mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-26 00:29:06 +02:00
[misc] Build the upload server from source, nonroot on Chainguard (#7663)
upload-server/Dockerfile only packaged the goreleaser-built binary, so the image could not be built from a checkout. It is now a multi-stage build on Chainguard static, running as the nonroot user (uid 65532), with a VARIANT=debug build arg that swaps in busybox for a shell. The goreleaser packaging file moves unchanged to Dockerfile.release and .goreleaser.yaml points at it, so the published netbirdio/upload image stays as it was: distroless and root. The bases are pinned by digest, since Chainguard publishes only :latest for free. A Dependabot docker entry for /upload-server moves them weekly, leaving the release base alone and holding golang to patch updates.
This commit is contained in:
@@ -46,3 +46,25 @@ updates:
|
||||
wireguard:
|
||||
patterns:
|
||||
- "golang.zx2c4.com/wireguard*"
|
||||
|
||||
# Base images of the source-build Dockerfiles, pinned by digest (Chainguard
|
||||
# publishes only :latest for free). Dockerfile.release files feed goreleaser
|
||||
# and keep the published images as they are, so their bases are left alone.
|
||||
- package-ecosystem: "docker"
|
||||
directories:
|
||||
- "/upload-server"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
open-pull-requests-limit: 3
|
||||
groups:
|
||||
base-images:
|
||||
patterns:
|
||||
- "*"
|
||||
ignore:
|
||||
- dependency-name: "gcr.io/distroless/base"
|
||||
# Go minor and major versions move with the rest of the repository;
|
||||
# patch releases and new digests of the pinned tag still come through.
|
||||
- dependency-name: "golang"
|
||||
update-types:
|
||||
- "version-update:semver-minor"
|
||||
- "version-update:semver-major"
|
||||
|
||||
Reference in New Issue
Block a user