feat: AtroPIM image pipeline with secret-free build (AZ-NIX-ava.1)
- flake input atrocore-docker rev-pinned (e1e9bed) - pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage podman build (vendor pdf target + entrypoint wrapper) - entrypoint writes ATRO_DB_* to data/config.php at runtime, guarded by isInstalled (idempotent); no DB credentials in layers - devShell documents build/push commands and ENV variables
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
# Stage 2 of the AtroPIM image pipeline: takes the vendor-built base image
|
||||
# (atrocore/docker, target "pdf") and layers the secret-free entrypoint
|
||||
# wrapper on top. The base image reference is injected via BASE_IMAGE so the
|
||||
# vendor Dockerfile stays untouched (pinned flake input).
|
||||
ARG BASE_IMAGE
|
||||
FROM ${BASE_IMAGE}
|
||||
|
||||
COPY entrypoint.sh /entrypoint.sh
|
||||
COPY entrypoint-prepare-pim.php /entrypoint-prepare-pim.php
|
||||
|
||||
RUN chmod +x /entrypoint.sh
|
||||
|
||||
CMD ["/entrypoint.sh"]
|
||||
Reference in New Issue
Block a user