Pull all fallback base images from Harbor, not Docker Hub
Every language's Dockerfile fallback template now pulls from harbor.192.168.1.7.nip.io/base-images/... (mirrored from Docker Hub via the new devops-base-images repo) instead of pulling live from Docker Hub on every build. Eliminates that external dependency at build time, and lets the mirrored tags be deliberately the leanest official variant rather than whatever a public tag happens to default to. - go: unchanged tags (golang:1.22-alpine, alpine:3.20 — already minimal), just re-hosted. - node/python/java: moved from their Debian-slim defaults to the -alpine equivalent (node:20-alpine, python:3.12-alpine, maven:3-eclipse-temurin-21-alpine, eclipse-temurin:21-jre-alpine). - php: bigger change — dropped php:*-apache (Debian, full Apache httpd) entirely for php:*-cli-alpine + PHP's own built-in dev server (`php -S`), moving to port 8080 like every other language instead of PHP's special-cased 80. Not production-grade PHP serving (PHP's own docs call the built-in server not designed for that), but genuinely minimal and fine for a homelab/demo app — would need php-fpm+nginx for anything serving real traffic. Only versions actually mirrored into Harbor resolve now — a dockerBuildVersion whose tag isn't in devops-base-images/images.txt needs that added and re-mirrored first, unlike pulling straight from Docker Hub where any tag "just worked". Chose keeping a shell (Alpine) over full distroless — homelab kubectl-exec debuggability weighed more than the last bit of attack-surface reduction.
This commit is contained in:
@@ -4,14 +4,23 @@
|
|||||||
# kafka-specific CGO toggle. Assumes a standard single-binary repo layout
|
# kafka-specific CGO toggle. Assumes a standard single-binary repo layout
|
||||||
# (main package at the repo root) — a repo with a different structure
|
# (main package at the repo root) — a repo with a different structure
|
||||||
# should just bring its own Dockerfile, same as demo-go-app does.
|
# should just bring its own Dockerfile, same as demo-go-app does.
|
||||||
FROM golang:${version}-alpine AS build
|
# Both stages pulled from Harbor's base-images project (mirrored from
|
||||||
|
# Docker Hub via devops-base-images), not Docker Hub directly — see that
|
||||||
|
# repo's README for the one-off mirror setup and why (build-time
|
||||||
|
# dependency on an external registry, plus wanting to pick the leanest
|
||||||
|
# variant of each deliberately rather than accept whatever a public tag
|
||||||
|
# defaults to). Only versions actually mirrored there resolve — passing
|
||||||
|
# a dockerBuildVersion whose tag isn't in devops-base-images/images.txt
|
||||||
|
# yet needs that added and re-mirrored first, unlike pulling straight
|
||||||
|
# from Docker Hub where any tag "just worked".
|
||||||
|
FROM harbor.192.168.1.7.nip.io/base-images/golang:${version}-alpine AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum* ./
|
COPY go.mod go.sum* ./
|
||||||
RUN go mod download 2>/dev/null || true
|
RUN go mod download 2>/dev/null || true
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN CGO_ENABLED=0 go build -o /app .
|
RUN CGO_ENABLED=0 go build -o /app .
|
||||||
|
|
||||||
FROM alpine:3.20
|
FROM harbor.192.168.1.7.nip.io/base-images/alpine:3.20
|
||||||
COPY --from=build /app /app
|
COPY --from=build /app /app
|
||||||
EXPOSE 8080
|
EXPOSE 8080
|
||||||
ENTRYPOINT ["/app"]
|
ENTRYPOINT ["/app"]
