-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.debug
More file actions
98 lines (76 loc) · 4.5 KB
/
Copy pathDockerfile.debug
File metadata and controls
98 lines (76 loc) · 4.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# syntax=docker/dockerfile:1.7
# Debug image: the server, the bundled native plugins and the fake SMTP/IMAP test servers.
# The reputation-worker executable, nauthilus-client and the OIDC/SAML test clients are intentionally
# left out; they ship only in the stable image built from Dockerfile.
FROM --platform=$TARGETPLATFORM golang:1.27.1-alpine3.24 AS builder
ARG REQUIRE_PLUGIN_SIGNATURE=false
ARG BUILD_TAGS=""
ARG TARGETOS
ARG TARGETARCH
ARG NAUTHILUS_CONF_DIR=/etc/nauthilus
ARG NAUTHILUS_PLUGINS_DIR=/usr/app/lua-plugins.d
ARG BUNDLED_NATIVE_PLUGINS="geoip clickhouse haveibeenpwnd reputation dkim2-intelligence"
WORKDIR /usr/app
COPY . ./
# Set necessarry environment vairables and compile the app
ENV CGO_ENABLED=1
ENV GOEXPERIMENT=runtimesecret
RUN apk add --no-cache build-base git
RUN NATIVE_ARTIFACT_LDFLAGS="$(go run -mod=vendor ./scripts/native_artifact_fingerprint -tags="netgo ${BUILD_TAGS}")" && \
cd server && go build -mod=vendor -tags="netgo ${BUILD_TAGS}" -trimpath -ldflags="${NATIVE_ARTIFACT_LDFLAGS} -X main.buildTime=$(date -u +'%Y-%m-%dT%H:%M:%SZ') -X main.version=dev-dbg -X github.com/croessner/nauthilus/v4/server/config.nauthilusConfDir=${NAUTHILUS_CONF_DIR} -X github.com/croessner/nauthilus/v4/server/config.nauthilusPluginsDir=${NAUTHILUS_PLUGINS_DIR}" -o nauthilus .
RUN NATIVE_ARTIFACT_LDFLAGS="$(go run -mod=vendor ./scripts/native_artifact_fingerprint -tags="netgo ${BUILD_TAGS}")" && \
mkdir -p /usr/local/lib/nauthilus/plugins && \
for plugin in ${BUNDLED_NATIVE_PLUGINS}; do \
cd /usr/app/contrib/plugins/${plugin} && \
go build -mod=vendor -tags="netgo ${BUILD_TAGS}" -buildmode=plugin -trimpath -ldflags="${NATIVE_ARTIFACT_LDFLAGS}" -o /usr/local/lib/nauthilus/plugins/${plugin}.so .; \
done
RUN --mount=type=secret,id=plugin_signing_private_key \
if [ "${REQUIRE_PLUGIN_SIGNATURE}" = "true" ]; then \
test -s /run/secrets/plugin_signing_private_key && \
for plugin in ${BUNDLED_NATIVE_PLUGINS}; do \
go run -mod=vendor ./server/pluginloader/cmd/nauthilus-plugin-sign sign \
--artifact /usr/local/lib/nauthilus/plugins/${plugin}.so \
--signature /usr/local/lib/nauthilus/plugins/${plugin}.so.minisig \
--private-key-file /run/secrets/plugin_signing_private_key; \
done; \
fi
RUN for plugin in ${BUNDLED_NATIVE_PLUGINS}; do \
chmod 0644 /usr/local/lib/nauthilus/plugins/${plugin}.so; \
if [ -f /usr/local/lib/nauthilus/plugins/${plugin}.so.minisig ]; then \
chmod 0644 /usr/local/lib/nauthilus/plugins/${plugin}.so.minisig; \
fi; \
done
RUN cd docker-healthcheck && go build -mod=vendor -trimpath -ldflags="-s" -o healthcheck .
RUN cd contrib/smtp-server && go build -mod=vendor -trimpath -ldflags="-s" -o fakesmtp .
RUN cd contrib/imap-server && go build -mod=vendor -trimpath -ldflags="-s" -o fakeimap .
FROM alpine:3.24
LABEL org.opencontainers.image.authors="christian@roessner.email"
LABEL org.opencontainers.image.source="https://github.com/croessner/nauthilus"
LABEL org.opencontainers.image.description="Authentication and identity platform with OIDC, SAML, MFA, LDAP, Lua, and mail integrations"
LABEL org.opencontainers.image.licenses=GPL3
LABEL com.roessner-network-solutions.vendor="Rößner-Network-Solutions"
WORKDIR /usr/app
RUN addgroup -S nauthilus; \
adduser -S nauthilus -G nauthilus -D -H -s /bin/nologin
RUN apk --no-cache --upgrade add ca-certificates bash curl
COPY --from=builder ["/usr/app/server/nauthilus", "./server/"]
COPY --from=builder ["/usr/app/server/resources/", "./server/resources/"]
COPY --from=builder ["/usr/app/server/resources/security-policy.md", "./server/resources/security-policy.md"]
COPY --from=builder ["/usr/app/server/lua-plugins.d/", "./server/lua-plugins.d/"]
COPY --from=builder ["/usr/app/docker-healthcheck/healthcheck", "./"]
COPY --from=builder ["/usr/app/contrib/smtp-server/fakesmtp", "./"]
COPY --from=builder ["/usr/app/contrib/imap-server/fakeimap", "./"]
COPY --from=builder ["/usr/app/static/", "./static/"]
COPY --from=builder ["/usr/local/go/lib/time/zoneinfo.zip", "/"]
COPY --from=builder ["/usr/local/lib/nauthilus/plugins/", "/usr/local/lib/nauthilus/plugins/"]
RUN ln -s ./server/lua-plugins.d ./lua-plugins.d
RUN ln -s ./server/resources ./resources
# set up nsswitch.conf for Go's "netgo" implementation
# - https://github.com/golang/go/blob/go1.9.1/src/net/conf.go#L194-L275
RUN echo 'hosts: files dns' > /etc/nsswitch.conf
ENV TERM=xterm-256color
ENV ZONEINFO=/zoneinfo.zip
ENV TZ=UTC
EXPOSE 8080
USER nauthilus
CMD ["/usr/app/server/nauthilus"]