# The docker-cli image the pipeline's build pod runs its shell steps in. # # Bakes in everything the stages need — git, yq, bash, python3 with pip and # venv for runHooks' python hooks, curl — so nothing is installed on demand # on every single build. Installing tools per build was slow and, worse, # quietly undermined reproducibility: a build's behaviour depended on # whatever the package mirror served that morning. # # Lives here rather than in devops-lib because it is the same kind of thing # as everything else in this repo: an image built by hand, occasionally, # and pushed into Harbor for builds to pull. devops-lib only references the # result by tag. # # Built and pushed manually — never by a Jenkins job, which would need this # image to already exist in order to run. See README.md. # # Pushed to base-images, not homelab: that project is public, so build pods # pull this with no credentials at all, which is the same reason the # mirrored language images live there. # # The tag is pinned explicitly by devops-lib-gcp's dind-pod.yaml, so # rebuilding this does not roll anything out until that pin is bumped too. # Bump the tag when this file changes; do not overwrite an existing tag. FROM harbor.35.238.248.203.nip.io/base-images/docker:27-cli # Pinned rather than the homelab's "releases/latest": an image that resolves # a different yq every time it is built is not reproducible, and this is # exactly the sort of thing that changes under you months later. Bump it # deliberately. ARG YQ_VERSION=v4.44.3 RUN apk add --no-cache git bash python3 py3-pip py3-virtualenv curl \ && curl -sL -o /usr/local/bin/yq \ "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" \ && chmod +x /usr/local/bin/yq \ && yq --version \ && git --version