From ba1da5e0369526810a18fbe5f72fb006688d6d25 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 7 Mar 2017 18:42:50 +0100 Subject: [PATCH 01/30] Initial commit --- Dockerfile | 83 ++++++++++++++++ LICENSE | 202 +++++++++++++++++++++++++++++++++++++++ bin/base-usage | 24 +++++ bin/cgroup-limits | 92 ++++++++++++++++++ bin/container-entrypoint | 2 + bin/fix-permissions | 6 ++ contrib/scl_enable | 2 + test/run | 26 +++++ 8 files changed, 437 insertions(+) create mode 100644 Dockerfile create mode 100644 LICENSE create mode 100755 bin/base-usage create mode 100755 bin/cgroup-limits create mode 100755 bin/container-entrypoint create mode 100755 bin/fix-permissions create mode 100644 contrib/scl_enable create mode 100755 test/run diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..74a799d --- /dev/null +++ b/Dockerfile @@ -0,0 +1,83 @@ +# This image is the base image for all OpenShift v3 language Docker images. +FROM fedora:25 + +LABEL \ + io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ + io.s2i.scripts-url=image:///usr/libexec/s2i + +ENV NAME=s2i-base \ + VERSION=1 \ + RELEASE=1 \ + ARCH=x86_64 + +LABEL BZComponent="$NAME" \ + Name="$FGC/$NAME" \ + Version="$VERSION" \ + Release="$RELEASE.$DISTTAG" \ + Architecture="$ARCH" + +ENV \ + # DEPRECATED: Use above LABEL instead, because this will be removed in future versions. + STI_SCRIPTS_URL=image:///usr/libexec/s2i \ + # Path to be used in other layers to place s2i scripts into + STI_SCRIPTS_PATH=/usr/libexec/s2i \ + # The $HOME is not set by default, but some applications needs this variable + # TODO: There is a bug in rhel7.1 image where the PATH variable is not exported + # properly as Docker image metadata, which causes the $PATH variable do not + # expand properly. + HOME=/opt/app-root/src \ + PATH=/opt/app-root/src/bin:/opt/app-root/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin + +# This is the list of basic dependencies that all language Docker image can +# consume. +# Also setup the 'openshift' user that is used for the build execution and for the +# application runtime execution. +# TODO: Use better UID and GID values +RUN dnf repolist > /dev/null && \ + INSTALL_PKGS="autoconf \ + automake \ + bsdtar \ + bzip2 \ + findutils \ + gcc-c++ \ + gd-devel \ + gdb \ + gettext \ + git \ + libcurl-devel \ + libxml2-devel \ + libxslt-devel \ + lsof \ + make \ + mariadb-devel \ + mariadb-libs \ + openssl-devel \ + patch \ + postgresql-devel \ + procps-ng \ + redhat-rpm-config \ + scl-utils \ + sqlite-devel \ + tar \ + unzip \ + wget \ + which \ + yum-utils \ + zlib-devel" && \ + mkdir -p ${HOME}/.pki/nssdb && \ + chown -R 1001:0 ${HOME}/.pki && \ + dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ + rpm -V $INSTALL_PKGS && \ + dnf clean all -y && \ + useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \ + -c "Default Application User" default && \ + chown -R 1001:0 /opt/app-root + +# Copy executable utilities. +COPY bin/ /usr/bin/ + +# Directory with the sources is set as the working directory so all STI scripts +# can execute relative to this path. +WORKDIR ${HOME} + +CMD ["base-usage"] diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..7a4a3ea --- /dev/null +++ b/LICENSE @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/bin/base-usage b/bin/base-usage new file mode 100755 index 0000000..154ccc4 --- /dev/null +++ b/bin/base-usage @@ -0,0 +1,24 @@ +#!/bin/sh -e + +cat <= 92233720368547: + env_vars["NO_MEMORY_LIMIT"] = "true" + + for key, value in env_vars.items(): + print("{0}={1}".format(key, value)) diff --git a/bin/container-entrypoint b/bin/container-entrypoint new file mode 100755 index 0000000..9d8ad4d --- /dev/null +++ b/bin/container-entrypoint @@ -0,0 +1,2 @@ +#!/bin/bash +exec "$@" diff --git a/bin/fix-permissions b/bin/fix-permissions new file mode 100755 index 0000000..0ed1f10 --- /dev/null +++ b/bin/fix-permissions @@ -0,0 +1,6 @@ +#!/bin/sh +# Fix permissions on the given directory to allow group read/write of +# regular files and execute of directories. +find $1 -exec chgrp 0 {} \; +find $1 -exec chmod g+rw {} \; +find $1 -type d -exec chmod g+x {} + diff --git a/contrib/scl_enable b/contrib/scl_enable new file mode 100644 index 0000000..8fca598 --- /dev/null +++ b/contrib/scl_enable @@ -0,0 +1,2 @@ +# This file contains automatic SCL enablement. +unset BASH_ENV PROMPT_COMMAND ENV diff --git a/test/run b/test/run new file mode 100755 index 0000000..3a9fe2d --- /dev/null +++ b/test/run @@ -0,0 +1,26 @@ +#!/bin/bash +# +# The 'run' performs a simple test that verifies that STI image. +# The main focus is that the image prints out the base-usage properly. +# +# IMAGE_NAME specifies a name of the candidate image used for testing. +# The image has to be available before this script is executed. +# +IMAGE_NAME=${IMAGE_NAME-openshift/base-centos7-candidate} + +test_docker_run_usage() { + echo "Testing 'docker run' usage..." + docker run --rm ${IMAGE_NAME} &>/dev/null +} + +check_result() { + local result="$1" + if [[ "$result" != "0" ]]; then + echo "STI image '${IMAGE_NAME}' test FAILED (exit code: ${result})" + exit $result + fi +} + +# Verify the 'usage' script is working properly when running the base image with 'docker run ...' +test_docker_run_usage +check_result $? From af207cd2070bc180b13198c82433135c9ebcd18b Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 7 Mar 2017 22:45:54 +0100 Subject: [PATCH 02/30] Bump release --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 74a799d..9ee38bd 100644 --- a/Dockerfile +++ b/Dockerfile @@ -7,7 +7,7 @@ LABEL \ ENV NAME=s2i-base \ VERSION=1 \ - RELEASE=1 \ + RELEASE=2 \ ARCH=x86_64 LABEL BZComponent="$NAME" \ From 5d7cf8eb96ae80291f5b615d7cf8880bd1a89d82 Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Wed, 15 Mar 2017 16:50:11 -0500 Subject: [PATCH 03/30] Bump RELEASE for automatic rebuild --- Dockerfile | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 9ee38bd..3e53392 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,10 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base \ - VERSION=1 \ - RELEASE=2 \ - ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=3 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From e4f3c0c2b7daf0239176e6d104fd1b330f6cc469 Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Wed, 15 Mar 2017 17:24:41 -0500 Subject: [PATCH 04/30] Bump RELEASE for automatic rebuild --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 3e53392..882b7d7 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base VERSION=1 RELEASE=3 ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=4 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From 4211e02b3cdc5f1a3b8e4b05e89449d5b9caf55b Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Wed, 29 Mar 2017 15:17:45 -0500 Subject: [PATCH 05/30] Bump RELEASE for automatic rebuild --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 882b7d7..1d8b5b8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base VERSION=1 RELEASE=4 ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=5 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From 71328f0c29fe2b1455261b1a90c11da95b4f071e Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Wed, 29 Mar 2017 22:39:05 -0500 Subject: [PATCH 06/30] Bump RELEASE for automatic rebuild --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 1d8b5b8..6ddb382 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base VERSION=1 RELEASE=5 ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=6 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From 90703923f4c9c9d395d13f5c15105ab426e99157 Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Wed, 29 Mar 2017 23:06:03 -0500 Subject: [PATCH 07/30] Bump RELEASE for automatic rebuild --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 6ddb382..fe11cc8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base VERSION=1 RELEASE=6 ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=7 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From 73e07ee8d834303b1f469f554fb71071de15e20a Mon Sep 17 00:00:00 2001 From: Adam Miller Date: Thu, 20 Apr 2017 21:33:55 -0500 Subject: [PATCH 08/30] Bump RELEASE for automatic rebuild --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index fe11cc8..68b62bf 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,7 @@ LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ io.s2i.scripts-url=image:///usr/libexec/s2i -ENV NAME=s2i-base VERSION=1 RELEASE=7 ARCH=x86_64 +ENV NAME=s2i-base VERSION=1 RELEASE=8 ARCH=x86_64 LABEL BZComponent="$NAME" \ Name="$FGC/$NAME" \ From d19376160ec92837a2e9def79346e0aa1588e3db Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 16 May 2017 12:15:41 +0200 Subject: [PATCH 09/30] Change version in FROM to 26 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 68b62bf..7420ab8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language Docker images. -FROM fedora:25 +FROM fedora:26 LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ From 923d814d45a53f76b895979e783fde3ff7284aa2 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 16 May 2017 12:19:00 +0200 Subject: [PATCH 10/30] Change version in FROM to rawhide --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 7420ab8..46fc285 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language Docker images. -FROM fedora:26 +FROM fedora:rawhide LABEL \ io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ From 7e9f733d390159f8bcca907aed19a9cf24e2a484 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Wed, 22 Nov 2017 15:36:15 +0100 Subject: [PATCH 11/30] Do sync from upstream - https://github.com/sclorg/s2i-base-container/tree/master/base --- Dockerfile | 74 ++++++------------- README.md | 104 ++++++++++++++++++++++++++ bin/base-usage | 24 ------ bin/cgroup-limits | 92 ----------------------- bin/container-entrypoint | 2 - bin/fix-permissions | 6 -- contrib/scl_enable | 2 - root/help.1 | 153 +++++++++++++++++++++++++++++++++++++++ test/run | 2 +- 9 files changed, 282 insertions(+), 177 deletions(-) create mode 100644 README.md delete mode 100755 bin/base-usage delete mode 100755 bin/cgroup-limits delete mode 100755 bin/container-entrypoint delete mode 100755 bin/fix-permissions delete mode 100644 contrib/scl_enable create mode 100644 root/help.1 diff --git a/Dockerfile b/Dockerfile index 46fc285..7f00f3d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,45 +1,36 @@ # This image is the base image for all OpenShift v3 language Docker images. -FROM fedora:rawhide +FROM registry.fedoraproject.org/rawhide/s2i-core -LABEL \ - io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \ - io.s2i.scripts-url=image:///usr/libexec/s2i +ENV SUMMARY="Base image with essential libraries and tools used as a base for \ +builder images like perl, python, ruby, etc." \ + DESCRIPTION="The s2i-base image, being built upon s2i-core, provides any \ +images layered on top of it with all the tools needed to use source-to-image \ +functionality. Additionally, s2i-base also contains various libraries needed for \ +it to serve as a base for other builder images, like s2i-python or s2i-ruby." \ + NAME=s2i-base \ + VERSION=1 \ + RELEASE=1 \ + ARCH=x86_64 -ENV NAME=s2i-base VERSION=1 RELEASE=8 ARCH=x86_64 - -LABEL BZComponent="$NAME" \ - Name="$FGC/$NAME" \ - Version="$VERSION" \ - Release="$RELEASE.$DISTTAG" \ - Architecture="$ARCH" - -ENV \ - # DEPRECATED: Use above LABEL instead, because this will be removed in future versions. - STI_SCRIPTS_URL=image:///usr/libexec/s2i \ - # Path to be used in other layers to place s2i scripts into - STI_SCRIPTS_PATH=/usr/libexec/s2i \ - # The $HOME is not set by default, but some applications needs this variable - # TODO: There is a bug in rhel7.1 image where the PATH variable is not exported - # properly as Docker image metadata, which causes the $PATH variable do not - # expand properly. - HOME=/opt/app-root/src \ - PATH=/opt/app-root/src/bin:/opt/app-root/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin +LABEL summary="$SUMMARY" \ + description="$DESCRIPTION" \ + io.k8s.description="$DESCRIPTION" \ + io.k8s.display-name="s2i base" \ + com.redhat.component="$NAME" \ + name="$FGC/$NAME" \ + version="$VERSION" \ + release="$RELEASE.$DISTTAG" \ + architecture="$ARCH" \ + maintainer="SoftwareCollections.org " # This is the list of basic dependencies that all language Docker image can # consume. -# Also setup the 'openshift' user that is used for the build execution and for the -# application runtime execution. -# TODO: Use better UID and GID values -RUN dnf repolist > /dev/null && \ - INSTALL_PKGS="autoconf \ +RUN INSTALL_PKGS="autoconf \ automake \ - bsdtar \ bzip2 \ - findutils \ gcc-c++ \ gd-devel \ gdb \ - gettext \ git \ libcurl-devel \ libxml2-devel \ @@ -48,33 +39,16 @@ RUN dnf repolist > /dev/null && \ make \ mariadb-devel \ mariadb-libs \ + npm \ openssl-devel \ patch \ postgresql-devel \ procps-ng \ - redhat-rpm-config \ - scl-utils \ sqlite-devel \ - tar \ unzip \ wget \ which \ - yum-utils \ zlib-devel" && \ - mkdir -p ${HOME}/.pki/nssdb && \ - chown -R 1001:0 ${HOME}/.pki && \ dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ rpm -V $INSTALL_PKGS && \ - dnf clean all -y && \ - useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \ - -c "Default Application User" default && \ - chown -R 1001:0 /opt/app-root - -# Copy executable utilities. -COPY bin/ /usr/bin/ - -# Directory with the sources is set as the working directory so all STI scripts -# can execute relative to this path. -WORKDIR ${HOME} - -CMD ["base-usage"] + dnf clean all -y diff --git a/README.md b/README.md new file mode 100644 index 0000000..13e4efe --- /dev/null +++ b/README.md @@ -0,0 +1,104 @@ +OpenShift base images +======================================== + +This repository contains Dockerfiles for images which serve as base images with all the +essential libraries and tools needed for OpenShift language images, for example: + +* [s2i-ruby](https://github.com/sclorg/s2i-ruby-container) +* [s2i-nodejs](https://github.com/sclorg/s2i-nodejs-container) +* [s2i-python](https://github.com/sclorg/s2i-python-container) +* [s2i-perl](https://github.com/sclorg/s2i-perl-container) +* [s2i-php](https://github.com/sclorg/s2i-php-container) + +This container image also installs several development libraries, that are +often required in the builder images above. It also includes NPM package manager. +Sharing those development packages in a common layer saves disk space and +improves pulling speed. + +NPM, a package manager for Node.js, offers a pleasant way to install JavaScript +libraries, that are often needed as static files for various web applications. +In order to offer good experience for web developers, the NPM package manager +is also installed in the image. + +For containers where the development libraries and NPM package manager are not +necessary, users are advised to use the s2i-core variant of this container image. + + +Description +----------- + +OpenShift S2I images use [Software Collections](https://www.softwarecollections.org/en/) +packages to provide the latest versions of various software. +The SCL packages are released more frequently than the RHEL or CentOS systems, +which are unlikely to change for several years. +We rely on RHEL and CentOS for base images, on the other hand, +because those are stable, supported, and secure platforms. + +Normally, SCL requires manual operation to enable the collection you want to use. +This is burdensome and can be prone to error. +The OpenShift S2I approach is to set Bash environment variables that +serve to automatically enable the desired collection: + +* `BASH_ENV`: enables the collection for all non-interactive Bash sessions +* `ENV`: enables the collection for all invocations of `/bin/sh` +* `PROMPT_COMMAND`: enables the collection in interactive shell + +Two examples: +* If you specify `BASH_ENV`, then all your `#!/bin/bash` scripts +do not need to call `scl enable`. +* If you specify `PROMPT_COMMAND`, then on execution of the +`docker exec ... /bin/bash` command, the collection will be automatically enabled. + +*Note*: +Executables in Software Collections packages (e.g., `ruby`) +are not directly in a directory named in the `PATH` environment variable. +This means that you cannot do: + + $ docker exec ... ruby + +but must instead do: + + $ docker exec ... /bin/bash -c ruby + +The `/bin/bash -c`, along with the setting the appropriate environment variable, +ensures the correct `ruby` executable is found and invoked. + + +Usage +------------------------ +Choose either the CentOS7 or RHEL7 base image: +* **RHEL7 base image** + +To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. + +``` +$ git clone --recursive https://github.com/sclorg/s2i-base-container.git +$ cd s2i-base-container +$ make build VERSIONS=base TARGET=rhel7 +``` + +* **CentOS7 base image** + +This image is available on DockerHub. To download it run: + +```console +docker pull sclorg/s2i-base-centos7 +``` + +To build a Base image from scratch run: + +``` +$ git clone --recursive https://github.com/sclorg/s2i-base-container.git +$ cd s2i-base-container +$ make build VERSIONS=base +``` + +**Notice: By omitting the `VERSION` parameter, the build/test action will be performed +on all provided versions of s2i image.** + + +See also +-------- +Dockerfile and other sources are available on https://github.com/sclorg/s2i-base-container. +In that repository you also can find another variants of S2I base Dockerfiles. +Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/bin/base-usage b/bin/base-usage deleted file mode 100755 index 154ccc4..0000000 --- a/bin/base-usage +++ /dev/null @@ -1,24 +0,0 @@ -#!/bin/sh -e - -cat <= 92233720368547: - env_vars["NO_MEMORY_LIMIT"] = "true" - - for key, value in env_vars.items(): - print("{0}={1}".format(key, value)) diff --git a/bin/container-entrypoint b/bin/container-entrypoint deleted file mode 100755 index 9d8ad4d..0000000 --- a/bin/container-entrypoint +++ /dev/null @@ -1,2 +0,0 @@ -#!/bin/bash -exec "$@" diff --git a/bin/fix-permissions b/bin/fix-permissions deleted file mode 100755 index 0ed1f10..0000000 --- a/bin/fix-permissions +++ /dev/null @@ -1,6 +0,0 @@ -#!/bin/sh -# Fix permissions on the given directory to allow group read/write of -# regular files and execute of directories. -find $1 -exec chgrp 0 {} \; -find $1 -exec chmod g+rw {} \; -find $1 -type d -exec chmod g+x {} + diff --git a/contrib/scl_enable b/contrib/scl_enable deleted file mode 100644 index 8fca598..0000000 --- a/contrib/scl_enable +++ /dev/null @@ -1,2 +0,0 @@ -# This file contains automatic SCL enablement. -unset BASH_ENV PROMPT_COMMAND ENV diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..887acd7 --- /dev/null +++ b/root/help.1 @@ -0,0 +1,153 @@ +.TH OpenShift base images +.PP +This repository contains Dockerfiles for images which serve as base images with all the +essential libraries and tools needed for OpenShift language images, for example: +.IP \(bu 2 +s2i\-ruby +\[la]https://github.com/sclorg/s2i-ruby-container\[ra] +.IP \(bu 2 +s2i\-nodejs +\[la]https://github.com/sclorg/s2i-nodejs-container\[ra] +.IP \(bu 2 +s2i\-python +\[la]https://github.com/sclorg/s2i-python-container\[ra] +.IP \(bu 2 +s2i\-perl +\[la]https://github.com/sclorg/s2i-perl-container\[ra] +.IP \(bu 2 +s2i\-php +\[la]https://github.com/sclorg/s2i-php-container\[ra] + +.PP +This container image also installs several development libraries, that are +often required in the builder images above. It also includes NPM package manager. +Sharing those development packages in a common layer saves disk space and +improves pulling speed. + +.PP +NPM, a package manager for Node.js, offers a pleasant way to install JavaScript +libraries, that are often needed as static files for various web applications. +In order to offer good experience for web developers, the NPM package manager +is also installed in the image. + +.PP +For containers where the development libraries and NPM package manager are not +necessary, users are advised to use the s2i\-core variant of this container image. + +.SH Description +.PP +OpenShift S2I images use Software Collections +\[la]https://www.softwarecollections.org/en/\[ra] +packages to provide the latest versions of various software. +The SCL packages are released more frequently than the RHEL or CentOS systems, +which are unlikely to change for several years. +We rely on RHEL and CentOS for base images, on the other hand, +because those are stable, supported, and secure platforms. + +.PP +Normally, SCL requires manual operation to enable the collection you want to use. +This is burdensome and can be prone to error. +The OpenShift S2I approach is to set Bash environment variables that +serve to automatically enable the desired collection: +.IP \(bu 2 +\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions +.IP \(bu 2 +\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR +.IP \(bu 2 +\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell + +.PP +Two examples: +* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts +do not need to call \fB\fCscl enable\fR\&. +* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the +\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. + +.PP +\fINote\fP: +Executables in Software Collections packages (e.g., \fB\fCruby\fR) +are not directly in a directory named in the \fB\fCPATH\fR environment variable. +This means that you cannot do: + +.PP +.RS + +.nf +$ docker exec ... ruby + +.fi +.RE + +.PP +but must instead do: + +.PP +.RS + +.nf +$ docker exec ... /bin/bash \-c ruby + +.fi +.RE + +.PP +The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, +ensures the correct \fB\fCruby\fR executable is found and invoked. + +.SH Usage +.PP +Choose either the CentOS7 or RHEL7 base image: +* \fBRHEL7 base image\fP + +.PP +To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=base TARGET=rhel7 + +.fi +.RE +.IP \(bu 2 +\fBCentOS7 base image\fP + +.PP +This image is available on DockerHub. To download it run: + +.PP +.RS + +.nf +docker pull sclorg/s2i\-base\-centos7 + +.fi +.RE + +.PP +To build a Base image from scratch run: + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=base + +.fi +.RE + +.PP +\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed +on all provided versions of s2i image.