mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
fb5ff78c24
This includes some refactors to the build steps. High level items: * Add variables for DOCKER_IMAGE, S3_RELEASE_BUCKET to allow for forks of OPA to re-use the GitHub actions with their own s3 buckets and docker orgs/image names. * Unify the release build steps to use `make release` and the binaries being located under `_release/$(VERSION)`. All CI targets now rely on binaries being in that `RELEASE_DIR`, including image building steps The `make build` target is unaffected. * Add a wrapper to allow the CI to run the various golang target stages separately, but sharing the same docker configuration. * Conditionally specify `-it` for docker run commands based on whether A tty is available. * Added scripts to automate drafting a release with binary assets vi the `hub` CLI. * The release process triggered on a tag being pushed will now use the same binaries from `make release` for the docker images as well as the ones attached to the release (which are available under https://openpolicyagent.org/downloads/). The actions themselves are split into 3 workflows: pull-request.yaml: Triggers on pull requests. This will run all the normal tests/checks as before on Travis, however they are now split into separate jobs. In addition to what was done on Travis we will now have Codecov results included. post-merge.yaml: Triggers after a change is pushed to master. This will run tests and build+publish the `edge` and `dev` artifacts to dockerhub and s3. post-tag.yaml: Triggers after a tag has been pushed. Similar to post-merge.yaml it will run tests and build+publish release artifacts (for the tagged version). It will also create a draft release on GitHub with the same artifacts and notes from the CHANGELOG.md. If a release already exists it will be updated to include the assets, however the release notes will _not_ be added. The RELEASE.md steps have been updated and include notes on the new steps. Signed-off-by: Patrick East <east.patrick@gmail.com>
29 lines
812 B
Docker
29 lines
812 B
Docker
# Copyright 2019 The OPA Authors. All rights reserved.
|
|
# Use of this source code is governed by an Apache2
|
|
# license that can be found in the LICENSE file.
|
|
|
|
ARG BASE
|
|
|
|
FROM gcr.io/distroless/base as certs
|
|
|
|
FROM ${BASE}
|
|
|
|
# Any non-zero number will do, and unfortunately a named user will not, as k8s
|
|
# pod securityContext runAsNonRoot can't resolve the user ID:
|
|
# https://github.com/kubernetes/kubernetes/issues/40958. Make root (uid 0) when
|
|
# not specified.
|
|
ARG USER=0
|
|
|
|
MAINTAINER Torin Sandall <torinsandall@gmail.com>
|
|
COPY --from=certs /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
|
|
|
|
# Hack.. https://github.com/moby/moby/issues/37965
|
|
# _Something_ needs to be between the two COPY steps.
|
|
USER ${USER}
|
|
|
|
ARG BIN_DIR=.
|
|
COPY ${BIN_DIR}/opa_linux_amd64 /opa
|
|
|
|
ENTRYPOINT ["/opa"]
|
|
CMD ["run"]
|