/apimon,log/apimon,log/executor,log/scheduler} | ||
| # Create a dedicated, non-root user with a real home directory (the container | ||
| # runs as this user at the end). | ||
| RUN useradd -m -d /home/apimon apimon | ||
|
|
||
| RUN chown apimon:apimon /var/lib/apimon && chown -R apimon:apimon /var/log/apimon | ||
| RUN mkdir -p /var/lib/apimon /var/log/apimon /var/log/executor /var/log/scheduler | ||
| RUN chown -R apimon:apimon /var/lib/apimon /var/log/apimon /var/log/executor /var/log/scheduler | ||
|
|
||
| WORKDIR /usr/app | ||
|
|
||
| COPY ./requirements.txt /usr/app/requirements.txt | ||
|
|
||
| #RUN \ | ||
| # git clone https://github.com/opentelekomcloud/python-otcextensions && \ | ||
| # git clone https://github.com/ansible/ansible --branch stable-2.10 && \ | ||
| # git clone https://review.opendev.org/openstack/openstacksdk | ||
|
|
||
| RUN pip3 install -r /usr/app/requirements.txt | ||
|
|
||
| #RUN cd ansible && python3 setup.py install --user | ||
| #RUN cd openstacksdk && python3 setup.py install --force | ||
| #RUN cd python-otcextensions && python3 setup.py install --force | ||
| RUN pip install --no-cache-dir --break-system-packages -r /usr/app/requirements.txt | ||
|
|
||
| ADD . /usr/app/apimon | ||
|
|
||
| # RUN cd openstacksdk \ | ||
| # && git fetch https://review.opendev.org/openstack/openstacksdk \ | ||
| # refs/changes/97/727097/7 \ | ||
| # && git checkout FETCH_HEAD \ | ||
| # && python3 setup.py install --user | ||
|
|
||
| RUN cd apimon && python3 setup.py install | ||
|
|
||
| RUN rm -rf /usr/app/{ansible,apimon,python-otcextensions} | ||
| RUN cd /usr/app/apimon && python3 setup.py install | ||
|
|
||
| USER apimon | ||
|
|
||
| ENV HOME=/home/apimon | ||
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
On a merged pull_request these rules resolve to the head branch or pr-, not main or latest, so the published image gets a feature-branch tag; push on push to main or add type=raw,value=latest,enable={{is_default_branch}}.