mirror of
https://github.com/bitnami/containers.git
synced 2026-10-10 11:00:31 +02:00
[bitnami/cassandra] Release 5.0.8-debian-12-r3 (#93736)
Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
@@ -8,7 +8,7 @@ ARG JAVA_EXTRA_SECURITY_DIR="/bitnami/java/extra-security"
|
||||
ARG TARGETARCH
|
||||
|
||||
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
|
||||
org.opencontainers.image.created="2026-05-21T01:06:42Z" \
|
||||
org.opencontainers.image.created="2026-05-22T09:12:02Z" \
|
||||
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
|
||||
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/cassandra/README.md" \
|
||||
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/cassandra" \
|
||||
@@ -55,7 +55,7 @@ RUN /opt/bitnami/scripts/cassandra/postunpack.sh
|
||||
RUN /opt/bitnami/scripts/java/postunpack.sh
|
||||
ENV APP_VERSION="5.0.8" \
|
||||
BITNAMI_APP_NAME="cassandra" \
|
||||
IMAGE_REVISION="2" \
|
||||
IMAGE_REVISION="3" \
|
||||
JAVA_HOME="/opt/bitnami/java" \
|
||||
PATH="/opt/bitnami/python/bin:/opt/bitnami/java/bin:/opt/bitnami/cassandra/bin:$PATH"
|
||||
|
||||
|
||||
@@ -63,21 +63,31 @@ cassandra_setup_client_ssl() {
|
||||
|
||||
mkdir -p "$(dirname "${DB_SSL_CERT_FILE}")"
|
||||
|
||||
# Avoid passing keystore passwords as arguments to keytool, to avoid leaking them given
|
||||
# given a local observer with /proc read access can read them
|
||||
# Instead, we can read them from temporary files
|
||||
local keystore_password_file
|
||||
keystore_password_file="$(mktemp)"
|
||||
chmod 0600 "$keystore_password_file"
|
||||
echo "$DB_KEYSTORE_PASSWORD" > "$keystore_password_file"
|
||||
# shellcheck disable=SC2064
|
||||
trap "rm -f $keystore_password_file" RETURN ERR INT TERM
|
||||
|
||||
if [[ "${JAVA_FIPS_MODE:-}" == "restricted" ]]; then
|
||||
keytool -importkeystore -srckeystore "${DB_KEYSTORE_LOCATION}" \
|
||||
-destkeystore "${DB_SSL_CERT_FILE}" \
|
||||
-storetype BCFKS \
|
||||
-srcstorepass "${DB_KEYSTORE_PASSWORD}" \
|
||||
-deststorepass "${DB_KEYSTORE_PASSWORD}"
|
||||
-srcstorepass "$(<"$keystore_password_file")" \
|
||||
-deststorepass "$(<"$keystore_password_file")"
|
||||
else
|
||||
keytool -importkeystore -srckeystore "${DB_KEYSTORE_LOCATION}" \
|
||||
-destkeystore "${DB_TMP_P12_FILE}" \
|
||||
-deststoretype PKCS12 \
|
||||
-srcstorepass "${DB_KEYSTORE_PASSWORD}" \
|
||||
-deststorepass "${DB_KEYSTORE_PASSWORD}"
|
||||
-srcstorepass "$(<"$keystore_password_file")" \
|
||||
-deststorepass "$(<"$keystore_password_file")"
|
||||
|
||||
openssl pkcs12 -in "${DB_TMP_P12_FILE}" -nokeys \
|
||||
-out "${DB_SSL_CERT_FILE}" -passin pass:"${DB_KEYSTORE_PASSWORD}"
|
||||
-out "${DB_SSL_CERT_FILE}" -passin pass:"$(<"$keystore_password_file")"
|
||||
|
||||
rm "${DB_TMP_P12_FILE}"
|
||||
fi
|
||||
@@ -791,6 +801,8 @@ cassandra_create_admin_user() {
|
||||
local -r escaped_password="${password//\'/\'\'}"
|
||||
|
||||
echo "CREATE USER '${new_user}' WITH PASSWORD \$\$${escaped_password}\$\$ SUPERUSER;" | cassandra_execute_with_retries "$retries" "$sleep_time" "$admin_user" "$admin_user_password"
|
||||
info "Dropping builtin 'cassandra' superuser"
|
||||
echo "DROP USER 'cassandra';" | cassandra_execute_with_retries "$retries" "$sleep_time" "$new_user" "$password"
|
||||
}
|
||||
|
||||
########################
|
||||
@@ -1027,7 +1039,18 @@ cassandra_execute() {
|
||||
local -r extra_args="${5:-}"
|
||||
local -r port="${DB_CQL_PORT_NUMBER}"
|
||||
local -r cmd=("cqlsh")
|
||||
local args=("-u" "$user" "-p" "$pass")
|
||||
|
||||
# Avoid passing user / password as arguments to cqlsh, to avoid leaking them given
|
||||
# cqlsh is a Python client and does not scrub argv, so the cleartext password appears
|
||||
# in /proc/<pid>/cmdline for the duration of every init-time CQL call.
|
||||
# Instead, we use a temporary cqlshrc credentials file
|
||||
local cqlshrc
|
||||
cqlshrc="$(mktemp)"
|
||||
chmod 0600 "$cqlshrc"
|
||||
printf '[authentication]\nusername = %s\npassword = %s\n' "$user" "$pass" > "$cqlshrc"
|
||||
# shellcheck disable=SC2064
|
||||
trap "rm -f $cqlshrc" RETURN ERR INT TERM
|
||||
local args=("--cqlshrc" "$cqlshrc")
|
||||
|
||||
is_boolean_yes "$DB_CLIENT_ENCRYPTION" && args+=("--ssl")
|
||||
[[ -n "$keyspace" ]] && args+=("-k" "$keyspace")
|
||||
|
||||
Reference in New Issue
Block a user