{ lib, pkgs, atrocore-docker, registryHost ? "git.az-gruppe.com", registryNamespace ? "az-intec-gmbh", imageName ? "atrocore-web", skeletonVariant ? "pim-no-demo", buildVariant ? "pdf", productionDomain ? "pim.l.az-gruppe.com", productionStability ? "stable", }: let imageRef = "${registryHost}/${registryNamespace}/${imageName}"; baseTag = "localhost/${imageName}-base:build"; entrypointContext = ./entrypoint; # The vendor Dockerfile uses the unqualified FROM "php:8.4-apache-bookworm"; # resolve it against docker.io without touching the host's registries.conf. registriesConf = pkgs.writeText "atropim-registries.conf" '' unqualified-search-registries = ["docker.io"] ''; podman = lib.getExe pkgs.podman; atropim-build = pkgs.writeShellApplication { name = "atropim-build"; runtimeInputs = with pkgs; [coreutils]; text = '' # Two-stage build: stage 1 builds the untouched vendor image from the # rev-pinned atrocore/docker flake input, stage 2 layers the secret-free # entrypoint wrapper on top. All DB build args stay empty on purpose: # no credentials are ever baked into any layer. export CONTAINERS_REGISTRIES_CONF="${registriesConf}" echo "[atropim-build] stage 1: vendor image from ${atrocore-docker} (target ${buildVariant})" ${podman} build \ --target "${buildVariant}" \ --build-arg "SKELETON_VARIANT=${skeletonVariant}" \ --build-arg "PRODUCTION_DOMAIN=${productionDomain}" \ --build-arg "PRODUCTION_STABILITY=${productionStability}" \ --build-arg "PRODUCTION_DB=" \ --build-arg "DB_USER=" \ --build-arg "DB_PASSWORD=" \ --tag "${baseTag}" \ --file "${atrocore-docker}/.docker/php/Dockerfile" \ "${atrocore-docker}/.docker" echo "[atropim-build] stage 2: entrypoint wrapper -> ${imageRef}:latest" ${podman} build \ --build-arg "BASE_IMAGE=${baseTag}" \ --label "org.opencontainers.image.title=${imageName}" \ --label "org.opencontainers.image.description=AtroPIM (${skeletonVariant}) web image, secret-free build with runtime DB config" \ --tag "${imageRef}:latest" \ --file "${entrypointContext}/Dockerfile" \ "${entrypointContext}" echo "[atropim-build] done: ${imageRef}:latest" echo "[atropim-build] verify the image is secret-free:" echo " podman run --rm ${imageRef}:latest ls /var/www/${productionDomain}/data" ''; }; atropim-push = pkgs.writeShellApplication { name = "atropim-push"; runtimeInputs = with pkgs; [coreutils]; text = '' VERSION="''${1:-$(date +%Y%m%d)}" if ! ${podman} image exists "${imageRef}:latest"; then echo "error: ${imageRef}:latest not found - run atropim-build first" >&2 exit 1 fi if ! ${podman} login --get-login "${registryHost}" >/dev/null 2>&1; then echo "not logged in to ${registryHost} - run: podman login ${registryHost}" >&2 exit 1 fi echo "[atropim-push] pushing ${imageRef}:{latest,''${VERSION}}" ${podman} tag "${imageRef}:latest" "${imageRef}:''${VERSION}" ${podman} push "${imageRef}:''${VERSION}" ${podman} push "${imageRef}:latest" echo "[atropim-push] done - package visible at https://${registryHost}/${registryNamespace}/-/packages" ''; }; in pkgs.symlinkJoin { name = "atropim-tools"; paths = [atropim-build atropim-push]; meta = { description = "Build/push tooling for the secret-free AtroPIM image (${imageRef})"; platforms = lib.platforms.linux; }; }