\fP + +.SH See also +.PP +Dockerfile and other sources are available on +\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. +In that repository you also can find another variants of S2I base Dockerfiles. +Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/test/run b/test/run index 3a9fe2d..a745d6d 100755 --- a/test/run +++ b/test/run @@ -6,7 +6,7 @@ # IMAGE_NAME specifies a name of the candidate image used for testing. # The image has to be available before this script is executed. # -IMAGE_NAME=${IMAGE_NAME-openshift/base-centos7-candidate} +IMAGE_NAME=${IMAGE_NAME-centos/s2i-base-centos7-candidate} test_docker_run_usage() { echo "Testing 'docker run' usage..." From 38dff7522e78457ce6e242ca3b1c40e3e7722fa0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Tue, 5 Dec 2017 11:13:20 +0100 Subject: [PATCH 12/30] Add back release number + remove unused help file (needs to be fixed upstream) --- Dockerfile | 2 +- root/help.1 | 153 ---------------------------------------------------- 2 files changed, 1 insertion(+), 154 deletions(-) delete mode 100644 root/help.1 diff --git a/Dockerfile b/Dockerfile index 7f00f3d..8d94bf8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,7 +9,7 @@ functionality. Additionally, s2i-base also contains various libraries needed for it to serve as a base for other builder images, like s2i-python or s2i-ruby." \ NAME=s2i-base \ VERSION=1 \ - RELEASE=1 \ + RELEASE=9 \ ARCH=x86_64 LABEL summary="$SUMMARY" \ diff --git a/root/help.1 b/root/help.1 deleted file mode 100644 index 887acd7..0000000 --- a/root/help.1 +++ /dev/null @@ -1,153 +0,0 @@ -.TH OpenShift base images -.PP -This repository contains Dockerfiles for images which serve as base images with all the -essential libraries and tools needed for OpenShift language images, for example: -.IP \(bu 2 -s2i\-ruby -\[la]https://github.com/sclorg/s2i-ruby-container\[ra] -.IP \(bu 2 -s2i\-nodejs -\[la]https://github.com/sclorg/s2i-nodejs-container\[ra] -.IP \(bu 2 -s2i\-python -\[la]https://github.com/sclorg/s2i-python-container\[ra] -.IP \(bu 2 -s2i\-perl -\[la]https://github.com/sclorg/s2i-perl-container\[ra] -.IP \(bu 2 -s2i\-php -\[la]https://github.com/sclorg/s2i-php-container\[ra] - -.PP -This container image also installs several development libraries, that are -often required in the builder images above. It also includes NPM package manager. -Sharing those development packages in a common layer saves disk space and -improves pulling speed. - -.PP -NPM, a package manager for Node.js, offers a pleasant way to install JavaScript -libraries, that are often needed as static files for various web applications. -In order to offer good experience for web developers, the NPM package manager -is also installed in the image. - -.PP -For containers where the development libraries and NPM package manager are not -necessary, users are advised to use the s2i\-core variant of this container image. - -.SH Description -.PP -OpenShift S2I images use Software Collections -\[la]https://www.softwarecollections.org/en/\[ra] -packages to provide the latest versions of various software. -The SCL packages are released more frequently than the RHEL or CentOS systems, -which are unlikely to change for several years. -We rely on RHEL and CentOS for base images, on the other hand, -because those are stable, supported, and secure platforms. - -.PP -Normally, SCL requires manual operation to enable the collection you want to use. -This is burdensome and can be prone to error. -The OpenShift S2I approach is to set Bash environment variables that -serve to automatically enable the desired collection: -.IP \(bu 2 -\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions -.IP \(bu 2 -\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR -.IP \(bu 2 -\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell - -.PP -Two examples: -* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts -do not need to call \fB\fCscl enable\fR\&. -* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the -\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. - -.PP -\fINote\fP: -Executables in Software Collections packages (e.g., \fB\fCruby\fR) -are not directly in a directory named in the \fB\fCPATH\fR environment variable. -This means that you cannot do: - -.PP -.RS - -.nf -$ docker exec ... ruby - -.fi -.RE - -.PP -but must instead do: - -.PP -.RS - -.nf -$ docker exec ... /bin/bash \-c ruby - -.fi -.RE - -.PP -The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, -ensures the correct \fB\fCruby\fR executable is found and invoked. - -.SH Usage -.PP -Choose either the CentOS7 or RHEL7 base image: -* \fBRHEL7 base image\fP - -.PP -To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=base TARGET=rhel7 - -.fi -.RE -.IP \(bu 2 -\fBCentOS7 base image\fP - -.PP -This image is available on DockerHub. To download it run: - -.PP -.RS - -.nf -docker pull sclorg/s2i\-base\-centos7 - -.fi -.RE - -.PP -To build a Base image from scratch run: - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=base - -.fi -.RE - -.PP -\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed -on all provided versions of s2i image.\fP - -.SH See also -.PP -Dockerfile and other sources are available on -\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. -In that repository you also can find another variants of S2I base Dockerfiles. -Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. From 00171b45664eaffa143816b3a4f7900fdb83c855 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Wed, 18 Apr 2018 08:58:45 +0200 Subject: [PATCH 13/30] Do sync from upstream - substitute Docker by container --- Dockerfile | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 8d94bf8..c181dea 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ -# This image is the base image for all OpenShift v3 language Docker images. -FROM registry.fedoraproject.org/rawhide/s2i-core +# This image is the base image for all OpenShift v3 language container images. +FROM registry.fedoraproject.org/26/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ @@ -9,7 +9,7 @@ functionality. Additionally, s2i-base also contains various libraries needed for it to serve as a base for other builder images, like s2i-python or s2i-ruby." \ NAME=s2i-base \ VERSION=1 \ - RELEASE=9 \ + RELEASE=1 \ ARCH=x86_64 LABEL summary="$SUMMARY" \ @@ -23,7 +23,7 @@ LABEL summary="$SUMMARY" \ architecture="$ARCH" \ maintainer="SoftwareCollections.org " -# This is the list of basic dependencies that all language Docker image can +# This is the list of basic dependencies that all language container image can # consume. RUN INSTALL_PKGS="autoconf \ automake \ From a33f3ed1df3bbb064d64d6d838974f0920bf1408 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Wed, 18 Apr 2018 09:14:42 +0200 Subject: [PATCH 14/30] Change base image to f28/s2i-core --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index c181dea..21758f5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/26/s2i-core +FROM registry.fedoraproject.org/28/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From 6e88d8de55f7de512f42cb900a0c488700913895 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 18 Apr 2018 22:42:11 +0200 Subject: [PATCH 15/30] Fix parent image name --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 21758f5..52ff87e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/28/s2i-core +FROM registry.fedoraproject.org/f28/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From 17c5ac7c9134387c4e2755d72ade16ee2f9085eb Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 18 Apr 2018 22:44:21 +0200 Subject: [PATCH 16/30] Not using registry url in FROM to be able to build the image --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 52ff87e..5c9493b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f28/s2i-core +FROM f28/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From 767487ab49aa70b467eda6d87d9d09251717e36b Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 18 Apr 2018 22:48:12 +0200 Subject: [PATCH 17/30] Using candiate registry url in FROM to be able to build the image --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 5c9493b..3a9cfb7 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM f28/s2i-core +FROM candidate-registry.fedoraproject.org/f28/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From d55b20144b16e85d637b5095e21231a271f6ea29 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 18 Apr 2018 22:51:04 +0200 Subject: [PATCH 18/30] Return back changes in FROM --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 