From 7e5eadb491de3ec30a5aa70ac779e847874ac93d Mon Sep 17 00:00:00 2001 From: Andrei Jiroh Halili Date: Sat, 31 Aug 2024 18:47:04 +0000 Subject: [PATCH] feat(docker): add custom image for FrakenPHP and more CI related updates Also in this update, we'll be using GitLab Dependency Proxy for pulling Docker Hub images as a way to limit rate-limit related issues on CI. Signed-off-by: Andrei Jiroh Halili --- .github/workflows/docker-buildops.yml | 96 +++++++++++++++++++ .github/workflows/lint-and-test.yml | 5 +- docker/caddy/Dockerfile | 26 ++--- docker/caddy/php.Dockerfile | 74 ++++++++++++++ docker/devenv/base/Dockerfile | 7 +- docker/devenv/base/alpine.Dockerfile | 8 ++ .../devenv/base/sources.list.d/caddy.sources | 5 + docker/mkdocs-material/Dockerfile | 3 +- docker/pkgops-alpine/Dockerfile | 3 +- 9 files changed, 203 insertions(+), 24 deletions(-) create mode 100644 docker/caddy/php.Dockerfile create mode 100644 docker/devenv/base/alpine.Dockerfile create mode 100644 docker/devenv/base/sources.list.d/caddy.sources diff --git a/.github/workflows/docker-buildops.yml b/.github/workflows/docker-buildops.yml index 47e2a96..289d219 100644 --- a/.github/workflows/docker-buildops.yml +++ b/.github/workflows/docker-buildops.yml @@ -346,3 +346,99 @@ jobs: subject-name: index.docker.io/ajhalili2006/pkgsops-alpine subject-digest: ${{ steps.build.outputs.digest }} push-to-registry: true + caddy: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Load secrets with dotenvx + uses: andreijiroh-dev/dotenvx-action@v0.3.0 + if: github.event_name != 'pull_request' + id: dotenvx + with: + path: .env.ci + key: ${{ secrets.DOTENV_PRIVATE_KEY_CI }} + + # Workaround: https://github.com/docker/build-push-action/issues/461 + - name: Setup Docker buildx + uses: docker/setup-buildx-action@v3 + with: + buildkitd-flags: --debug + + # Login against a Docker registry except on PR + # https://github.com/docker/login-action + - name: Sign in to GitLab Dependency Proxy + uses: docker/login-action@v3 + with: + registry: mau.dev + username: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_PASSWORD }} + - name: Login into GLCR on mau.dev + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: dock.mau.dev + username: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_PASSWORD }} + - name: Log into GHCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ steps.dotenvx.outputs.GHCR_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GHCR_BOT_PASSWORD }} + + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/caddy + dock.mau.dev/${{ env.IMAGE_NAME_PREFIX }}/caddy + tags: | + type=raw,value=latest,enable={{is_default_branch}} + type=sha,enable=true,priority=100,prefix=commit-,suffix=,format=long + type=schedule,pattern=nightly + type=schedule,prefix=nightly-,pattern={{date 'YYYYMMDDhhmmss'}} + type=raw,prefix=branch-,value={{branch}} + + - name: Extract Docker metadata + id: meta-frankenphp + uses: docker/metadata-action@v5 + with: + images: | + ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/frankenphp + dock.mau.dev/${{ env.IMAGE_NAME_PREFIX }}/franken-php + tags: | + type=raw,value=latest,enable={{is_default_branch}} + type=sha,enable=true,priority=100,prefix=commit-,suffix=,format=long + type=schedule,pattern=nightly + type=schedule,prefix=nightly-,pattern={{date 