mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-06 21:49:08 +02:00
[self-hosted] Add a UBI image variant for the combined server (#7953)
* [self-hosted] Add a UBI image variant for the combined server OpenShift and other Red Hat environments expect UBI-based images that run as an arbitrary non-root UID. The proxy and rootless client already ship -ubi variants; this adds the same for netbird-server, published as <version>-ubi and ubi-latest for amd64 and arm64. * [self-hosted] Check the license output path before creating temp files The existing-output exit ran before the cleanup trap was registered, so it left the two mktemp files behind. * [self-hosted] Certify the netbird-server UBI image Adds netbird-server to the Red Hat certification components. Its Partner Connect component ID goes in the REDHAT_CERT_ID_NETBIRD_SERVER repository variable.
This commit is contained in:
@@ -32,6 +32,7 @@ on:
|
|||||||
- all
|
- all
|
||||||
- client-rootless
|
- client-rootless
|
||||||
- reverse-proxy
|
- reverse-proxy
|
||||||
|
- netbird-server
|
||||||
version:
|
version:
|
||||||
description: "Released version, e.g. v0.80.0"
|
description: "Released version, e.g. v0.80.0"
|
||||||
type: string
|
type: string
|
||||||
@@ -66,6 +67,7 @@ jobs:
|
|||||||
components=(
|
components=(
|
||||||
"client-rootless ghcr.io/netbirdio/netbird -rootless-ubi"
|
"client-rootless ghcr.io/netbirdio/netbird -rootless-ubi"
|
||||||
"reverse-proxy ghcr.io/netbirdio/reverse-proxy -ubi"
|
"reverse-proxy ghcr.io/netbirdio/reverse-proxy -ubi"
|
||||||
|
"netbird-server ghcr.io/netbirdio/netbird-server -ubi"
|
||||||
)
|
)
|
||||||
matrix="[]"
|
matrix="[]"
|
||||||
missing=()
|
missing=()
|
||||||
|
|||||||
@@ -511,6 +511,41 @@ dockers_v2:
|
|||||||
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
||||||
"org.opencontainers.image.source": "{{.GitURL}}"
|
"org.opencontainers.image.source": "{{.GitURL}}"
|
||||||
"maintainer": "dev@netbird.io"
|
"maintainer": "dev@netbird.io"
|
||||||
|
- id: netbird-server-ubi
|
||||||
|
disable: "{{ .Env.SKIP_DOCKER_PUSH }}"
|
||||||
|
ids:
|
||||||
|
- netbird-server
|
||||||
|
images:
|
||||||
|
- netbirdio/netbird-server
|
||||||
|
- ghcr.io/netbirdio/netbird-server
|
||||||
|
tags:
|
||||||
|
- "{{ .Version }}-ubi"
|
||||||
|
- "{{ if eq .Env.SKIP_PUBLISH \"false\" }}ubi-latest{{ end }}"
|
||||||
|
dockerfile: combined/Dockerfile.ubi
|
||||||
|
platforms:
|
||||||
|
- linux/amd64
|
||||||
|
- linux/arm64
|
||||||
|
build_args:
|
||||||
|
VERSION: "{{ .Version }}"
|
||||||
|
RELEASE: "{{ .Timestamp }}"
|
||||||
|
hooks:
|
||||||
|
pre:
|
||||||
|
- cmd: 'sh combined/collect-licenses.sh "{{ .ContextDir }}/licenses" amd64 arm64'
|
||||||
|
env:
|
||||||
|
- GOOS=linux
|
||||||
|
- CGO_ENABLED=1
|
||||||
|
labels:
|
||||||
|
"org.opencontainers.image.created": "{{.Date}}"
|
||||||
|
"org.opencontainers.image.version": "{{.Version}}"
|
||||||
|
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
||||||
|
"org.opencontainers.image.source": "{{.GitURL}}"
|
||||||
|
annotations:
|
||||||
|
"org.opencontainers.image.created": "{{.Date}}"
|
||||||
|
"org.opencontainers.image.title": "{{.ProjectName}}"
|
||||||
|
"org.opencontainers.image.version": "{{.Version}}"
|
||||||
|
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
||||||
|
"org.opencontainers.image.source": "{{.GitURL}}"
|
||||||
|
"maintainer": "dev@netbird.io"
|
||||||
- id: netbird-proxy
|
- id: netbird-proxy
|
||||||
disable: "{{ .Env.SKIP_DOCKER_PUSH }}"
|
disable: "{{ .Env.SKIP_DOCKER_PUSH }}"
|
||||||
ids:
|
ids:
|
||||||
|
|||||||
@@ -0,0 +1,31 @@
|
|||||||
|
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
|
||||||
|
|
||||||
|
ARG TARGETPLATFORM
|
||||||
|
ARG VERSION=dev
|
||||||
|
ARG RELEASE=1
|
||||||
|
|
||||||
|
LABEL name="netbird-server" \
|
||||||
|
maintainer="NetBird <dev@netbird.io>" \
|
||||||
|
vendor="NetBird GmbH" \
|
||||||
|
version="${VERSION}" \
|
||||||
|
release="${RELEASE}" \
|
||||||
|
summary="NetBird Server" \
|
||||||
|
description="NetBird Server runs the Management, Signal, Relay and STUN services of a self-hosted NetBird deployment in a single process."
