mirror of
https://github.com/bitnami/containers.git
synced 2026-10-09 20:48:34 +02:00
[bitnami/clickhouse] Release 26.5.2-debian-12-r0 (#94443)
Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
@@ -7,13 +7,13 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith"
|
||||
ARG TARGETARCH
|
||||
|
||||
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
|
||||
org.opencontainers.image.created="2026-05-23T07:10:01Z" \
|
||||
org.opencontainers.image.created="2026-06-08T15:33:05Z" \
|
||||
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
|
||||
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/clickhouse/README.md" \
|
||||
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/clickhouse" \
|
||||
org.opencontainers.image.title="clickhouse" \
|
||||
org.opencontainers.image.vendor="Broadcom, Inc." \
|
||||
org.opencontainers.image.version="26.5.1"
|
||||
org.opencontainers.image.version="26.5.2"
|
||||
|
||||
ENV HOME="/" \
|
||||
OS_ARCH="${TARGETARCH:-amd64}" \
|
||||
@@ -28,17 +28,17 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \
|
||||
DOWNLOADS_URL=${SECRET_DOWNLOADS_URL:-${DOWNLOADS_URL}} ; \
|
||||
mkdir -p /tmp/bitnami/pkg/cache/ ; cd /tmp/bitnami/pkg/cache/ || exit 1 ; \
|
||||
COMPONENTS=( \
|
||||
"clickhouse-26.5.1-0-linux-${OS_ARCH}-debian-12" \
|
||||
"clickhouse-26.5.2-0-linux-${OS_ARCH}-debian-12" \
|
||||
) ; \
|
||||
for COMPONENT in "${COMPONENTS[@]}"; do \
|
||||
if [ ! -f "${COMPONENT}.tar.gz" ]; then \
|
||||
curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz" -O ; \
|
||||
curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz.sha256" -O ; \
|
||||
fi ; \
|
||||
sha256sum -c "${COMPONENT}.tar.gz.sha256" ; \
|
||||
sha256sum -c "/opt/bitnami/checksums/${COMPONENT}.tar.gz.sha256" ; \
|
||||
tar -zxf "${COMPONENT}.tar.gz" -C /opt/bitnami --strip-components=2 --no-same-owner ; \
|
||||
rm -rf "${COMPONENT}".tar.gz{,.sha256} ; \
|
||||
done
|
||||
rm -rf "${COMPONENT}".tar.gz ; \
|
||||
done ; \
|
||||
rm -rf /opt/bitnami/checksums ;
|
||||
RUN apt-get update && apt-get upgrade -y && \
|
||||
apt-get clean && rm -rf /var/lib/apt/lists /var/cache/apt/archives
|
||||
RUN chmod g+rwX /opt/bitnami
|
||||
@@ -47,9 +47,9 @@ RUN uninstall_packages curl
|
||||
|
||||
COPY rootfs /
|
||||
RUN /opt/bitnami/scripts/clickhouse/postunpack.sh
|
||||
ENV APP_VERSION="26.5.1" \
|
||||
ENV APP_VERSION="26.5.2" \
|
||||
BITNAMI_APP_NAME="clickhouse" \
|
||||
IMAGE_REVISION="1" \
|
||||
IMAGE_REVISION="0" \
|
||||
PATH="/opt/bitnami/clickhouse/bin:/opt/bitnami/common/bin:$PATH" \
|
||||
clickhouseCTL_API="3"
|
||||
|
||||
|
||||
+1
@@ -0,0 +1 @@
|
||||
174de484fe61ee92a46c340178860f140b1784e45a15ec612a163c3f980e1600 clickhouse-26.5.2-0-linux-amd64-debian-12.tar.gz
|
||||
+1
@@ -0,0 +1 @@
|
||||
c6ca63bad3b238119696f6294893ebe8ce7bfe7c9e5e7c0a402b336d63d7deb4 clickhouse-26.5.2-0-linux-arm64-debian-12.tar.gz
|
||||
@@ -139,3 +139,40 @@ wait_for_log_entry() {
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
########################
|
||||
# Creates a secure temporary file containing the provided secret
|
||||
# Arguments:
|
||||
# $1 - secret to write to the temporary file
|
||||
# Returns:
|
||||
# String
|
||||
#########################
|
||||
credential_to_temp_file() {
|
||||
local secret="$1"
|
||||
local tmp_file
|
||||
|
||||
# Use mktemp with a specific prefix for easier debugging if something lingers
|
||||
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
|
||||
echo "Error: Failed to create temp file" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
# Restrict permissions before writing the secret
|
||||
chmod 0600 "$tmp_file"
|
||||
# Write secret and ensure it's flushed to disk
|
||||
printf "%s" "$secret" > "$tmp_file"
|
||||
# Output the filename so the caller can capture it
|
||||
echo "$tmp_file"
|
||||
}
|
||||
|
||||
########################
|
||||
# Cleans up temporary files created by credential_to_temp_file
|
||||
# Arguments:
|
||||
# None
|
||||
# Returns:
|
||||
# None
|
||||
#########################
|
||||
cleanup_credentials() {
|
||||
debug "Cleaning up temporary files containing credentials"
