Pull all fallback base images from Harbor, not Docker Hub

Every language's Dockerfile fallback template now pulls from
harbor.192.168.1.7.nip.io/base-images/... (mirrored from Docker Hub via
the new devops-base-images repo) instead of pulling live from Docker
Hub on every build. Eliminates that external dependency at build time,
and lets the mirrored tags be deliberately the leanest official
variant rather than whatever a public tag happens to default to.

- go: unchanged tags (golang:1.22-alpine, alpine:3.20 — already
  minimal), just re-hosted.
- node/python/java: moved from their Debian-slim defaults to the
  -alpine equivalent (node:20-alpine, python:3.12-alpine,
  maven:3-eclipse-temurin-21-alpine, eclipse-temurin:21-jre-alpine).
- php: bigger change — dropped php:*-apache (Debian, full Apache
  httpd) entirely for php:*-cli-alpine + PHP's own built-in dev server
  (`php -S`), moving to port 8080 like every other language instead of
  PHP's special-cased 80. Not production-grade PHP serving (PHP's own
  docs call the built-in server not designed for that), but genuinely
  minimal and fine for a homelab/demo app — would need php-fpm+nginx
  for anything serving real traffic.

Only versions actually mirrored into Harbor resolve now — a
dockerBuildVersion whose tag isn't in devops-base-images/images.txt
needs that added and re-mirrored first, unlike pulling straight from
Docker Hub where any tag "just worked". Chose keeping a shell (Alpine)
over full distroless — homelab kubectl-exec debuggability weighed more
than the last bit of attack-surface reduction.
This commit is contained in:
Mukul Sharma
2026-09-03 09:26:10 +05:30
parent e0572db0f4
commit 4b908150e4
5 changed files with 63 additions and 18 deletions
+8 -2
View File
@@ -1,9 +1,15 @@
# Fallback only — see go-Dockerfile's header comment for the general
# rule. Simplified from the real python-*-Dockerfile set (which had four
# rule, including the Harbor base-images sourcing (also applies here).
# Simplified from the real python-*-Dockerfile set (which had four
# separate version-pinned files, 2.7/3.7/3.10.12/3.13) into one
# version-parametrized template. Assumes a standard requirements.txt +
# app.py (Flask/FastAPI-style `app:app` target for gunicorn) repo.
FROM python:${version}-slim
# Switched from python:*-slim (Debian) to python:*-alpine — smaller,
# still keeps a shell (not distroless). Caveat: pip packages with C
# extensions that only ship glibc wheels may need musl-dev/gcc added
# here to build from source on Alpine — fine for this repo's pure-Python
# deps, worth knowing if a future repo's requirements.txt needs more.
FROM harbor.192.168.1.7.nip.io/base-images/python:${version}-alpine
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt