Files
oauth2-proxy/Dockerfile
T

55 lines
2.1 KiB
Docker
Raw Normal View History

2022-04-14 15:10:59 +02:00
# This ARG has to be at the top, otherwise the docker daemon does not known what to do with FROM ${RUNTIME_IMAGE}
ARG RUNTIME_IMAGE=alpine:3.15
# All builds should be done using the platform native to the build node to allow
# cache sharing of the go mod download step.
# Go cross compilation is also faster than emulation the go compilation across
# multiple platforms.
2021-12-17 16:37:43 +01:00
FROM --platform=${BUILDPLATFORM} golang:1.17-buster AS builder
2019-01-22 02:50:50 +09:00
# Copy sources
2020-03-29 14:54:36 +01:00
WORKDIR $GOPATH/src/github.com/oauth2-proxy/oauth2-proxy
2018-12-20 11:06:26 +00:00
# Fetch dependencies
2019-07-15 21:38:55 +01:00
COPY go.mod go.sum ./
RUN go mod download
2018-12-20 11:06:26 +00:00
# Now pull in our code
COPY . .
# Arguments go here so that the previous steps can be cached if no external
# sources have changed.
ARG VERSION
ARG TARGETPLATFORM
ARG BUILDPLATFORM
2019-03-20 15:15:47 -07:00
# Build binary and make sure there is at least an empty key file.
# This is useful for GCP App Engine custom runtime builds, because
# you cannot use multiline variables in their app.yaml, so you have to
# build the key into the container and then tell it where it is
# by setting OAUTH2_PROXY_JWT_KEY_FILE=/etc/ssl/private/jwt_signing_key.pem
# in app.yaml instead.
# Set the cross compilation arguments based on the TARGETPLATFORM which is
# automatically set by the docker engine.
RUN case ${TARGETPLATFORM} in \
"linux/amd64") GOARCH=amd64 ;; \
2022-04-14 10:52:43 -04:00
# arm64 and arm64v8 are equivilant in go and do not require a goarm
# https://github.com/golang/go/wiki/GoArm
"linux/arm64" | "linux/arm64/v8") GOARCH=arm64 ;; \
2022-02-17 22:55:57 +01:00
"linux/ppc64le") GOARCH=ppc64le ;; \
"linux/arm/v6") GOARCH=arm GOARM=6 ;; \
esac && \
printf "Building OAuth2 Proxy for arch ${GOARCH}\n" && \
GOARCH=${GOARCH} VERSION=${VERSION} make build && touch jwt_signing_key.pem
2018-12-20 11:06:26 +00:00
2019-01-22 02:50:50 +09:00
# Copy binary to alpine
2022-04-14 15:10:59 +02:00
FROM ${RUNTIME_IMAGE}
2020-02-23 18:16:18 +00:00
COPY nsswitch.conf /etc/nsswitch.conf
2020-03-29 14:54:36 +01:00
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/oauth2-proxy /bin/oauth2-proxy
COPY --from=builder /go/src/github.com/oauth2-proxy/oauth2-proxy/jwt_signing_key.pem /etc/ssl/private/jwt_signing_key.pem
2018-12-20 11:06:26 +00:00
2022-04-14 15:10:59 +02:00
# UID/GID 65532 is also known as nonroot user in distroless image
USER 65532:65532
2020-03-29 14:54:36 +01:00
ENTRYPOINT ["/bin/oauth2-proxy"]