-
-
Notifications
You must be signed in to change notification settings - Fork 34
Expand file tree
/
Copy pathDockerfile.foreman-agent.goreleaser
More file actions
25 lines (24 loc) · 1.06 KB
/
Copy pathDockerfile.foreman-agent.goreleaser
File metadata and controls
25 lines (24 loc) · 1.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# Dockerfile for GoReleaser builds of the foreman-agent. dockers_v2 stages
# the pre-built binary per platform under $TARGETPLATFORM in the build
# context.
#
# The foreman-agent shells out to `git` for clone / commit / push from
# its repo helpers, so the runtime image swaps distroless static for
# alpine + git. nonroot uid 65532 stays.
FROM alpine:3.24
ARG TARGETPLATFORM
# apk upgrade before apk add: the alpine:3.24 base image is rebuilt less
# often than its package repo is published, so packages baked into the
# base can sit behind a published fix even on a fresh build. Trivy scans
# this image before push and fails the release on HIGH findings, so the
# upgrade is what keeps a base-image lag from blocking a release
# (CVE-2026-14456: libcrypto3/libssl3 3.5.7-r0 in the base, 3.5.8-r0 in
# the v3.24 repo).
RUN apk upgrade --no-cache \
&& apk add --no-cache git ca-certificates \
&& addgroup -S -g 65532 nonroot \
&& adduser -S -u 65532 -G nonroot nonroot
WORKDIR /
COPY $TARGETPLATFORM/foreman-agent /foreman-agent
USER 65532:65532
ENTRYPOINT ["/foreman-agent"]