|
||||||
|
|||||||
@@ -1,15 +1,21 @@
|
|||||||
# Fallback only — see go-Dockerfile's header comment for the general
|
# Fallback only — see go-Dockerfile's header comment for the general
|
||||||
# rule. Simplified from the real java-Dockerfile: no JFrog artifact
|
# rule, including the Harbor base-images sourcing (also applies here).
|
||||||
|
# Simplified from the real java-Dockerfile: no JFrog artifact
|
||||||
# resolution, no Homelab-internal Maven mirror. Assumes a standard Maven
|
# resolution, no Homelab-internal Maven mirror. Assumes a standard Maven
|
||||||
# repo producing a single runnable jar under target/.
|
# repo producing a single runnable jar under target/. Switched both
|
||||||
FROM maven:3-eclipse-temurin-${version} AS build
|
# stages from their Debian defaults to the -alpine variant — smaller,
|
||||||
|
# still keeps a shell (not distroless). Maven itself still reaches out
|
||||||
|
# to Maven Central for plugins/dependencies during the build regardless
|
||||||
|
# of base image — this only removes the Docker Hub dependency for the
|
||||||
|
# base image layer, not package-registry traffic during the build.
|
||||||
|
FROM harbor.192.168.1.7.nip.io/base-images/maven:3-eclipse-temurin-${version}-alpine AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY pom.xml .
|
COPY pom.xml .
|
||||||
RUN mvn -B dependency:go-offline
|
RUN mvn -B dependency:go-offline
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN mvn -B package -DskipTests
|
RUN mvn -B package -DskipTests
|
||||||
|
|
||||||
FROM eclipse-temurin:${version}-jre
|
FROM harbor.192.168.1.7.nip.io/base-images/eclipse-temurin:${version}-jre-alpine
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
COPY --from=build /src/target/*.jar app.jar
|
COPY --from=build /src/target/*.jar app.jar
|
||||||
EXPOSE 8080
|
EXPOSE 8080
|
||||||
|
|||||||
@@ -1,15 +1,18 @@
|
|||||||
# Fallback only — see go-Dockerfile's header comment for the general
|
# Fallback only — see go-Dockerfile's header comment for the general
|
||||||
# rule. Simplified from the real node-Dockerfile: no PBAC registry sync,
|
# rule, including the Harbor base-images sourcing (also applies here).
|
||||||
|
# Simplified from the real node-Dockerfile: no PBAC registry sync,
|
||||||
# no inline Sonar/coverage stage, no .npmrc-across-subdirectories dance.
|
# no inline Sonar/coverage stage, no .npmrc-across-subdirectories dance.
|
||||||
# Assumes a standard `npm run build` + `npm start` repo.
|
# Assumes a standard `npm run build` + `npm start` repo. Switched from
|
||||||
FROM node:${version}-slim AS build
|
# node:*-slim (Debian) to node:*-alpine for both stages — smaller, still
|
||||||
|
# keeps a shell for kubectl exec debugging (not distroless).
|
||||||
|
FROM harbor.192.168.1.7.nip.io/base-images/node:${version}-alpine AS build
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
COPY package*.json ./
|
COPY package*.json ./
|
||||||
RUN npm ci
|
RUN npm ci
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN npm run build --if-present
|
RUN npm run build --if-present
|
||||||
|
|
||||||
FROM node:${version}-slim
|
FROM harbor.192.168.1.7.nip.io/base-images/node:${version}-alpine
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
COPY --from=build /app .
|
COPY --from=build /app .
