From 394e37665c2bbcfe025ff129683b85fc5c8dd98e Mon Sep 17 00:00:00 2001 From: Bitnami Bot Date: Tue, 26 May 2026 15:08:35 +0200 Subject: [PATCH] [bitnami/mongodb-sharded] Release 8.3.2-debian-12-r5 (#94005) Signed-off-by: Bitnami Bot --- .../mongodb-sharded/8.3/debian-12/Dockerfile | 12 +++--- ....3.2-0-linux-amd64-debian-12.tar.gz.sha256 | 1 + ....8.3-0-linux-amd64-debian-12.tar.gz.sha256 | 1 + ....8.3-0-linux-arm64-debian-12.tar.gz.sha256 | 1 + ....9-165-linux-amd64-debian-12.tar.gz.sha256 | 1 + ....9-165-linux-arm64-debian-12.tar.gz.sha256 | 1 + ....10-10-linux-amd64-debian-12.tar.gz.sha256 | 1 + ....10-10-linux-arm64-debian-12.tar.gz.sha256 | 1 + ...53.2-1-linux-amd64-debian-12.tar.gz.sha256 | 1 + ...53.2-1-linux-arm64-debian-12.tar.gz.sha256 | 1 + .../prebuildfs/opt/bitnami/scripts/libfile.sh | 37 +++++++++++++++++++ .../opt/bitnami/scripts/libmongodb-sharded.sh | 1 + .../rootfs/opt/bitnami/scripts/libmongodb.sh | 31 ++++++++-------- .../bitnami/scripts/mongodb-sharded/setup.sh | 4 +- 14 files changed, 70 insertions(+), 24 deletions(-) create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-8.3.2-0-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-arm64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-arm64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-arm64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-arm64-debian-12.tar.gz.sha256 diff --git a/bitnami/mongodb-sharded/8.3/debian-12/Dockerfile b/bitnami/mongodb-sharded/8.3/debian-12/Dockerfile index 47b6d6ff7a82..c6ae03d04c13 100644 --- a/bitnami/mongodb-sharded/8.3/debian-12/Dockerfile +++ b/bitnami/mongodb-sharded/8.3/debian-12/Dockerfile @@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith" ARG TARGETARCH LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \ - org.opencontainers.image.created="2026-05-23T09:33:11Z" \ + org.opencontainers.image.created="2026-05-26T12:58:39Z" \ org.opencontainers.image.description="Application packaged by Broadcom, Inc." \ org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/mongodb-sharded/README.md" \ org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/mongodb-sharded" \ @@ -37,12 +37,12 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \ for COMPONENT in "${COMPONENTS[@]}"; do \ if [ ! -f "${COMPONENT}.tar.gz" ]; then \ curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz" -O ; \ - curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz.sha256" -O ; \ fi ; \ - sha256sum -c "${COMPONENT}.tar.gz.sha256" ; \ + sha256sum -c "/opt/bitnami/checksums/${COMPONENT}.tar.gz.sha256" ; \ tar -zxf "${COMPONENT}.tar.gz" -C /opt/bitnami --strip-components=2 --no-same-owner ; \ - rm -rf "${COMPONENT}".tar.gz{,.sha256} ; \ - done + rm -rf "${COMPONENT}".tar.gz ; \ + done ; \ + rm -rf *.tar.gz.sha256 ; RUN apt-get update && apt-get upgrade -y && \ apt-get clean && rm -rf /var/lib/apt/lists /var/cache/apt/archives RUN chmod g+rwX /opt/bitnami @@ -55,7 +55,7 @@ COPY rootfs / RUN /opt/bitnami/scripts/mongodb-sharded/postunpack.sh ENV APP_VERSION="8.3.2" \ BITNAMI_APP_NAME="mongodb-sharded" \ - IMAGE_REVISION="4" \ + IMAGE_REVISION="5" \ PATH="/opt/bitnami/common/bin:/opt/bitnami/mongodb/bin:$PATH" EXPOSE 27017 diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-8.3.2-0-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-8.3.2-0-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..e65ba44e2efd --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-8.3.2-0-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +c60ca403c7bb8d27e1e14da8b78d2fded923892eaee703994138a42c9a8570db mongodb-8.3.2-0-linux-amd64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..a08b51656660 --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +8143bfe5292ed5e3a48e7558eb7a7b39d58d9945c2287cf44625ccf45df173da mongodb-shell-2.8.3-0-linux-amd64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-arm64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-arm64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..53dedf41c5ec --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/mongodb-shell-2.8.3-0-linux-arm64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +bad32aa7e1b11cc56a3b7dfb131598d8b3f1aa0f5d09b6e174fd8a1c931e1916 