'YYYYMMDDhhmmss'}} + type=raw,prefix=branch-,value={{branch}} + + - name: Build and push image + uses: docker/build-push-action@v6 + id: build-main + with: + context: docker/caddy + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + pull: true + provenance: mode=max + sbom: true + - name: Build and push image for FrankenPHP + uses: docker/build-push-action@v6 + id: build-fphp + continue-on-error: true + with: + context: docker/pkgops-alpine + file: docker/pkgops-alpine/php.Dockerfile + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + pull: true + provenance: mode=max + sbom: true + \ No newline at end of file diff --git a/.github/workflows/lint-and-test.yml b/.github/workflows/lint-and-test.yml index 7f6d594..ebf235a 100644 --- a/.github/workflows/lint-and-test.yml +++ b/.github/workflows/lint-and-test.yml @@ -1,10 +1,9 @@ name: Linters and Tests on: + push: pull_request: branches: [ "main" ] - paths: - - docker/** jobs: hadolint: @@ -17,5 +16,5 @@ jobs: with: dockerfile: Dockerfile recursive: true - trusted-registries: quay.io, ghcr.io,docker.io,dock.mau.dev,index.docker.io,registry-1.docker.io + trusted-registries: mau.dev,quay.io,ghcr.io,docker.io,dock.mau.dev,index.docker.io,registry-1.docker.io continue-on-error: true \ No newline at end of file diff --git a/docker/caddy/Dockerfile b/docker/caddy/Dockerfile index a105ccd..4edeb2d 100644 --- a/docker/caddy/Dockerfile +++ b/docker/caddy/Dockerfile @@ -1,10 +1,7 @@ # syntax=docker/dockerfile:1 -FROM mau.dev/andreijiroh-dev/dependency_proxy/containers/tailscale/tailscale:latest as tailscale +FROM tailscale/tailscale:latest as tailscale -FROM mau.dev/andreijiroh-dev/dependency_proxy/containers/caddy:builder-alpine as builder - -ARG CGO_ENABLED=1 -ARG XCADDY_GO_BUILD_FLAGS="-ldflags '-w -s -Wl,-z,stack-size=0x80000'" +FROM caddy:builder-alpine as builder RUN xcaddy build \ --with github.com/caddy-dns/cloudflare \ @@ -12,18 +9,15 @@ RUN xcaddy build \ --with github.com/caddy-dns/netlify \ --with github.com/ss098/certmagic-s3 \ --with github.com/sagikazarmark/caddy-fs-s3 \ - --with github.com/kadeessh/kadeessh \ - --with github.com/dunglas/frankenphp/caddy \ - --with github.com/dunglas/caddy-cbrotli \ - --with github.com/dunglas/mercure/caddy \ - --with github.com/dunglas/vulcain/caddy - -FROM mau.dev/andreijiroh-dev/dependency_proxy/containers/caddy:alpine as deploy + --with github.com/kadeessh/kadeessh -COPY entrypoint.sh /usr/local/bin/ -RUN apk add --no-cache ca-certificates iptables iproute2 ip6tables \ - && mkdir -p /var/run/tailscale /var/cache/tailscale /var/lib/tailscale +FROM caddy:alpine as runner COPY --from=builder /usr/bin/caddy /usr/bin/caddy COPY --from=tailscale /usr/local/bin/tailscale /usr/local/bin/tailscaled /usr/local/bin/ -RUN ["/usr/local/bin/entrypoint.sh"] +COPY entrypoint.sh /usr/local/bin/ +RUN apk add --no-cache ca-certificates iptables iproute2 ip6tables bash ca-certificates libcap mailcap \ + && mkdir -p /var/run/tailscale /var/cache/tailscale /var/lib/tailscale \ + && setcap cap_net_bind_service=+ep /usr/bin/caddy +ENTRYPOINT [ "/usr/bin/dumb-init" ] +CMD ["/usr/local/bin/entrypoint.sh"] diff --git a/docker/caddy/php.Dockerfile b/docker/caddy/php.Dockerfile new file mode 100644 index 0000000..56580ce --- /dev/null +++ b/docker/caddy/php.Dockerfile @@ -0,0 +1,74 @@ +# syntax=docker/dockerfile:1-labs +ARG GITLAB_DEPENDENCY_PROXY_PATH=mau.dev/andreijiroh-dev + +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/tailscale/tailscale:latest as tailscale + +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/golang:1.22.5-alpine as golang + +# At this stage, we need to compile go from source using go1.22.5 binaries from official image +# while reverting commit 3560cf0afb3c29300a6c88ccd98256949ca7a6f6 as a workaround to +# https://github.com/golang/go/issues/68285. +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/dunglas/frankenphp:alpine as builder +ENV PATH="/usr/local/golang/bin:$PATH" GOROOT=/usr/local/golang GOPATH=/usr/local/golang +RUN apk add --no-cache \ + autoconf \ + dpkg-dev \ + file \ + g++ \ + gcc \ + libc-dev \ + make \ + pkgconfig \ + re2c \ + argon2-dev \ + brotli-dev \ + coreutils \ + curl-dev \ + gnu-libiconv-dev \ + libsodium-dev \ + libxml2-dev \ + linux-headers \ + oniguruma-dev \ + openssl-dev \ + readline-dev \ + sqlite-dev \ + upx \ + # Needed for the custom Go build + git \ + bash \ + && git config --global user.email "builds@andreijiroh.xyz" \ + && git config --global user.name "BuildOps" \ + && git clone --single-branch --branch go1.22.6 https://github.com/golang/go.git /usr/local/golang + +WORKDIR /usr/local/golang/src +COPY --from=golang /usr/local/go /usr/local/gobootstrap +RUN export GOROOT_BOOTSTRAP=/usr/local/gobootstrap \ + && git checkout && git revert 3560cf0afb3c29300a6c88ccd98256949ca7a6f6 \ + && mkdir /go \ + && ./make.bash \ + && /usr/local/golang/bin/go install github.com/caddyserver/xcaddy/cmd/xcaddy@latest +ARG CGO_ENABLED=1 +ARG XCADDY_GO_BUILD_FLAGS="-ldflags '-w -s'" + +RUN xcaddy build \ + --with github.com/sagikazarmark/caddy-fs-s3 \ + --with github.com/dunglas/frankenphp/caddy \ + --with github.com/dunglas/caddy-cbrotli \ + --with github.com/dunglas/mercure/caddy \ + --with github.com/dunglas/vulcain/caddy \ + --output /usr/local/bin/frankenphp-buildkit \ + && setcap cap_net_bind_service=+ep /usr/local/bin/frankenphp-buildkit \ + && upx --best /usr/local/bin/frankenphp-buildkit + +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/dunglas/frankenphp:alpine as runner + +COPY --from=builder /usr/local/bin/frankenphp-buildkit /usr/local/bin/frankenphp +COPY --from=tailscale /usr/local/bin/tailscale /usr/local/bin/tailscaled /usr/local/bin/ +COPY entrypoint.sh /usr/local/bin/ +RUN apk add --no-cache ca-certificates iptables iproute2 ip6tables dumb-init bash \ + && mkdir -p /var/run/tailscale /var/cache/tailscale /var/lib/tailscale \ + && chmod +x /usr/local/bin/entrypoint.sh \ + && ln -s /usr/local/bin/frankenphp /usr/local/bin/caddy \ + && setcap cap_net_bind_service=+ep /usr/local/bin/frankenphp +ENTRYPOINT [ "dumb-init" ] +CMD ["/usr/local/bin/entrypoint.sh"] diff --git a/docker/devenv/base/Dockerfile b/docker/devenv/base/Dockerfile index caa73f6..343ea3f 100644 --- a/docker/devenv/base/Dockerfile +++ b/docker/devenv/base/Dockerfile @@ -1,13 +1,13 @@ ARG BUILDPACK_DEPS_TAG=noble -FROM buildpack-deps:${BUILDPACK_DEPS_TAG} +ARG GITLAB_DEPENDENCY_PROXY_PATH=mau.dev/andreijiroh-dev +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/buildpack-deps:${BUILDPACK_DEPS_TAG} USER root # Get the utility scripts from gitpod