|
||||||
ENV NODE_ENV=production
|
ENV NODE_ENV=production
|
||||||
|
|||||||
@@ -1,12 +1,33 @@
|
|||||||
# Fallback only — see go-Dockerfile's header comment for the general
|
# Fallback only — see go-Dockerfile's header comment for the general
|
||||||
# rule. Simplified from the real php-Dockerfile. Assumes a standard
|
# rule, including the Harbor base-images sourcing (also applies here).
|
||||||
# composer-based repo served by Apache.
|
# Simplified from the real php-Dockerfile. Assumes a standard
|
||||||
FROM php:${version}-apache
|
# composer-based repo.
|
||||||
|
#
|
||||||
|
# Was php:*-apache (Debian, full Apache httpd) — dropped Apache
|
||||||
|
# entirely in favor of php:*-cli-alpine + PHP's own built-in dev server
|
||||||
|
# (`php -S`). Genuinely minimal (no httpd, no extra process, Alpine
|
||||||
|
# base) and brings this language in line with every other one here on
|
||||||
|
# port 8080 instead of PHP's special-cased 80. Trade-off, stated
|
||||||
|
# plainly: PHP's own docs call the built-in server "not designed to be
|
||||||
|
# a full-featured web server" for production — perfectly fine for a
|
||||||
|
# homelab/demo app, would need revisiting (php-fpm + nginx, two
|
||||||
|
# processes/containers) for anything serving real production traffic.
|
||||||
|
#
|
||||||
|
# docker-php-ext-install needs PHPIZE_DEPS present to compile
|
||||||
|
# extensions on Alpine (unlike the Debian image, which had them
|
||||||
|
# preinstalled) — installed as a virtual package and removed again
|
||||||
|
# right after, so the final image doesn't carry build tooling.
|
||||||
|
FROM harbor.192.168.1.7.nip.io/base-images/php:${version}-cli-alpine
|
||||||
WORKDIR /var/www/html
|
WORKDIR /var/www/html
|
||||||
RUN docker-php-ext-install pdo pdo_mysql
|
RUN apk add --no-cache --virtual .build-deps $PHPIZE_DEPS \
|
||||||
|
&& docker-php-ext-install pdo pdo_mysql \
|
||||||
|
&& apk del .build-deps
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN if [ -f composer.json ]; then \
|
RUN if [ -f composer.json ]; then \
|
||||||
|
apk add --no-cache --virtual .composer-deps curl && \
|
||||||
curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer && \
|
curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer && \
|
||||||
composer install --no-dev --optimize-autoloader; \
|
composer install --no-dev --optimize-autoloader && \
|
||||||
|
apk del .composer-deps; \
|
||||||
fi
|
fi
|
||||||
EXPOSE 80
|
EXPOSE 8080
|
||||||
|
CMD ["php", "-S", "0.0.0.0:8080", "-t", "."]
|
||||||
|
|||||||
@@ -1,9 +1,15 @@
|
|||||||
# Fallback only — see go-Dockerfile's header comment for the general
|
# Fallback only — see go-Dockerfile's header comment for the general
|
||||||
# rule. Simplified from the real python-*-Dockerfile set (which had four
|
# rule, including the Harbor base-images sourcing (also applies here).
|
||||||
|
# Simplified from the real python-*-Dockerfile set (which had four
|
||||||
# separate version-pinned files, 2.7/3.7/3.10.12/3.13) into one
|
# separate version-pinned files, 2.7/3.7/3.10.12/3.13) into one
|
||||||
# version-parametrized template. Assumes a standard requirements.txt +
|
# version-parametrized template. Assumes a standard requirements.txt +
|
||||||
# app.py (Flask/FastAPI-style `app:app` target for gunicorn) repo.
|
# app.py (Flask/FastAPI-style `app:app` target for gunicorn) repo.
|
||||||
FROM python:${version}-slim
|
# Switched from python:*-slim (Debian) to python:*-alpine — smaller,
|
||||||
|
# still keeps a shell (not distroless). Caveat: pip packages with C
|
||||||
|
# extensions that only ship glibc wheels may need musl-dev/gcc added
|
||||||
|
# here to build from source on Alpine — fine for this repo's pure-Python
|
||||||
|
# deps, worth knowing if a future repo's requirements.txt needs more.
|
||||||
|
FROM harbor.192.168.1.7.nip.io/base-images/python:${version}-alpine
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
COPY requirements.txt .
|
COPY requirements.txt .
|
||||||
RUN pip install --no-cache-dir -r requirements.txt
|
RUN pip install --no-cache-dir -r requirements.txt
|
||||||
|
|||||||
Reference in New Issue
Block a user