mirror of
https://github.com/GoogleContainerTools/kaniko
synced 2026-10-03 00:44:43 +02:00
In v1.8.0 (commit 7410007) kaniko switched to using the pax tar header
format for compressing image layers, since this format allows for greater
precision in recording timestamps, however this inadvertendly broke the
"--reproducible" functionality, due to an bug in the underlying
go-containerregistry dependency which did not set the additional
timestamps in the pax header when canonicalizing image layers. This
oversight has since been fixed in the dependency.
This commit bumps the google/go-containerregistry dependency to the
first commit which has fixed the bug
(v0.13.1-0.20230201183932-824efc7772b0). It also bumps the version of
cloud.google.com/go/storage to v1.29.0 to be compatible with the higher
transitive dependency.
51 lines
1.6 KiB
Docker
51 lines
1.6 KiB
Docker
# syntax=docker/dockerfile:1.3
|
|
|
|
ARG GO_VERSION=1.16.15
|
|
ARG GORELEASER_XX_VERSION=1.2.5
|
|
|
|
FROM --platform=$BUILDPLATFORM crazymax/goreleaser-xx:${GORELEASER_XX_VERSION} AS goreleaser-xx
|
|
FROM --platform=$BUILDPLATFORM golang:${GO_VERSION}-alpine AS base
|
|
COPY --from=goreleaser-xx / /
|
|
RUN apk add --no-cache file git
|
|
WORKDIR /go/src/github.com/docker/distribution
|
|
|
|
FROM base AS build
|
|
ENV GO111MODULE=auto
|
|
ENV CGO_ENABLED=0
|
|
# GIT_REF is used by goreleaser-xx to handle the proper git ref when available.
|
|
# It will fallback to the working tree info if empty and use "git tag --points-at"
|
|
# or "git describe" to define the version info.
|
|
ARG GIT_REF
|
|
ARG TARGETPLATFORM
|
|
ARG PKG="github.com/distribution/distribution"
|
|
ARG BUILDTAGS="include_oss include_gcs"
|
|
RUN --mount=type=bind,rw \
|
|
--mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=target=/go/pkg/mod,type=cache \
|
|
goreleaser-xx --debug \
|
|
--name="registry" \
|
|
--dist="/out" \
|
|
--main="./cmd/registry" \
|
|
--flags="-v" \
|
|
--ldflags="-s -w -X '$PKG/version.Version={{.Version}}' -X '$PKG/version.Revision={{.Commit}}' -X '$PKG/version.Package=$PKG'" \
|
|
--tags="$BUILDTAGS" \
|
|
--files="LICENSE" \
|
|
--files="README.md"
|
|
|
|
FROM scratch AS artifact
|
|
COPY --from=build /out/*.tar.gz /
|
|
COPY --from=build /out/*.zip /
|
|
COPY --from=build /out/*.sha256 /
|
|
|
|
FROM scratch AS binary
|
|
COPY --from=build /usr/local/bin/registry* /
|
|
|
|
FROM alpine:3.14
|
|
RUN apk add --no-cache ca-certificates
|
|
COPY cmd/registry/config-dev.yml /etc/docker/registry/config.yml
|
|
COPY --from=build /usr/local/bin/registry /bin/registry
|
|
VOLUME ["/var/lib/registry"]
|
|
EXPOSE 5000
|
|
ENTRYPOINT ["registry"]
|
|
CMD ["serve", "/etc/docker/registry/config.yml"]
|