mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
5c183f5ecb
Currently all OPA image variants except "rootless" use uid/gid 0 (i.e. root). Per container security best practices it is better to run as non-root. So now OPA defaults to non-root uid/gid in images. If root user if needed, it can be explicitly set. The "rootless" image variant is no longer needed and will be not published in future releases. Also currently the debug variant is published for `linux/amd64` platform. For `linux/arm64` only static images are generated. The debug variant can be useful for debugging purposes and hence this change adds that to the static image which can then be used on amd64 and arm64 arch. Signed-off-by: Ashutosh Narkar <anarkar4387@gmail.com>
36 lines
1.2 KiB
Docker
36 lines
1.2 KiB
Docker
# Copyright 2019 The OPA Authors. All rights reserved.
|
|
# Use of this source code is governed by an Apache2
|
|
# license that can be found in the LICENSE file.
|
|
|
|
ARG BASE
|
|
|
|
FROM ${BASE}
|
|
|
|
LABEL org.opencontainers.image.authors="Torin Sandall <torinsandall@gmail.com>"
|
|
LABEL org.opencontainers.image.source="https://github.com/open-policy-agent/opa"
|
|
|
|
|
|
# Temporarily allow us to identify whether running from within an offical
|
|
# Docker image with a "rootless" tag, so that we may print a warning that this image tag
|
|
# will not be published after 0.50.0. Remove after 0.50.0 release.
|
|
ARG OPA_DOCKER_IMAGE_TAG
|
|
ENV OPA_DOCKER_IMAGE_TAG=${OPA_DOCKER_IMAGE_TAG}
|
|
|
|
# Any non-zero number will do, and unfortunately a named user will not, as k8s
|
|
# pod securityContext runAsNonRoot can't resolve the user ID:
|
|
# https://github.com/kubernetes/kubernetes/issues/40958.
|
|
ARG USER=1000:1000
|
|
USER ${USER}
|
|
|
|
# TARGETOS and TARGETARCH are automatic platform args injected by BuildKit
|
|
# https://docs.docker.com/engine/reference/builder/#automatic-platform-args-in-the-global-scope
|
|
ARG TARGETOS
|
|
ARG TARGETARCH
|
|
ARG BIN_DIR=.
|
|
ARG BIN_SUFFIX=
|
|
COPY ${BIN_DIR}/opa_${TARGETOS}_${TARGETARCH}${BIN_SUFFIX} /opa
|
|
ENV PATH=${PATH}:/
|
|
|
|
ENTRYPOINT ["/opa"]
|
|
CMD ["run"]
|