3a9cfb7..52ff87e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM candidate-registry.fedoraproject.org/f28/s2i-core +FROM registry.fedoraproject.org/f28/s2i-core ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From a4389f00122d23b76bbbaac0274c1c1ef8780c2a Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 25 Apr 2018 08:18:30 +0200 Subject: [PATCH 19/30] Add s2i-core sources as well, temporarily, since depended layered images are problem in fedora --- Dockerfile | 57 +++++++++++- root/help.1 | 124 ++++++++++++++++++++++++++ root/opt/app-root/etc/scl_enable | 2 + root/usr/bin/base-usage | 24 +++++ root/usr/bin/cgroup-limits | 92 +++++++++++++++++++ root/usr/bin/container-entrypoint | 2 + root/usr/bin/fix-permissions | 27 ++++++ root/usr/bin/prepare-yum-repositories | 48 ++++++++++ root/usr/bin/rpm-file-permissions | 21 +++++ 9 files changed, 393 insertions(+), 4 deletions(-) create mode 100644 root/help.1 create mode 100644 root/opt/app-root/etc/scl_enable create mode 100755 root/usr/bin/base-usage create mode 100755 root/usr/bin/cgroup-limits create mode 100755 root/usr/bin/container-entrypoint create mode 100755 root/usr/bin/fix-permissions create mode 100755 root/usr/bin/prepare-yum-repositories create mode 100755 root/usr/bin/rpm-file-permissions diff --git a/Dockerfile b/Dockerfile index 52ff87e..46024a7 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ -# This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f28/s2i-core +# This image is the base image for all s2i configurable container images. +FROM registry.fedoraproject.org/fedora:28 ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ @@ -23,6 +23,40 @@ LABEL summary="$SUMMARY" \ architecture="$ARCH" \ maintainer="SoftwareCollections.org " +ENV \ + # DEPRECATED: Use above LABEL instead, because this will be removed in future versions. + STI_SCRIPTS_URL=image:///usr/libexec/s2i \ + # Path to be used in other layers to place s2i scripts into + STI_SCRIPTS_PATH=/usr/libexec/s2i \ + APP_ROOT=/opt/app-root \ + # The $HOME is not set by default, but some applications needs this variable + HOME=/opt/app-root/src \ + PATH=/opt/app-root/src/bin:/opt/app-root/bin:$PATH + +# When bash is started non-interactively, to run a shell script, for example it +# looks for this variable and source the content of this file. This will enable +# the SCL for all scripts without need to do 'scl enable'. +ENV BASH_ENV=${APP_ROOT}/etc/scl_enable \ + ENV=${APP_ROOT}/etc/scl_enable \ + PROMPT_COMMAND=". ${APP_ROOT}/etc/scl_enable" + +# This is the list of basic dependencies that all language container image can +# consume. +# Also setup the 'openshift' user that is used for the build execution and for the +# application runtime execution. +# TODO: Use better UID and GID values +RUN INSTALL_PKGS="bsdtar \ + findutils \ + gettext \ + groff \ + tar \ + unzip" && \ + mkdir -p ${HOME}/.pki/nssdb && \ + chown -R 1001:0 ${HOME}/.pki && \ + dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ + rpm -V $INSTALL_PKGS && \ + dnf clean all -y + # This is the list of basic dependencies that all language container image can # consume. RUN INSTALL_PKGS="autoconf \ @@ -37,8 +71,7 @@ RUN INSTALL_PKGS="autoconf \ libxslt-devel \ lsof \ make \ - mariadb-devel \ - mariadb-libs \ + mariadb-connector-c-devel \ npm \ openssl-devel \ patch \ @@ -52,3 +85,19 @@ RUN INSTALL_PKGS="autoconf \ dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ rpm -V $INSTALL_PKGS && \ dnf clean all -y + +# Copy extra files to the image. +COPY ./root/ / + +# Directory with the sources is set as the working directory so all STI scripts +# can execute relative to this path. +WORKDIR ${HOME} + +ENTRYPOINT ["container-entrypoint"] +CMD ["base-usage"] + +# Reset permissions of modified directories and add default user +RUN rpm-file-permissions && \ + useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \ + -c "Default Application User" default && \ + chown -R 1001:0 ${APP_ROOT} diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..2f46315 --- /dev/null +++ b/root/help.1 @@ -0,0 +1,124 @@ +.TH OpenShift base images (core variant) +.PP +This repository contains Dockerfiles for images which can be used as base images +to add support for source\-to\-image +\[la]https://github.com/openshift/source-to-image\[ra] +without installing several development libraries. + +.SH Description +.PP +OpenShift S2I images use Software Collections +\[la]https://www.softwarecollections.org/en/\[ra] +packages to provide the latest versions of various software. +The SCL packages are released more frequently than the RHEL or CentOS systems, +which are unlikely to change for several years. +We rely on RHEL and CentOS for base images, on the other hand, +because those are stable, supported, and secure platforms. + +.PP +Normally, SCL requires manual operation to enable the collection you want to use. +This is burdensome and can be prone to error. +The OpenShift S2I approach is to set Bash environment variables that +serve to automatically enable the desired collection: +.IP \(bu 2 +\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions +.IP \(bu 2 +\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR +.IP \(bu 2 +\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell + +.PP +Two examples: +* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts +do not need to call \fB\fCscl enable\fR\&. +* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the +\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. + +.PP +\fINote\fP: +Executables in Software Collections packages (e.g., \fB\fCruby\fR) +are not directly in a directory named in the \fB\fCPATH\fR environment variable. +This means that you cannot do: + +.PP +.RS + +.nf +$ docker exec ... ruby + +.fi +.RE + +.PP +but must instead do: + +.PP +.RS + +.nf +$ docker exec ... /bin/bash \-c ruby + +.fi +.RE + +.PP +The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, +ensures the correct \fB\fCruby\fR executable is found and invoked. + +.SH Usage +.PP +Choose either the CentOS7 or RHEL7 base image: +* \fBRHEL7 base image\fP + +.PP +To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=core TARGET=rhel7 + +.fi +.RE +.IP \(bu 2 +\fBCentOS7 base image\fP + +.PP +This image is available on DockerHub. To download it run: + +.PP +.RS + +.nf +docker pull sclorg/s2i\-core\-centos7 + +.fi +.RE + +.PP +To build a Base image from scratch run: + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=core + +.fi +.RE + +.PP +\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed +on all provided versions of s2i image.\fP + +.SH See also +.PP +Dockerfile and other sources are available on +\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. +In that repository you also can find another variants of S2I Base Dockerfiles. +Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/root/opt/app-root/etc/scl_enable b/root/opt/app-root/etc/scl_enable new file mode 100644 index 0000000..8fca598 --- /dev/null +++ b/root/opt/app-root/etc/scl_enable @@ -0,0 +1,2 @@ +# This file contains automatic SCL enablement. +unset BASH_ENV PROMPT_COMMAND ENV diff --git a/root/usr/bin/base-usage b/root/usr/bin/base-usage new file mode 100755 index 0000000..154ccc4 --- /dev/null +++ b/root/usr/bin/base-usage @@ -0,0 +1,24 @@ +#!/bin/sh -e + +cat <= 92233720368547: + env_vars["NO_MEMORY_LIMIT"] = "true" + + for key, value in env_vars.items(): + print("{0}={1}".format(key, value)) diff --git a/root/usr/bin/container-entrypoint b/root/usr/bin/container-entrypoint new file mode 100755 index 0000000..9d8ad4d --- /dev/null +++ b/root/usr/bin/container-entrypoint @@ -0,0 +1,2 @@ +#!/bin/bash +exec "$@" diff --git a/root/usr/bin/fix-permissions b/root/usr/bin/fix-permissions new file mode 100755 index 0000000..ddd33ac --- /dev/null +++ b/root/usr/bin/fix-permissions @@ -0,0 +1,27 @@ +#!