for use during the build. RUN curl -o /usr/local/bin/install-packages -fsSL https://github.com/gitpod-io/workspace-images/raw/main/base/install-packages \ - && curl -o /usr/local/bin/upgrade-packages -fsSL https://github.com/gitpod-io/workspace-images/raw/main/base/install-packages \ && chmod +x /usr/local/bin/install-packages \ - && chmod +x /usr/local/bin/upgrade-packages + && ln -s /usr/local/bin/install-packages /usr/local/bin/upgrade-packages RUN yes | unminimize \ && install-packages \ @@ -51,6 +51,7 @@ RUN curl -fsSL "https://keyserver.ubuntu.com/pks/lookup?op=get&search=0xf911ab18 && gpg --dearmor - < /tmp/key.gpg > /usr/share/keyrings/github_git-lfs.gpg \ && curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/jammy.gpg > /tmp/key.gpg \ && gpg --dearmor - < /tmp/key.gpg > /usr/share/keyrings/tailscale-archive-keyring.gpg \ + && curl -fsLf 'https://dl.cloudsmith.io/public/caddy/xcaddy/gpg.key'| gpg --dearmor -o /usr/share/keyrings/caddy-xcaddy-archive-keyring.gpg \ && rm /tmp/key.gpg RUN install-packages git git-lfs git-email \ diff --git a/docker/devenv/base/alpine.Dockerfile b/docker/devenv/base/alpine.Dockerfile new file mode 100644 index 0000000..d9799d2 --- /dev/null +++ b/docker/devenv/base/alpine.Dockerfile @@ -0,0 +1,8 @@ +# syntax=docker/dockerfile:experimental +ARG GITLAB_DEPENDENCY_PROXY_PATH=mau.dev/andreijiroh-dev +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/golang:alpine as golang +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/alpine:edge as base + +COPY --from=golang /usr/local/go/ /usr/local/go/ +ENV PATH=/usr/local/go/bin:/go/bin:$PATH GOPATH=/go +RUN mkdir /go && go install github.com/caddyserver/xcaddy/cmd/xcaddy@latest \ No newline at end of file diff --git a/docker/devenv/base/sources.list.d/caddy.sources b/docker/devenv/base/sources.list.d/caddy.sources new file mode 100644 index 0000000..095df2c --- /dev/null +++ b/docker/devenv/base/sources.list.d/caddy.sources @@ -0,0 +1,5 @@ +Types: deb +URIs: https://dl.cloudsmith.io/public/caddy/xcaddy/deb/debian +Suites: any-version +Components: main +Signed-By: /usr/share/keyrings/caddy-xcaddy-archive-keyring.gpg \ No newline at end of file diff --git a/docker/mkdocs-material/Dockerfile b/docker/mkdocs-material/Dockerfile index 518abbc..5c42dbc 100644 --- a/docker/mkdocs-material/Dockerfile +++ b/docker/mkdocs-material/Dockerfile @@ -1,5 +1,6 @@ # syntax=docker/dockerfile:1 -FROM python:3.12-alpine AS buildkit +ARG GITLAB_DEPENDENCY_PROXY_PATH=mau.dev/andreijiroh-dev +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/dependency_proxy/containers/python:3.12-alpine AS buildkit # Instead of using Alpine base image and then installing Python from pkgs.al.o, # we'll go with the official images instead. diff --git a/docker/pkgops-alpine/Dockerfile b/docker/pkgops-alpine/Dockerfile index b386d93..fd41cc6 100644 --- a/docker/pkgops-alpine/Dockerfile +++ b/docker/pkgops-alpine/Dockerfile @@ -1,6 +1,7 @@ # syntax=docker/dockerfile:1.3 ARG ALPINE_RELEASE=edge -FROM alpine:${ALPINE_RELEASE} +ARG GITLAB_DEPENDENCY_PROXY_PATH=mau.dev/andreijiroh-dev +FROM ${GITLAB_DEPENDENCY_PROXY_PATH}/containers/dependency_proxy/alpine:${ALPINE_RELEASE} # ref: https://gitlab.alpinelinux.org/alpine/infra/docker/build-base/-/merge_requests/1 ENV SUDO=doas -- 2.51.2