enhancement: Change base image from alpine to distroless (#2295)

* Changed base image from alpine to distroless

* chore: updated Makefile

* fix: removed arm/v6 and ppc64le for distroless variant

* Update Dockerfile

* Update Makefile

* docs: Add README-section, CHANGELOG-entry and --pull to prevent caching

---------

Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>
This commit is contained in:
Koen van Zuijlen
2024-01-20 18:48:04 +00:00
committed by GitHub
co-authored by Joel Speed
parent c7185e7005
commit be84906fbc
4 changed files with 43 additions and 24 deletions
+2 -5
View File
@@ -1,5 +1,5 @@
# This ARG has to be at the top, otherwise the docker daemon does not known what to do with FROM ${RUNTIME_IMAGE}
ARG RUNTIME_IMAGE=docker.io/library/alpine:3.18
ARG RUNTIME_IMAGE=gcr.io/distroless/static:nonroot
# All builds should be done using the platform native to the build node to allow
# cache sharing of the go mod download step.
@@ -43,13 +43,10 @@ RUN case ${TARGETPLATFORM} in \
printf "Building OAuth2 Proxy for arch ${GOARCH}\n" && \
GOARCH=${GOARCH} VERSION=${VERSION} make build && touch jwt_signing_key.pem
# Copy binary to alpine
# Copy binary to runtime image
FROM ${RUNTIME_IMAGE}
COPY nsswitch.conf /etc/nsswitch.conf
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/oauth2-proxy /bin/oauth2-proxy
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/jwt_signing_key.pem /etc/ssl/private/jwt_signing_key.pem
# UID/GID 65532 is also known as nonroot user in distroless image
USER 65532:65532
ENTRYPOINT ["/bin/oauth2-proxy"]