Something went wrong. Try again.
Monorepo for Tangled
Something went wrong. Try again.
3.0 kB · 102 lines
at master
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103# Development only. Not for production use.
FROM golang:1.25-alpine AS builder
RUN apk add --no-cache git build-base sqlite-dev
ENV CGO_ENABLED=1ENV GOCACHE=/go/cacheENV GOMODCACHE=/go/mod
WORKDIR /src
COPY go.mod go.sum ./RUN --mount=type=cache,target=/go/cache \ --mount=type=cache,target=/go/mod \ go mod download
COPY . .RUN --mount=type=cache,target=/go/cache \ --mount=type=cache,target=/go/mod \ go build -tags libsqlite3 -o /out/knot ./cmd/knot
FROM alpine:3.20
RUN apk add --no-cache git openssh-server tini sqlite-libs su-exec ca-certificates shadow openssl bash
RUN groupadd -g 1000 -f git && \ useradd -u 1000 -g 1000 -d /home/git -s /bin/sh -m git && \ echo "git:$(openssl rand -hex 16)" | chpasswd
COPY --from=builder /out/knot /usr/local/bin/knotRUN chmod 0755 /usr/local/bin/knot
COPY <<'EOF' /usr/local/bin/knot-keys-wrapper#!/bin/shexec /usr/local/bin/knot keys -output authorized-keys \ -internal-api "http://${KNOT_SERVER_INTERNAL_LISTEN_ADDR:-127.0.0.1:5444}" \ -git-dir "${KNOT_REPO_SCAN_PATH:-/home/git/repositories}" \ -log-path "/tmp/knotguard.log"EOFRUN chmod +x /usr/local/bin/knot-keys-wrapper
# sshd configCOPY <<'EOF' /etc/ssh/sshd_config.d/knot.confPermitRootLogin noPasswordAuthentication noChallengeResponseAuthentication no
Match User git AuthorizedKeysCommand /usr/local/bin/knot-keys-wrapper AuthorizedKeysCommandUser nobodyEOF
RUN echo 'Include /etc/ssh/sshd_config.d/*.conf' >> /etc/ssh/sshd_config
COPY <<'EOF' /etc/ssh/sshd_config.d/host-keys.confHostKey /etc/ssh/keys/ssh_host_rsa_keyHostKey /etc/ssh/keys/ssh_host_ecdsa_keyHostKey /etc/ssh/keys/ssh_host_ed25519_keyEOF
RUN mkdir -p /home/git/.config/gitCOPY <<'EOF' /home/git/.config/git/config[user] name = Tangled email = noreply@tangled.org[receive] advertisePushOptions = true[uploadpack] allowFilter = true allowReachableSHA1InWant = trueEOFRUN mkdir -p /home/git/repositories && chown -R git:git /home/git
COPY <<'EOF' /usr/local/bin/knot-entrypoint.sh#!/bin/shset -eu[ -z "${KNOT_SERVER_OWNER:-}" ] && [ -r /shared/owner-did ] && \ export KNOT_SERVER_OWNER="$(cat /shared/owner-did)": "${KNOT_SERVER_OWNER:?set via env or /shared/owner-did}"
mkdir -p /etc/ssh/keys[ -f /etc/ssh/keys/ssh_host_rsa_key ] || ssh-keygen -t rsa -f /etc/ssh/keys/ssh_host_rsa_key -q -N ""[ -f /etc/ssh/keys/ssh_host_ecdsa_key ] || ssh-keygen -t ecdsa -f /etc/ssh/keys/ssh_host_ecdsa_key -q -N ""[ -f /etc/ssh/keys/ssh_host_ed25519_key ] || ssh-keygen -t ed25519 -f /etc/ssh/keys/ssh_host_ed25519_key -q -N ""
if [ -f /usr/local/share/ca-certificates/caddy.crt ]; then update-ca-certificatesfi
/usr/sbin/sshd -D -e &exec su-exec git /usr/local/bin/knot serverEOFRUN chmod +x /usr/local/bin/knot-entrypoint.sh
VOLUME /home/gitEXPOSE 22 5555
WORKDIR /home/git
ENTRYPOINT ["/sbin/tini", "--"]CMD ["/usr/local/bin/knot-entrypoint.sh"]