mirror of
https://github.com/bitnami/containers.git
synced 2026-10-10 12:12:43 +02:00
[bitnami/wordpress-nginx] Release 7.0.0-debian-12-r1 (#93998)
Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
@@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith"
|
||||
ARG TARGETARCH
|
||||
|
||||
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
|
||||
org.opencontainers.image.created="2026-05-21T15:16:46Z" \
|
||||
org.opencontainers.image.created="2026-05-26T08:55:00Z" \
|
||||
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
|
||||
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/wordpress-nginx/README.md" \
|
||||
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/wordpress-nginx" \
|
||||
@@ -29,8 +29,8 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \
|
||||
mkdir -p /tmp/bitnami/pkg/cache/ ; cd /tmp/bitnami/pkg/cache/ || exit 1 ; \
|
||||
COMPONENTS=( \
|
||||
"render-template-1.0.9-165-linux-${OS_ARCH}-debian-12" \
|
||||
"php-8.4.21-2-linux-${OS_ARCH}-debian-12" \
|
||||
"nginx-1.31.0-1-linux-${OS_ARCH}-debian-12" \
|
||||
"php-8.4.21-3-linux-${OS_ARCH}-debian-12" \
|
||||
"nginx-1.31.1-0-linux-${OS_ARCH}-debian-12" \
|
||||
"mysql-client-12.2.2-0-linux-${OS_ARCH}-debian-12" \
|
||||
"postgresql-lib-18.4.0-0-linux-${OS_ARCH}-debian-12" \
|
||||
"wordpress-nginx-7.0.0-0-linux-${OS_ARCH}-debian-12" \
|
||||
@@ -58,7 +58,7 @@ RUN /opt/bitnami/scripts/nginx-php-fpm/postunpack.sh
|
||||
RUN /opt/bitnami/scripts/wordpress/postunpack.sh
|
||||
ENV APP_VERSION="7.0.0" \
|
||||
BITNAMI_APP_NAME="wordpress-nginx" \
|
||||
IMAGE_REVISION="0" \
|
||||
IMAGE_REVISION="1" \
|
||||
LD_LIBRARY_PATH="/opt/bitnami/postgresql/lib:$LD_LIBRARY_PATH" \
|
||||
NGINX_HTTPS_PORT_NUMBER="" \
|
||||
NGINX_HTTP_PORT_NUMBER="" \
|
||||
|
||||
@@ -139,3 +139,40 @@ wait_for_log_entry() {
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
########################
|
||||
# Creates a secure temporary file containing the provided secret
|
||||
# Arguments:
|
||||
# $1 - secret to write to the temporary file
|
||||
# Returns:
|
||||
# String
|
||||
#########################
|
||||
credential_to_temp_file() {
|
||||
local secret="$1"
|
||||
local tmp_file
|
||||
|
||||
# Use mktemp with a specific prefix for easier debugging if something lingers
|
||||
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
|
||||
echo "Error: Failed to create temp file" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
# Restrict permissions before writing the secret
|
||||
chmod 0600 "$tmp_file"
|
||||
# Write secret and ensure it's flushed to disk
|
||||
printf "%s" "$secret" > "$tmp_file"
|
||||
# Output the filename so the caller can capture it
|
||||
echo "$tmp_file"
|
||||
}
|
||||
|
||||
########################
|
||||
# Cleans up temporary files created by credential_to_temp_file
|
||||
# Arguments:
|
||||
# None
|
||||
# Returns:
|
||||
# None
|
||||
#########################
|
||||
cleanup_credentials() {
|
||||
debug "Cleaning up temporary files containing credentials"
|
||||
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
|
||||
}
|
||||
|
||||
@@ -263,7 +263,12 @@ mysql_execute_print_output() {
|
||||
fi
|
||||
args+=("-N" "-u" "$user")
|
||||
[[ -n "$db" ]] && args+=("$db")
|
||||
[[ -n "$pass" ]] && args+=("-p$pass")
|
||||
# Avoid passing credentials as arguments to mysql, to avoid leaking them given a local observer with /proc read access can read them
|
||||
if [[ -n "$pass" ]]; then
|
||||
local pass_file
|
||||
pass_file="$(credential_to_temp_file "$pass")"
|
||||
args+=("-p$(<"$pass_file")")
|
||||
fi
|
||||
[[ "${#opts[@]}" -gt 0 ]] && args+=("${opts[@]}")
|
||||
[[ "${#extra_opts[@]}" -gt 0 ]] && args+=("${extra_opts[@]}")
|
||||
|
||||
@@ -271,7 +276,6 @@ mysql_execute_print_output() {
|
||||
if [[ "${BITNAMI_DEBUG:-false}" = true ]]; then
|
||||
local mysql_cmd
|
||||
mysql_cmd="$(</dev/stdin)"
|
||||
debug "Executing SQL command:\n$mysql_cmd"
|
||||
"$(mysql_binary)" "${args[@]}" <<<"$mysql_cmd"
|
||||
else
|
||||
# Do not store the command(s) as a variable, to avoid issues when importing large files
|
||||
@@ -988,7 +992,10 @@ mysql_healthcheck() {
|
||||
|
||||
root_password="$(get_master_env_var_value ROOT_PASSWORD)"
|
||||
if [[ -n "$root_password" ]]; then
|
||||
args+=("-p${root_password}")
|
||||
# Avoid passing credentials as arguments to mysqladmin, to avoid leaking them given a local observer with /proc read access can read them
|
||||
local root_password_file
|
||||
root_password_file="$(credential_to_temp_file "$root_password")"
|
||||
args+=("-p$(<"$root_password_file")")
|
||||
fi
|
||||
|
||||
mysqladmin "${args[@]}" ping && mysqladmin "${args[@]}" status
|
||||
|
||||
Reference in New Issue
Block a user