ci: scope credential umask and preserve nonroot execution
This commit is contained in:
parent
e9f24b1053
commit
4743b678fc
@ -1,6 +1,6 @@
|
||||
# Jenkins compiles on its scratch PVC; image assembly needs no toolchain layers.
|
||||
FROM gcr.io/distroless/static-debian12:nonroot@sha256:afa5c872c891853ca7fcf1f12c3edb23f7eeef36189728842dd51042ff57f7ab
|
||||
COPY soteria /soteria
|
||||
COPY --chown=65532:65532 soteria /soteria
|
||||
USER 65532:65532
|
||||
EXPOSE 8080
|
||||
ENTRYPOINT ["/soteria"]
|
||||
|
||||
4
Jenkinsfile
vendored
4
Jenkinsfile
vendored
@ -573,6 +573,7 @@ PY
|
||||
mkdir -p build/image internal/server/ui-dist
|
||||
cp -R web/dist/. internal/server/ui-dist/
|
||||
CGO_ENABLED=0 GOOS=linux GOARCH=arm64 go build -p 2 -buildvcs=false -trimpath -ldflags="-s -w" -o build/image/soteria ./cmd/soteria
|
||||
chmod 0755 build/image/soteria
|
||||
cp Dockerfile.runtime build/image/Dockerfile
|
||||
'''
|
||||
}
|
||||
@ -589,9 +590,8 @@ PY
|
||||
set -eu
|
||||
set +x
|
||||
VERSION_TAG=$(cut -d= -f2 build.env)
|
||||
umask 077
|
||||
auth=$(printf '%s:%s' "${HARBOR_USERNAME}" "${HARBOR_PASSWORD}" | base64 | tr -d '\\n')
|
||||
printf '{"auths":{"registry.bstein.dev":{"auth":"%s"}}}\\n' "${auth}" > /kaniko/.docker/config.json
|
||||
(umask 077; printf '{"auths":{"registry.bstein.dev":{"auth":"%s"}}}\\n' "${auth}" > /kaniko/.docker/config.json)
|
||||
trap 'rm -f /kaniko/.docker/config.json' EXIT
|
||||
/kaniko/executor \
|
||||
--context "${WORKSPACE}/build/image" \
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user