feat: AtroPIM image pipeline with secret-free build (AZ-NIX-ava.1)
- flake input atrocore-docker rev-pinned (e1e9bed) - pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage podman build (vendor pdf target + entrypoint wrapper) - entrypoint writes ATRO_DB_* to data/config.php at runtime, guarded by isInstalled (idempotent); no DB credentials in layers - devShell documents build/push commands and ENV variables
This commit is contained in:
@@ -0,0 +1,95 @@
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
atrocore-docker,
|
||||
registryHost ? "git.az-gruppe.com",
|
||||
registryNamespace ? "az-intec-gmbh",
|
||||
imageName ? "atrocore-web",
|
||||
skeletonVariant ? "pim-no-demo",
|
||||
buildVariant ? "pdf",
|
||||
productionDomain ? "pim.l.az-gruppe.com",
|
||||
productionStability ? "stable",
|
||||
}: let
|
||||
imageRef = "${registryHost}/${registryNamespace}/${imageName}";
|
||||
baseTag = "localhost/${imageName}-base:build";
|
||||
entrypointContext = ./entrypoint;
|
||||
|
||||
# The vendor Dockerfile uses the unqualified FROM "php:8.4-apache-bookworm";
|
||||
# resolve it against docker.io without touching the host's registries.conf.
|
||||
registriesConf = pkgs.writeText "atropim-registries.conf" ''
|
||||
unqualified-search-registries = ["docker.io"]
|
||||
'';
|
||||
|
||||
podman = lib.getExe pkgs.podman;
|
||||
|
||||
atropim-build = pkgs.writeShellApplication {
|
||||
name = "atropim-build";
|
||||
runtimeInputs = with pkgs; [coreutils];
|
||||
text = ''
|
||||
# Two-stage build: stage 1 builds the untouched vendor image from the
|
||||
# rev-pinned atrocore/docker flake input, stage 2 layers the secret-free
|
||||
# entrypoint wrapper on top. All DB build args stay empty on purpose:
|
||||
# no credentials are ever baked into any layer.
|
||||
export CONTAINERS_REGISTRIES_CONF="${registriesConf}"
|
||||
|
||||
echo "[atropim-build] stage 1: vendor image from ${atrocore-docker} (target ${buildVariant})"
|
||||
${podman} build \
|
||||
--target "${buildVariant}" \
|
||||
--build-arg "SKELETON_VARIANT=${skeletonVariant}" \
|
||||
--build-arg "PRODUCTION_DOMAIN=${productionDomain}" \
|
||||
--build-arg "PRODUCTION_STABILITY=${productionStability}" \
|
||||
--build-arg "PRODUCTION_DB=" \
|
||||
--build-arg "DB_USER=" \
|
||||
--build-arg "DB_PASSWORD=" \
|
||||
--tag "${baseTag}" \
|
||||
--file "${atrocore-docker}/.docker/php/Dockerfile" \
|
||||
"${atrocore-docker}/.docker"
|
||||
|
||||
echo "[atropim-build] stage 2: entrypoint wrapper -> ${imageRef}:latest"
|
||||
${podman} build \
|
||||
--build-arg "BASE_IMAGE=${baseTag}" \
|
||||
--label "org.opencontainers.image.title=${imageName}" \
|
||||
--label "org.opencontainers.image.description=AtroPIM (${skeletonVariant}) web image, secret-free build with runtime DB config" \
|
||||
--tag "${imageRef}:latest" \
|
||||
--file "${entrypointContext}/Dockerfile" \
|
||||
"${entrypointContext}"
|
||||
|
||||
echo "[atropim-build] done: ${imageRef}:latest"
|
||||
echo "[atropim-build] verify the image is secret-free:"
|
||||
echo " podman run --rm ${imageRef}:latest ls /var/www/${productionDomain}/data"
|
||||
'';
|
||||
};
|
||||
|
||||
atropim-push = pkgs.writeShellApplication {
|
||||
name = "atropim-push";
|
||||
runtimeInputs = with pkgs; [coreutils];
|
||||
text = ''
|
||||
VERSION="''${1:-$(date +%Y%m%d)}"
|
||||
|
||||
if ! ${podman} image exists "${imageRef}:latest"; then
|
||||
echo "error: ${imageRef}:latest not found - run atropim-build first" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! ${podman} login --get-login "${registryHost}" >/dev/null 2>&1; then
|
||||
echo "not logged in to ${registryHost} - run: podman login ${registryHost}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "[atropim-push] pushing ${imageRef}:{latest,''${VERSION}}"
|
||||
${podman} tag "${imageRef}:latest" "${imageRef}:''${VERSION}"
|
||||
${podman} push "${imageRef}:''${VERSION}"
|
||||
${podman} push "${imageRef}:latest"
|
||||
|
||||
echo "[atropim-push] done - package visible at https://${registryHost}/${registryNamespace}/-/packages"
|
||||
'';
|
||||
};
|
||||
in
|
||||
pkgs.symlinkJoin {
|
||||
name = "atropim-tools";
|
||||
paths = [atropim-build atropim-push];
|
||||
meta = {
|
||||
description = "Build/push tooling for the secret-free AtroPIM image (${imageRef})";
|
||||
platforms = lib.platforms.linux;
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user