/bin/sh + +# Allow this script to fail without failing a build +set +e + +SYMLINK_OPT=${2:--L} + +# Fix permissions on the given directory or file to allow group read/write of +# regular files and execute of directories. + +[ $(id -u) -ne 0 ] && CHECK_OWNER=" -uid $(id -u)" + +# If argument does not exist, script will still exit with 0, +# but at least we'll see something went wrong in the log +if ! [ -e "$1" ] ; then + echo "ERROR: File or directory $1 does not exist." >&2 + # We still want to end successfully + exit 0 +fi + +find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -gid 0 -exec chgrp 0 {} + +find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -perm -g+rw -exec chmod g+rw {} + +find $SYMLINK_OPT "$1" ${CHECK_OWNER} -perm /u+x -a \! -perm /g+x -exec chmod g+x {} + +find $SYMLINK_OPT "$1" ${CHECK_OWNER} -type d \! -perm /g+x -exec chmod g+x {} + + +# Always end successfully +exit 0 diff --git a/root/usr/bin/prepare-yum-repositories b/root/usr/bin/prepare-yum-repositories new file mode 100755 index 0000000..850701b --- /dev/null +++ b/root/usr/bin/prepare-yum-repositories @@ -0,0 +1,48 @@ +#!/bin/bash + +# This script is used to prepare yum repositories, that are given as arguments. + +set -ex + +# DEFAULT_REPOS and SKIP_REPOS_{ENABLE,DISABLE} are intentionally undocumented, +# but might be used if we need to change this behaviour. +# Once we realize there are real use cases for using those variables, we should +# document them properly. +DEFAULT_REPOS=${DEFAULT_REPOS:-"rhel-7-server-rpms rhel-7-server-optional-rpms"} +SKIP_REPOS_ENABLE=${SKIP_REPOS_ENABLE:-false} +SKIP_REPOS_DISABLE=${SKIP_REPOS_DISABLE:-false} + +function is_subscribed() { + for f in /run/secrets/etc-pki-entitlement/*.pem ; do + [ -e "$f" ] && return 0 + break + done + return 1 +} + +# if redhat.repo does not exist we have a mounted-in dir, do not enable repositories +[ -f /etc/yum.repos.d/redhat.repo ] || SKIP_REPOS_ENABLE=true + +# install yum-utils for yum-config-manager +yum install -y yum-utils + +if [ "$SKIP_REPOS_DISABLE" = false ] && is_subscribed; then + # Disable only repos that might come from subscribed host, because there + # might be other repos provided by user or build system + + disable_repos= + # Lines look like: "Repo-id : dist-tag-override/x86_64" + while IFS=' /' read -r _ _ repo_id _; do + case $repo_id in rhel-*) + disable_repos+=" $repo_id" ;; + esac + done <<<"$(yum repolist -v 2>/dev/null | grep Repo-id)" + + if test -n "$disable_repos"; then + yum-config-manager --disable $disable_repos &> /dev/null + fi +fi + +if [ ${SKIP_REPOS_ENABLE} = false ] && [ -n "${DEFAULT_REPOS}" -o $# -gt 0 ] ; then + yum-config-manager --enable ${DEFAULT_REPOS} "$@" +fi diff --git a/root/usr/bin/rpm-file-permissions b/root/usr/bin/rpm-file-permissions new file mode 100755 index 0000000..8be1fb0 --- /dev/null +++ b/root/usr/bin/rpm-file-permissions @@ -0,0 +1,21 @@ +#!/bin/sh + +CHECK_DIRS="/ /opt /etc /usr /usr/bin /usr/lib /usr/lib64 /usr/share /usr/libexec" + +rpm_format="[%{FILESTATES:fstate} %7{FILEMODES:octal} %{FILENAMES:shescape}\n]" + +rpm -q --qf "$rpm_format" filesystem | while read line +do + eval "set -- $line" + + case $1 in + normal) ;; + *) continue ;; + esac + + case " $CHECK_DIRS " in + *" $3 "*) + chmod "${2: -4}" "$3" + ;; + esac +done From d96a7fee0371e7c50cbfd56bee3a311f4efddec0 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 25 Apr 2018 08:22:34 +0200 Subject: [PATCH 20/30] update to f29 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 46024a7..35276c0 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all s2i configurable container images. -FROM registry.fedoraproject.org/fedora:28 +FROM registry.fedoraproject.org/fedora:29 ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From e8f7d21158555ef57ca3265546c67851b01b8e9f Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 24 Jul 2018 18:03:19 +0200 Subject: [PATCH 21/30] Remove the temporarily added s2i-core content --- Dockerfile | 54 +---------- root/help.1 | 124 -------------------------- root/opt/app-root/etc/scl_enable | 2 - root/usr/bin/base-usage | 24 ----- root/usr/bin/cgroup-limits | 92 ------------------- root/usr/bin/container-entrypoint | 2 - root/usr/bin/fix-permissions | 27 ------ root/usr/bin/prepare-yum-repositories | 48 ---------- root/usr/bin/rpm-file-permissions | 21 ----- 9 files changed, 2 insertions(+), 392 deletions(-) delete mode 100644 root/help.1 delete mode 100644 root/opt/app-root/etc/scl_enable delete mode 100755 root/usr/bin/base-usage delete mode 100755 root/usr/bin/cgroup-limits delete mode 100755 root/usr/bin/container-entrypoint delete mode 100755 root/usr/bin/fix-permissions delete mode 100755 root/usr/bin/prepare-yum-repositories delete mode 100755 root/usr/bin/rpm-file-permissions diff --git a/Dockerfile b/Dockerfile index 35276c0..f857ab4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ -# This image is the base image for all s2i configurable container images. -FROM registry.fedoraproject.org/fedora:29 +# This image is the base image for all OpenShift v3 language container images. +FROM registry.fedoraproject.org/f29/s2i-core:latest ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ @@ -23,40 +23,6 @@ LABEL summary="$SUMMARY" \ architecture="$ARCH" \ maintainer="SoftwareCollections.org " -ENV \ - # DEPRECATED: Use above LABEL instead, because this will be removed in future versions. - STI_SCRIPTS_URL=image:///usr/libexec/s2i \ - # Path to be used in other layers to place s2i scripts into - STI_SCRIPTS_PATH=/usr/libexec/s2i \ - APP_ROOT=/opt/app-root \ - # The $HOME is not set by default, but some applications needs this variable - HOME=/opt/app-root/src \ - PATH=/opt/app-root/src/bin:/opt/app-root/bin:$PATH - -# When bash is started non-interactively, to run a shell script, for example it -# looks for this variable and source the content of this file. This will enable -# the SCL for all scripts without need to do 'scl enable'. -ENV BASH_ENV=${APP_ROOT}/etc/scl_enable \ - ENV=${APP_ROOT}/etc/scl_enable \ - PROMPT_COMMAND=". ${APP_ROOT}/etc/scl_enable" - -# This is the list of basic dependencies that all language container image can -# consume. -# Also setup the 'openshift' user that is used for the build execution and for the -# application runtime execution. -# TODO: Use better UID and GID values -RUN INSTALL_PKGS="bsdtar \ - findutils \ - gettext \ - groff \ - tar \ - unzip" && \ - mkdir -p ${HOME}/.pki/nssdb && \ - chown -R 1001:0 ${HOME}/.pki && \ - dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ - rpm -V $INSTALL_PKGS && \ - dnf clean all -y - # This is the list of basic dependencies that all language container image can # consume. RUN INSTALL_PKGS="autoconf \ @@ -85,19 +51,3 @@ RUN INSTALL_PKGS="autoconf \ dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ rpm -V $INSTALL_PKGS && \ dnf clean all -y - -# Copy extra files to the image. -COPY ./root/ / - -# Directory with the sources is set as the working directory so all STI scripts -# can execute relative to this path. -WORKDIR ${HOME} - -ENTRYPOINT ["container-entrypoint"] -CMD ["base-usage"] - -# Reset permissions of modified directories and add default user -RUN rpm-file-permissions && \ - useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \ - -c "Default Application User" default && \ - chown -R 1001:0 ${APP_ROOT} diff --git a/root/help.1 b/root/help.1 deleted file mode 100644 index 2f46315..0000000 --- a/root/help.1 +++ /dev/null @@ -1,124 +0,0 @@ -.TH OpenShift base images (core variant) -.PP -This repository contains Dockerfiles for images which can be used as base images -to add support for source\-to\-image -\[la]https://github.com/openshift/source-to-image\[ra] -without installing several development libraries. - -.SH Description -.PP -OpenShift S2I images use Software Collections -\[la]https://www.softwarecollections.org/en/\[ra] -packages to provide the latest versions of various software. -The SCL packages are released more frequently than the RHEL or CentOS systems, -which are unlikely to change for several years. -We rely on RHEL and CentOS for base images, on the other hand, -because those are stable, supported, and secure platforms. - -.PP -Normally, SCL requires manual operation to enable the collection you want to use. -This is burdensome and can be prone to error. -The OpenShift S2I approach is to set Bash environment variables that -serve to automatically enable the desired collection: -.IP \(bu 2 -\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions -.IP \(bu 2 -\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR -.IP \(bu 2 -\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell - -.PP -Two examples: -* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts -do not need to call \fB\fCscl enable\fR\&. -* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the -\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. - -.PP -\fINote\fP: -Executables in Software Collections packages (e.g., \fB\fCruby\fR) -are not directly in a directory named in the \fB\fCPATH\fR environment variable. -This means that you cannot do: - -.PP -.RS - -.nf -$ docker exec ... ruby - -.fi -.RE - -.PP -but must instead do: - -.PP -.RS - -.nf -$ docker exec ... /bin/bash \-c ruby - -.fi -.RE - -.PP -The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, -ensures the correct \fB\fCruby\fR executable is found and invoked. - -.SH Usage -.PP -Choose either the CentOS7 or RHEL7 base image: -* \fBRHEL7 base image\fP - -.PP -To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=core TARGET=rhel7 - -.fi -.RE -.IP \(bu 2 -\fBCentOS7 base image\fP - -.PP -This image is available on DockerHub. To download it run: - -.PP -.RS - -.nf -docker pull sclorg/s2i\-core\-centos7 - -.fi -.RE - -.PP -To build a Base image from scratch run: - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=core - -.fi -.RE - -.PP -\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed -on all provided versions of s2i image.\fP - -.SH See also -.PP -Dockerfile and other sources are available on -\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. -In that repository you also can find another variants of S2I Base Dockerfiles. -Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/root/opt/app-root/etc/scl_enable b/root/opt/app-root/etc/scl_enable deleted file mode 100644 index 8fca598..0000000 --- a/root/opt/app-root/etc/scl_enable +++ /dev/null @@ -1,2 +0,0 @@ -# This file contains automatic SCL enablement. -unset BASH_ENV PROMPT_COMMAND ENV diff --git a/root/usr/bin/base-usage b/root/usr/bin/base-usage deleted file mode 100755 index 154ccc4..0000000 --- a/root/usr/bin/base-usage +++ /dev/null @@ -1,24 +0,0 @@ -#!/bin/sh -e - -cat <= 92233720368547: - env_vars["NO_MEMORY_LIMIT"] = "true" - - for key, value in env_vars.items(): - print("{0}={1}".format(key, value)) diff --git a/root/usr/bin/container-entrypoint b/root/usr/bin/container-entrypoint deleted file mode 100755 index 9d8ad4d..0000000 --- a/root/usr/bin/container-entrypoint +++ /dev/null @@ -1,2 +0,0 @@ -#!/bin/bash -exec "$@" diff --git a/root/usr/bin/fix-permissions b/root/usr/bin/fix-permissions deleted file mode 100755 index ddd33ac..0000000 --- a/root/usr/bin/fix-permissions +++ /dev/null @@ -1,27 +0,0 @@ -#!/bin/sh - -# Allow this script to fail without failing a build -set +e - -SYMLINK_OPT=${2:--L} - -# Fix permissions on the given directory or file to allow group read/write of -# regular files and execute of directories. - -[ $(id -u) -ne 0 ] && CHECK_OWNER=" -uid $(id -u)" - -# If argument does not exist, script will still exit with 0, -# but at least we'll see something went wrong in the log -if ! [ -e "$1" ] ; then - echo "ERROR: File or directory $1 does not exist." >&2 - # We still want to end successfully - exit 0 -fi - -find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -gid 0 -exec chgrp 0 {} + -find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -perm -g+rw -exec chmod g+rw {} + -find $SYMLINK_OPT "$1" ${CHECK_OWNER} -perm /u+x -a \! -perm /g+x -exec chmod g+x {} + -find $SYMLINK_OPT "$1" ${CHECK_OWNER} -type d \! -perm /g+x -exec chmod g+x {} + - -# Always end successfully -exit 0 diff --git a/root/usr/bin/prepare-yum-repositories b/root/usr/bin/prepare-yum-repositories deleted file mode 100755 index 850701b..0000000 --- a/root/usr/bin/prepare-yum-repositories +++ /dev/null @@ -1,48 +0,0 @@ -#!/bin/bash - -# This script is used to prepare yum repositories, that are given as arguments. - -set -ex - -# DEFAULT_REPOS and SKIP_REPOS_{ENABLE,DISABLE} are intentionally undocumented, -# but might be used if we need to change this behaviour. -# Once we realize there are real use cases for using those variables, we should -# document them properly. -DEFAULT_REPOS=${DEFAULT_REPOS:-"rhel-7-server-rpms rhel-7-server-optional-rpms"} -SKIP_REPOS_ENABLE=${SKIP_REPOS_ENABLE:-false} -SKIP_REPOS_DISABLE=${SKIP_REPOS_DISABLE:-false} - -function is_subscribed() { - for f in /run/secrets/etc-pki-entitlement/*.pem ; do - [ -e "$f" ] && return 0 - break - done - return 1 -} - -# if redhat.repo does not exist we have a mounted-in dir, do not enable repositories -[ -f /etc/yum.repos.d/redhat.repo ] || SKIP_REPOS_ENABLE=true - -# install yum-utils for yum-config-manager -yum install -y yum-utils - -if [ "$SKIP_REPOS_DISABLE" = false ] && is_subscribed; then - # Disable only repos that might come from subscribed host, because there - # might be other repos provided by user or build system - - disable_repos= - # Lines look like: "Repo-id : dist-tag-override/x86_64" - while IFS=' /' read -r _ _ repo_id _; do - case $repo_id in rhel-*) - disable_repos+=" $repo_id" ;; - esac - done <<<"$(yum repolist -v 2>/dev/null | grep Repo-id)" - - if test -n "$disable_repos"; then - yum-config-manager --disable $disable_repos &> /dev/null - fi -fi - -if [ ${SKIP_REPOS_ENABLE} = false ] && [ -n "${DEFAULT_REPOS}" -o $# -gt 0 ] ; then - yum-config-manager --enable ${DEFAULT_REPOS} "$@" -fi diff --git a/root/usr/bin/rpm-file-permissions b/root/usr/bin/rpm-file-permissions deleted file mode 100755 index 8be1fb0..0000000 --- a/root/usr/bin/rpm-file-permissions +++ /dev/null @@ -1,21 +0,0 @@ -#!/bin/sh - -CHECK_DIRS="/ /opt /etc /usr /usr/bin /usr/lib /usr/lib64 /usr/share /usr/libexec" - -rpm_format="[%{FILESTATES:fstate} %7{FILEMODES:octal} %{FILENAMES:shescape}\n]" - -rpm -q --qf "$rpm_format" filesystem | while read line -do - eval "set -- $line" - - case $1 in - normal) ;; - *) continue ;; - esac - - case " $CHECK_DIRS " in - *" $3 "*) - chmod "${2: -4}" "$3" - ;; - esac -done From 21e4d17ea5d56fd47531b682cdd89215b9f2d102 Mon Sep 17 00:00:00 2001 From: Clement Verna Date: Mon, 27 Aug 2018 10:31:27 +0200 Subject: [PATCH 22/30] Drop Release label in favor of OSBS release_bump plugin. OSBS can automatically bump the release number, for that we just need to drop the label from the Dockerfile See https://pagure.io/ContainerSIG/container-sig/issue/1 Signed-off-by: Clement Verna --- Dockerfile | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index f857ab4..d847167 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f29/s2i-core:latest +FROM registry.fedoraproject.org/f30/s2i-core:latest ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ @@ -9,7 +9,6 @@ functionality. Additionally, s2i-base also contains various libraries needed for it to serve as a base for other