diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 6ab9da749..48dcf7ff0 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -484,15 +484,15 @@ dockers_v2: dockerfile: signal/Dockerfile.ubi platforms: - linux/amd64 + - linux/arm64 build_args: VERSION: "{{ .Version }}" RELEASE: "{{ .Timestamp }}" hooks: pre: - - cmd: 'sh signal/collect-licenses.sh "{{ .ContextDir }}/licenses"' + - cmd: 'sh release_files/collect-licenses.sh -l signal/LICENSE "{{ .ContextDir }}/licenses" ./signal amd64 arm64' env: - GOOS=linux - - GOARCH=amd64 - CGO_ENABLED=0 labels: "org.opencontainers.image.created": "{{.Date}}" diff --git a/signal/Dockerfile.ubi b/signal/Dockerfile.ubi index 5f93d0551..a33800b1f 100644 --- a/signal/Dockerfile.ubi +++ b/signal/Dockerfile.ubi @@ -9,15 +9,28 @@ LABEL name="netbird-signal" \ vendor="NetBird GmbH" \ version="${VERSION}" \ release="${RELEASE}" \ - summary="NetBird Signal server" \ - description="NetBird Signal brokers peer handshakes." + summary="NetBird Signal" \ + description="NetBird Signal brokers the connection handshakes between peers in NetBird networks." COPY --chmod=0555 ${TARGETPLATFORM}/netbird-signal /go/bin/netbird-signal -COPY licenses/AGPL-3.0.txt licenses/BSD-3-Clause.txt licenses/Go-LICENSE licenses/Go-PATENTS /licenses/ -COPY licenses/third_party/ /licenses/third_party/ -RUN chmod -R a+rX /licenses +COPY licenses/ /licenses/ +# Only the data directory shares the root group for arbitrary non-root UIDs. +# Runtime-created Let's Encrypt keys retain the application's restrictive modes. +RUN mkdir -p /var/lib/netbird && \ + chown 1000:0 /var/lib/netbird && \ + chmod 0770 /var/lib/netbird && \ + chmod -R a+rX /licenses -USER 65532 +USER 1000:0 +ENV HOME=/var/lib/netbird +ENV NB_LETSENCRYPT_DATA_DIR="/var/lib/netbird" +# Unprivileged ports: runtimes such as OpenShift and Podman keep the kernel +# default that reserves ports below 1024 for root, so serve on the legacy +# gRPC port instead of 80/443. Let's Encrypt also needs its challenge +# listener on an unprivileged port. 9090 is the metrics endpoint. +ENV NB_PORT="10000" +EXPOSE 10000 9090 +# The signal server only handles SIGINT for a graceful stop. STOPSIGNAL SIGINT -ENTRYPOINT [ "/go/bin/netbird-signal", "run" ] +ENTRYPOINT ["/go/bin/netbird-signal", "run"] CMD ["--log-file", "console"] diff --git a/signal/collect-licenses.sh b/signal/collect-licenses.sh deleted file mode 100755 index 904f456c7..000000000 --- a/signal/collect-licenses.sh +++ /dev/null @@ -1,76 +0,0 @@ -#!/bin/sh -set -eu - -if [ "$#" -ne 1 ]; then - printf '%s\n' "usage: $0 OUTPUT_DIRECTORY" >&2 - exit 2 -fi - -repo_root=$(CDPATH= cd -- "$(dirname "$0")/.." && pwd) -output_name=$(basename "$1") -case "$output_name" in - "" | . | .. | /) - printf '%s\n' "OUTPUT_DIRECTORY must name a directory" >&2 - exit 2 - ;; -esac -output_parent=$(CDPATH= cd -- "$(dirname "$1")" && pwd) -output="$output_parent/$output_name" -modules=$(mktemp "${TMPDIR:-/tmp}/netbird-signal-licenses.modules.XXXXXX") -sorted_modules=$(mktemp "${TMPDIR:-/tmp}/netbird-signal-licenses.sorted.XXXXXX") -trap 'rm -f "$modules" "$sorted_modules"' EXIT HUP INT TERM - -if [ -e "$output" ] || [ -L "$output" ]; then - printf 'output directory already exists: %s\n' "$output" >&2 - exit 1 -fi -mkdir "$output" -mkdir "$output/third_party" - -cp "$repo_root/signal/LICENSE" "$output/AGPL-3.0.txt" -cp "$repo_root/LICENSE" "$output/BSD-3-Clause.txt" - -cd "$repo_root" -GOOS=${GOOS:-linux} GOARCH=${GOARCH:-amd64} CGO_ENABLED=${CGO_ENABLED:-0} \ - go list -deps -f '{{with .Module}}{{if .Replace}}{{.Replace.Path}}{{"\t"}}{{.Replace.Version}}{{"\t"}}{{.Replace.Dir}}{{else}}{{.Path}}{{"\t"}}{{.Version}}{{"\t"}}{{.Dir}}{{end}}{{end}}' ./signal >"$modules" -LC_ALL=C sort -u "$modules" >"$sorted_modules" - -goroot=$(go env GOROOT) -for term in LICENSE PATENTS; do - if [ ! -f "$goroot/$term" ]; then - printf 'missing Go standard-library term: %s\n' "$goroot/$term" >&2 - exit 1 - fi - cp "$goroot/$term" "$output/Go-$term" -done - -while IFS=' ' read -r module version module_dir; do - [ -n "$module" ] || continue - [ "$module" = "github.com/netbirdio/netbird" ] && continue - - if [ -z "$version" ] || [ ! -d "$module_dir" ]; then - printf 'cannot collect terms for module %s at version %s\n' "$module" "$version" >&2 - exit 1 - fi - - destination="$output/third_party/$module/$version" - mkdir -p "$destination" - printf 'module: %s\nversion: %s\n' "$module" "$version" >"$destination/MODULE" - - found=false - for term in \ - "$module_dir"/LICENSE* "$module_dir"/License* "$module_dir"/license* \ - "$module_dir"/LICENCE* "$module_dir"/Licence* "$module_dir"/licence* \ - "$module_dir"/COPYING* "$module_dir"/Copying* "$module_dir"/copying* \ - "$module_dir"/NOTICE* "$module_dir"/Notice* "$module_dir"/notice* \ - "$module_dir"/PATENTS* "$module_dir"/Patents* "$module_dir"/patents*; do - [ -f "$term" ] || continue - cp "$term" "$destination/" - found=true - done - - if [ "$found" = false ]; then - printf 'no root license terms found for module %s at %s\n' "$module" "$module_dir" >&2 - exit 1 - fi -done <"$sorted_modules"