mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-06 21:49:08 +02:00
* [self-hosted] Add a UBI image variant for the combined server OpenShift and other Red Hat environments expect UBI-based images that run as an arbitrary non-root UID. The proxy and rootless client already ship -ubi variants; this adds the same for netbird-server, published as <version>-ubi and ubi-latest for amd64 and arm64. * [self-hosted] Check the license output path before creating temp files The existing-output exit ran before the cleanup trap was registered, so it left the two mktemp files behind. * [self-hosted] Certify the netbird-server UBI image Adds netbird-server to the Red Hat certification components. Its Partner Connect component ID goes in the REDHAT_CERT_ID_NETBIRD_SERVER repository variable.
32 lines
1.2 KiB
Docker
32 lines
1.2 KiB
Docker
FROM registry.access.redhat.com/ubi9/ubi-minimal@sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
|
|
|
|
ARG TARGETPLATFORM
|
|
ARG VERSION=dev
|
|
ARG RELEASE=1
|
|
|
|
LABEL name="netbird-server" \
|
|
maintainer="NetBird <dev@netbird.io>" \
|
|
vendor="NetBird GmbH" \
|
|
version="${VERSION}" \
|
|
release="${RELEASE}" \
|
|
summary="NetBird Server" \
|
|
description="NetBird Server runs the Management, Signal, Relay and STUN services of a self-hosted NetBird deployment in a single process."
|
|
|
|
COPY --chmod=0555 ${TARGETPLATFORM}/netbird-server /go/bin/netbird-server
|
|
COPY licenses/ /licenses/
|
|
# Only the data directory shares the root group for arbitrary non-root UIDs.
|
|
# Runtime-created keys and databases retain the application's restrictive modes.
|
|
RUN mkdir -p /var/lib/netbird /etc/netbird && \
|
|
chown 1000:0 /var/lib/netbird && \
|
|
chmod 0770 /var/lib/netbird && \
|
|
chmod -R a+rX /licenses
|
|
|
|
USER 1000:0
|
|
ENV HOME=/var/lib/netbird
|
|
# Runtimes such as OpenShift and Podman reserve ports below 1024 for root, so
|
|
# the mounted config must set server.listenAddress to an unprivileged port.
|
|
EXPOSE 8443 3478/udp
|
|
STOPSIGNAL SIGTERM
|
|
ENTRYPOINT ["/go/bin/netbird-server"]
|
|
CMD ["--config", "/etc/netbird/config.yaml"]
|