|
||||||
|
|
||||||
|
COPY --chmod=0555 ${TARGETPLATFORM}/netbird-server /go/bin/netbird-server
|
||||||
|
COPY licenses/ /licenses/
|
||||||
|
# Only the data directory shares the root group for arbitrary non-root UIDs.
|
||||||
|
# Runtime-created keys and databases retain the application's restrictive modes.
|
||||||
|
RUN mkdir -p /var/lib/netbird /etc/netbird && \
|
||||||
|
chown 1000:0 /var/lib/netbird && \
|
||||||
|
chmod 0770 /var/lib/netbird && \
|
||||||
|
chmod -R a+rX /licenses
|
||||||
|
|
||||||
|
USER 1000:0
|
||||||
|
ENV HOME=/var/lib/netbird
|
||||||
|
# Runtimes such as OpenShift and Podman reserve ports below 1024 for root, so
|
||||||
|
# the mounted config must set server.listenAddress to an unprivileged port.
|
||||||
|
EXPOSE 8443 3478/udp
|
||||||
|
STOPSIGNAL SIGTERM
|
||||||
|
ENTRYPOINT ["/go/bin/netbird-server"]
|
||||||
|
CMD ["--config", "/etc/netbird/config.yaml"]
|
||||||
@@ -0,0 +1,81 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
if [ "$#" -lt 2 ]; then
|
||||||
|
printf '%s\n' "usage: $0 OUTPUT_DIRECTORY GOARCH..." >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
repo_root=$(CDPATH='' cd -- "$(dirname "$0")/.." && pwd)
|
||||||
|
output_name=$(basename "$1")
|
||||||
|
if [ -z "$output_name" ] || [ "$output_name" = . ] || [ "$output_name" = .. ] || [ "$output_name" = / ]; then
|
||||||
|
printf '%s\n' "OUTPUT_DIRECTORY must name a directory" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
output_parent=$(CDPATH='' cd -- "$(dirname "$1")" && pwd)
|
||||||
|
output="$output_parent/$output_name"
|
||||||
|
shift
|
||||||
|
|
||||||
|
if [ -e "$output" ] || [ -L "$output" ]; then
|
||||||
|
printf 'output directory already exists: %s\n' "$output" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
modules=$(mktemp "${TMPDIR:-/tmp}/netbird-server-licenses.modules.XXXXXX")
|
||||||
|
sorted_modules=$(mktemp "${TMPDIR:-/tmp}/netbird-server-licenses.sorted.XXXXXX")
|
||||||
|
# Assemble beside the target and rename on success, so a failed run leaves
|
||||||
|
# nothing behind that would block the next attempt.
|
||||||
|
staging=$(mktemp -d "$output_parent/.$output_name.XXXXXX")
|
||||||
|
trap 'rm -f "$modules" "$sorted_modules"; rm -rf "$staging"' EXIT HUP INT TERM
|
||||||
|
mkdir "$staging/third_party"
|
||||||
|
|
||||||
|
cp "$repo_root/combined/LICENSE" "$staging/AGPL-3.0.txt"
|
||||||
|
cp "$repo_root/LICENSE" "$staging/BSD-3-Clause.txt"
|
||||||
|
|
||||||
|
cd "$repo_root"
|
||||||
|
for arch in "$@"; do
|
||||||
|
GOOS=${GOOS:-linux} GOARCH="$arch" CGO_ENABLED=${CGO_ENABLED:-1} \
|
||||||
|
go list -deps -f '{{with .Module}}{{if .Replace}}{{.Replace.Path}}{{"\t"}}{{.Replace.Version}}{{"\t"}}{{.Replace.Dir}}{{else}}{{.Path}}{{"\t"}}{{.Version}}{{"\t"}}{{.Dir}}{{end}}{{end}}' ./combined >>"$modules"
|
||||||
|
done
|
||||||
|
LC_ALL=C sort -u "$modules" >"$sorted_modules"
|
||||||
|
|
||||||
|
goroot=$(go env GOROOT)
|
||||||
|
for term in LICENSE PATENTS; do
|
||||||
|
if [ ! -f "$goroot/$term" ]; then
|
||||||
|
printf 'missing Go standard-library term: %s\n' "$goroot/$term" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
cp "$goroot/$term" "$staging/Go-$term"
|
||||||
|
done
|
||||||
|
|
||||||
|
while IFS=' ' read -r module version module_dir; do
|
||||||
|
[ -n "$module" ] || continue
|
||||||
|
[ "$module" = "github.com/netbirdio/netbird" ] && continue
|
||||||
|
|
||||||
|
if [ -z "$version" ] || [ ! -d "$module_dir" ]; then
|
||||||
|
printf 'cannot collect terms for module %s at version %s\n' "$module" "$version" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
destination="$staging/third_party/$module/$version"
|
||||||
|
mkdir -p "$destination"
|
||||||
|
printf 'module: %s\nversion: %s\n' "$module" "$version" >"$destination/MODULE"
|
||||||
|
|
||||||
|
found=false
|
||||||
|
for term in \
|
||||||
|
"$module_dir"/LICENSE* "$module_dir"/License* "$module_dir"/license* \
|
||||||
|
"$module_dir"/LICENCE* "$module_dir"/Licence* "$module_dir"/licence* \
|
||||||
|
"$module_dir"/COPYING* "$module_dir"/Copying* "$module_dir"/copying* \
|
||||||
|
"$module_dir"/NOTICE* "$module_dir"/Notice* "$module_dir"/notice* \
|
||||||
|
"$module_dir"/PATENTS* "$module_dir"/Patents* "$module_dir"/patents*; do
|
||||||
|
[ -f "$term" ] || continue
|
||||||
|
cp "$term" "$destination/"
|
||||||
|
found=true
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$found" = false ]; then
|
||||||
|
printf 'no root license terms found for module %s at %s\n' "$module" "$module_dir" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done <"$sorted_modules"
|
||||||
|
|
||||||
|
mv "$staging" "$output"
|
||||||
Reference in New Issue
Block a user