mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-06 22:51:16 +02:00
enhancement: Change base image from alpine to distroless (#2295)
* Changed base image from alpine to distroless * chore: updated Makefile * fix: removed arm/v6 and ppc64le for distroless variant * Update Dockerfile * Update Makefile * docs: Add README-section, CHANGELOG-entry and --pull to prevent caching --------- Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>
This commit is contained in:
co-authored by
Joel Speed
parent
c7185e7005
commit
be84906fbc
+2
-5
@@ -1,5 +1,5 @@
|
||||
# This ARG has to be at the top, otherwise the docker daemon does not known what to do with FROM ${RUNTIME_IMAGE}
|
||||
ARG RUNTIME_IMAGE=docker.io/library/alpine:3.18
|
||||
ARG RUNTIME_IMAGE=gcr.io/distroless/static:nonroot
|
||||
|
||||
# All builds should be done using the platform native to the build node to allow
|
||||
# cache sharing of the go mod download step.
|
||||
@@ -43,13 +43,10 @@ RUN case ${TARGETPLATFORM} in \
|
||||
printf "Building OAuth2 Proxy for arch ${GOARCH}\n" && \
|
||||
GOARCH=${GOARCH} VERSION=${VERSION} make build && touch jwt_signing_key.pem
|
||||
|
||||
# Copy binary to alpine
|
||||
# Copy binary to runtime image
|
||||
FROM ${RUNTIME_IMAGE}
|
||||
COPY nsswitch.conf /etc/nsswitch.conf
|
||||
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/oauth2-proxy /bin/oauth2-proxy
|
||||
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/jwt_signing_key.pem /etc/ssl/private/jwt_signing_key.pem
|
||||
|
||||
# UID/GID 65532 is also known as nonroot user in distroless image
|
||||
USER 65532:65532
|
||||
|
||||
ENTRYPOINT ["/bin/oauth2-proxy"]
|
||||
|
||||
Reference in New Issue
Block a user