mongodb-shell-2.8.3-0-linux-arm64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..ecf216f2789c --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +374910c7361f00d393eca79a749d29f389b4522057902c7655f0a3a5ae3d1b32 render-template-1.0.9-165-linux-amd64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-arm64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-arm64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..e15b6bdd7577 --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/render-template-1.0.9-165-linux-arm64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +d492024d2d8261cfb147e7b508d341b91349fd41cf41aecd0706046be8cb108b render-template-1.0.9-165-linux-arm64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..c96cae9e8074 --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +4af7eb9cb9f027f08bd67ead26a6585ac71810c7dc396a453df794235e3476b3 wait-for-port-1.0.10-10-linux-amd64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-arm64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-arm64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..aebeba63fd0f --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/wait-for-port-1.0.10-10-linux-arm64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +72c721c238602c257e3f933797f266358032e3d2267c4f99707a33de5ee2038e wait-for-port-1.0.10-10-linux-arm64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..f2543765be33 --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +b7241b4121e1304b74a5e04db2d4e8d1db6aca71a65987d8c79836e5235cb927 yq-4.53.2-1-linux-amd64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-arm64-debian-12.tar.gz.sha256 b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-arm64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..fe49d01f636f --- /dev/null +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/checksums/yq-4.53.2-1-linux-arm64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +ba312982d2ba0a320c116b4db0e0ef2518813be9a948a29bc9c3e05951049da9 yq-4.53.2-1-linux-arm64-debian-12.tar.gz diff --git a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh index 1c69e0e48a5d..335c1c7c9ef7 100644 --- a/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh +++ b/bitnami/mongodb-sharded/8.3/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh @@ -139,3 +139,40 @@ wait_for_log_entry() { return 1 fi } + +######################## +# Creates a secure temporary file containing the provided secret +# Arguments: +# $1 - secret to write to the temporary file +# Returns: +# String +######################### +credential_to_temp_file() { + local secret="$1" + local tmp_file + + # Use mktemp with a specific prefix for easier debugging if something lingers + if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then + echo "Error: Failed to create temp file" >&2 + return 1 + fi + + # Restrict permissions before writing the secret + chmod 0600 "$tmp_file" + # Write secret and ensure it's flushed to disk + printf "%s" "$secret" > "$tmp_file" + # Output the filename so the caller can capture it + echo "$tmp_file" +} + +######################## +# Cleans up temporary files created by credential_to_temp_file +# Arguments: +# None +# Returns: +# None +######################### +cleanup_credentials() { + debug "Cleaning up temporary files containing credentials" + rm -rf "${TMPDIR:-/tmp}"/at.cred.* +} diff --git a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb-sharded.sh b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb-sharded.sh index 93847f4462f1..0421bb1f675d 100644 --- a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb-sharded.sh +++ b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb-sharded.sh @@ -8,6 +8,7 @@ # shellcheck disable=SC1091 # Load Generic Libraries +. /opt/bitnami/scripts/libfile.sh . /opt/bitnami/scripts/liblog.sh . /opt/bitnami/scripts/libvalidations.sh . /opt/bitnami/scripts/libmongodb.sh diff --git a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb.sh b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb.sh index 174738103877..d9c079a32c23 100644 --- a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb.sh +++ b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/libmongodb.sh @@ -114,12 +114,6 @@ in the primary node and MONGODB_INITIAL_PRIMARY_ROOT_PASSWORD in the rest of nod error_code=1 } - check_yes_no_value() { - if ! is_yes_no_value "${!1}" && ! is_true_false_value "${!1}"; then - print_validation_error "The allowed values for ${1} are: yes no" - fi - } - if [[ -n "$MONGODB_REPLICA_SET_MODE" ]]; then if [[ "$MONGODB_REPLICA_SET_MODE" =~ ^(secondary|arbiter|hidden) ]]; then if [[ -z "$MONGODB_INITIAL_PRIMARY_HOST" ]]; then @@ -155,6 +149,13 @@ This is only recommended for development." Available options are 'primary/secondary/arbiter/hidden'" print_validation_error "$error_message" fi + else + if [[ -z "$MONGODB_ROOT_PASSWORD" ]] && ! is_boolean_yes "$ALLOW_EMPTY_PASSWORD"; then + error_message="The MONGODB_ROOT_PASSWORD environment variable is empty or not set. \ +Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow the container to be started with blank passwords. \ +This is only recommended for development." + print_validation_error "$error_message" + fi fi if [[ -n "$MONGODB_REPLICA_SET_KEY" ]] && ((${#MONGODB_REPLICA_SET_KEY} < 5)); then @@ -185,19 +186,12 @@ Available options are 'primary/secondary/arbiter/hidden'" if is_boolean_yes "$ALLOW_EMPTY_PASSWORD"; then warn "You set the environment variable ALLOW_EMPTY_PASSWORD=${ALLOW_EMPTY_PASSWORD}. For safety reasons, do not use this flag in a production environment." - elif { [[ -n "$MONGODB_EXTRA_USERNAMES" ]] || [[ -n "$MONGODB_USERNAME" ]]; } && [[ -z "$MONGODB_ROOT_PASSWORD" ]]; then - # Authorization is turned on as soon as a set of users or a root - # password are given. If we have a set of users, but an empty root - # password, validation should fail unless ALLOW_EMPTY_PASSWORD is turned - # on. - error_message="The MONGODB_ROOT_PASSWORD environment variable is empty or not set. Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow the container to be started with a blank root password. This is only recommended for development." - print_validation_error "$error_message" fi # Warn for users with empty passwords, as these won't be created. Maybe # should we just end with an error here instead? if [[ -n "$MONGODB_EXTRA_USERNAMES" ]]; then - # Here we can access the arrays usernames and passwordsa, as these have + # Here we can access the arrays usernames and passwords, as these have # been initialised earlier on. for ((i = 0; i < ${#passwords[@]}; i++)); do if [[ -z "${passwords[i]}" ]]; then @@ -1696,7 +1690,12 @@ mongodb_execute() { local -a args=("--host" "$host" "--port" "$port") [[ -n "$final_user" ]] && args+=("-u" "$final_user") - [[ -n "$password" ]] && args+=("-p" "$password") + # Avoid passing credentials as arguments to mongosh, to avoid leaking them given a local observer with /proc read access can read them + if [[ -n "$password" ]]; then + local pass_file + pass_file="$(credential_to_temp_file "$password")" + args+=("-p" "$(<"$pass_file")") + fi if [[ -n "$extra_args" ]]; then local extra_args_array=() read -r -a extra_args_array <<<"$extra_args" @@ -1704,5 +1703,5 @@ mongodb_execute() { fi [[ -n "$database" ]] && args+=("$database") - "$MONGODB_BIN_DIR/mongosh" "${args[@]}" + "${MONGODB_BIN_DIR}/mongosh" "${args[@]}" } diff --git a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/mongodb-sharded/setup.sh b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/mongodb-sharded/setup.sh index 6c60dae563a9..20eba6e9aa2c 100755 --- a/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/mongodb-sharded/setup.sh +++ b/bitnami/mongodb-sharded/8.3/debian-12/rootfs/opt/bitnami/scripts/mongodb-sharded/setup.sh @@ -23,8 +23,8 @@ is_boolean_yes "$MONGODB_ENABLE_IPV6" && MONGODB_ENABLE_IPV6="true" || MONGODB_E # Ensure MongoDB env var settings are valid mongodb_sharded_validate -# Ensure MongoDB is stopped when this script ends. -trap "mongodb_stop" EXIT +# Ensure MongoDB is stopped when this script ends and we clean up temporary files +trap "mongodb_stop; cleanup_credentials" EXIT # Ensure 'daemon' user exists when running as 'root' am_i_root && ensure_user_exists "$MONGODB_DAEMON_USER" --group "$MONGODB_DAEMON_GROUP"