Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: improve docker image security #450

Merged
merged 1 commit into from
Jul 24, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 7 additions & 8 deletions connector/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,13 +1,12 @@
FROM gradle:7.6.0-jdk17 AS build
FROM gradle:7-jdk17-alpine AS build
Fixed Show fixed Hide fixed

ARG BUILD_ARGS

COPY --chown=gradle:gradle . /home/gradle/project/
WORKDIR /home/gradle/project/
RUN --mount=type=cache,target=/home/gradle/.gradle/caches gradle build --no-daemon $BUILD_ARGS

# -buster is required to have apt available
FROM openjdk:17-slim-buster
FROM eclipse-temurin:17-jre-alpine

ARG EDC_LAST_COMMIT_INFO_ARG="The docker container was built outside of github actions and you didn't provide the build arg EDC_LAST_COMMIT_INFO_ARG, so there's no last commit info."
ENV EDC_LAST_COMMIT_INFO=$EDC_LAST_COMMIT_INFO_ARG
Expand All @@ -18,11 +17,11 @@
# Optional JVM arguments, such as memory settings
ARG JVM_ARGS=""

# Install curl, then delete apt indexes to save image space
RUN apt update \
&& apt install -y curl \
&& rm -rf /var/cache/apt/archives /var/lib/apt/lists \
&& touch /emtpy-properties-file.properties
# Install curl for healthcheck
RUN apk add --no-cache curl

# Create empty properties file to avoid errors when loading properties
RUN touch /emtpy-properties-file.properties

WORKDIR /app

Expand Down
Loading