|
||||
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
|
||||
}
|
||||
|
||||
@@ -131,6 +131,7 @@ relativize() {
|
||||
# -d|--dir-mode - mode for files.
|
||||
# -u|--user - user
|
||||
# -g|--group - group
|
||||
# -n|--no-dereference - do not follow symlinks (use for runtime root chown of daemon-writable dirs)
|
||||
# Returns:
|
||||
# None
|
||||
#########################
|
||||
@@ -140,6 +141,7 @@ configure_permissions_ownership() {
|
||||
local file_mode=""
|
||||
local user=""
|
||||
local group=""
|
||||
local follow_symlinks="yes"
|
||||
|
||||
# Validate arguments
|
||||
shift 1
|
||||
@@ -161,6 +163,9 @@ configure_permissions_ownership() {
|
||||
shift
|
||||
group="${1:?missing group}"
|
||||
;;
|
||||
-n | --no-dereference)
|
||||
follow_symlinks="no"
|
||||
;;
|
||||
*)
|
||||
echo "Invalid command line flag $1" >&2
|
||||
return 1
|
||||
@@ -169,22 +174,29 @@ configure_permissions_ownership() {
|
||||
shift
|
||||
done
|
||||
|
||||
# -L: follow symlinks and emits the target path
|
||||
# This is dangerous at runtime, given a co-located lower-privileged process with write access
|
||||
# to the target path can redirect the chown/chmod to arbitrary paths. Example:
|
||||
# Lower-privileged process run: ln -s /etc /tmp/etc
|
||||
# Then, setup.sh runs: configure_permissions_ownership --dir-mode 775 /tmp
|
||||
local find_L_flag=(); [[ "$follow_symlinks" == "yes" ]] && find_L_flag=("-L")
|
||||
# -h: changes symlink inode ownership without touching the target.
|
||||
local chown_flags=(); [[ "$follow_symlinks" == "no" ]] && chown_flags=("-h")
|
||||
read -r -a filepaths <<<"$paths"
|
||||
for p in "${filepaths[@]}"; do
|
||||
if [[ -e "$p" ]]; then
|
||||
find -L "$p" -printf ""
|
||||
if [[ -n $dir_mode ]]; then
|
||||
find -L "$p" -type d ! -perm "$dir_mode" -print0 | xargs -r -0 chmod "$dir_mode"
|
||||
find "${find_L_flag[@]}" "$p" -not -type l -type d ! -perm "$dir_mode" -print0 | xargs -r -0 chmod "$dir_mode"
|
||||
fi
|
||||
if [[ -n $file_mode ]]; then
|
||||
find -L "$p" -type f ! -perm "$file_mode" -print0 | xargs -r -0 chmod "$file_mode"
|
||||
find "${find_L_flag[@]}" "$p" -not -type l -type f ! -perm "$file_mode" -print0 | xargs -r -0 chmod "$file_mode"
|
||||
fi
|
||||
if [[ -n $user ]] && [[ -n $group ]]; then
|
||||
find -L "$p" -print0 | xargs -r -0 chown "${user}:${group}"
|
||||
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chown "${chown_flags[@]}" "${user}:${group}"
|
||||
elif [[ -n $user ]] && [[ -z $group ]]; then
|
||||
find -L "$p" -print0 | xargs -r -0 chown "${user}"
|
||||
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chown "${chown_flags[@]}" "${user}"
|
||||
elif [[ -z $user ]] && [[ -n $group ]]; then
|
||||
find -L "$p" -print0 | xargs -r -0 chgrp "${group}"
|
||||
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chgrp "${chown_flags[@]}" "${group}"
|
||||
fi
|
||||
else
|
||||
stderr_print "$p does not exist"
|
||||
|
||||
@@ -170,7 +170,7 @@ ensure_user_exists() {
|
||||
if [[ -n "$home" ]]; then
|
||||
mkdir -p "$home"
|
||||
usermod -d "$home" "$user" >/dev/null 2>&1
|
||||
configure_permissions_ownership "$home" -d "775" -f "664" -u "$user" -g "$group"
|
||||
configure_permissions_ownership "$home" -d "775" -f "664" -u "$user" -g "$group" -n
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@
|
||||
#########################
|
||||
is_int() {
|
||||
local -r int="${1:?missing value}"
|
||||
if [[ "$int" =~ ^-?[0-9]+ ]]; then
|
||||
if [[ "$int" =~ ^-?[0-9]+$ ]]; then
|
||||
true
|
||||
else
|
||||
false
|
||||
|
||||
@@ -49,3 +49,36 @@ get_sematic_version () {
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
########################
|
||||
# Compares two semantic versions
|
||||
# Arguments:
|
||||
# $1 - version1: first version to compare
|
||||
# $2 - version2: second version to compare
|
||||
# Returns:
|
||||
# -1 if version1 is less than version2
|
||||
# 0 if version1 is equal to version2
|
||||
# 1 if version1 is greater than version2
|
||||
#########################
|
||||
compare_semantic_versions() {
|
||||
local version1="${1:?version1 is required}"
|
||||
local version2="${2:?version2 is required}"
|
||||
local major1 major2 minor1 minor2 patch1 patch2
|
||||
|
||||
major1="$(get_sematic_version "$version1" 1)"
|
||||
major2="$(get_sematic_version "$version2" 1)"
|
||||
minor1="$(get_sematic_version "$version1" 2)"
|
||||
minor2="$(get_sematic_version "$version2" 2)"
|
||||
patch1="$(get_sematic_version "$version1" 3)"
|
||||
patch2="$(get_sematic_version "$version2" 3)"
|
||||
|
||||
if [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -eq "$minor2" ]] && [[ "$patch1" -eq "$patch2" ]]; then
|
||||
echo "0"
|
||||
elif [[ "$major1" -lt "$major2" ]] ||
|
||||
{ [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -lt "$minor2" ]]; } ||
|
||||
{ [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -eq "$minor2" ]] && [[ "$patch1" -lt "$patch2" ]]; }; then
|
||||
echo "-1"
|
||||
else
|
||||
echo "1"
|
||||
fi
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user