builder images, like s2i-python or s2i-ruby." \ NAME=s2i-base \ VERSION=1 \ - RELEASE=1 \ ARCH=x86_64 LABEL summary="$SUMMARY" \ @@ -19,7 +18,6 @@ LABEL summary="$SUMMARY" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ maintainer="SoftwareCollections.org " From 325617e6e40dd850315dcd9440a383ac9bf5c392 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Fri, 14 Sep 2018 10:38:05 +0200 Subject: [PATCH 23/30] Use libpq-devel instead of postgresql-devel. Resolves RHBZ#1618698 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index d847167..704c4d5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -39,7 +39,7 @@ RUN INSTALL_PKGS="autoconf \ npm \ openssl-devel \ patch \ - postgresql-devel \ + libpq-devel \ procps-ng \ sqlite-devel \ unzip \ From 16612a97981726402277b9a296889e4fa85fb69e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Fri, 30 Nov 2018 17:46:25 +0000 Subject: [PATCH 24/30] Pull changes from upstream and rebase for: rebuild for latest f30 --- Dockerfile | 3 +- Dockerfile.fedora | 1 + LICENSE | 202 ---------------------------------------------- base | 1 + help.md | 1 + root/help.1 | 153 +++++++++++++++++++++++++++++++++++ sources | 0 7 files changed, 157 insertions(+), 204 deletions(-) create mode 120000 Dockerfile.fedora delete mode 100644 LICENSE create mode 120000 base create mode 120000 help.md create mode 100644 root/help.1 delete mode 100644 sources diff --git a/Dockerfile b/Dockerfile index 704c4d5..be89a8e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -18,7 +18,6 @@ LABEL summary="$SUMMARY" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ - architecture="$ARCH" \ maintainer="SoftwareCollections.org " # This is the list of basic dependencies that all language container image can @@ -39,7 +38,7 @@ RUN INSTALL_PKGS="autoconf \ npm \ openssl-devel \ patch \ - libpq-devel \ + postgresql-devel \ procps-ng \ sqlite-devel \ unzip \ diff --git a/Dockerfile.fedora b/Dockerfile.fedora new file mode 120000 index 0000000..1d1fe94 --- /dev/null +++ b/Dockerfile.fedora @@ -0,0 +1 @@ +Dockerfile \ No newline at end of file diff --git a/LICENSE b/LICENSE deleted file mode 100644 index 7a4a3ea..0000000 --- a/LICENSE +++ /dev/null @@ -1,202 +0,0 @@ - - Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ - - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION - - 1. Definitions. - - "License" shall mean the terms and conditions for use, reproduction, - and distribution as defined by Sections 1 through 9 of this document. - - "Licensor" shall mean the copyright owner or entity authorized by - the copyright owner that is granting the License. - - "Legal Entity" shall mean the union of the acting entity and all - other entities that control, are controlled by, or are under common - control with that entity. For the purposes of this definition, - "control" means (i) the power, direct or indirect, to cause the - direction or management of such entity, whether by contract or - otherwise, or (ii) ownership of fifty percent (50%) or more of the - outstanding shares, or (iii) beneficial ownership of such entity. - - "You" (or "Your") shall mean an individual or Legal Entity - exercising permissions granted by this License. - - "Source" form shall mean the preferred form for making modifications, - including but not limited to software source code, documentation - source, and configuration files. - - "Object" form shall mean any form resulting from mechanical - transformation or translation of a Source form, including but - not limited to compiled object code, generated documentation, - and conversions to other media types. - - "Work" shall mean the work of authorship, whether in Source or - Object form, made available under the License, as indicated by a - copyright notice that is included in or attached to the work - (an example is provided in the Appendix below). - - "Derivative Works" shall mean any work, whether in Source or Object - form, that is based on (or derived from) the Work and for which the - editorial revisions, annotations, elaborations, or other modifications - represent, as a whole, an original work of authorship. For the purposes - of this License, Derivative Works shall not include works that remain - separable from, or merely link (or bind by name) to the interfaces of, - the Work and Derivative Works thereof. - - "Contribution" shall mean any work of authorship, including - the original version of the Work and any modifications or additions - to that Work or Derivative Works thereof, that is intentionally - submitted to Licensor for inclusion in the Work by the copyright owner - or by an individual or Legal Entity authorized to submit on behalf of - the copyright owner. For the purposes of this definition, "submitted" - means any form of electronic, verbal, or written communication sent - to the Licensor or its representatives, including but not limited to - communication on electronic mailing lists, source code control systems, - and issue tracking systems that are managed by, or on behalf of, the - Licensor for the purpose of discussing and improving the Work, but - excluding communication that is conspicuously marked or otherwise - designated in writing by the copyright owner as "Not a Contribution." - - "Contributor" shall mean Licensor and any individual or Legal Entity - on behalf of whom a Contribution has been received by Licensor and - subsequently incorporated within the Work. - - 2. Grant of Copyright License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - copyright license to reproduce, prepare Derivative Works of, - publicly display, publicly perform, sublicense, and distribute the - Work and such Derivative Works in Source or Object form. - - 3. Grant of Patent License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - (except as stated in this section) patent license to make, have made, - use, offer to sell, sell, import, and otherwise transfer the Work, - where such license applies only to those patent claims licensable - by such Contributor that are necessarily infringed by their - Contribution(s) alone or by combination of their Contribution(s) - with the Work to which such Contribution(s) was submitted. If You - institute patent litigation against any entity (including a - cross-claim or counterclaim in a lawsuit) alleging that the Work - or a Contribution incorporated within the Work constitutes direct - or contributory patent infringement, then any patent licenses - granted to You under this License for that Work shall terminate - as of the date such litigation is filed. - - 4. Redistribution. You may reproduce and distribute copies of the - Work or Derivative Works thereof in any medium, with or without - modifications, and in Source or Object form, provided that You - meet the following conditions: - - (a) You must give any other recipients of the Work or - Derivative Works a copy of this License; and - - (b) You must cause any modified files to carry prominent notices - stating that You changed the files; and - - (c) You must retain, in the Source form of any Derivative Works - that You distribute, all copyright, patent, trademark, and - attribution notices from the Source form of the Work, - excluding those notices that do not pertain to any part of - the Derivative Works; and - - (d) If the Work includes a "NOTICE" text file as part of its - distribution, then any Derivative Works that You distribute must - include a readable copy of the attribution notices contained - within such NOTICE file, excluding those notices that do not - pertain to any part of the Derivative Works, in at least one - of the following places: within a NOTICE text file distributed - as part of the Derivative Works; within the Source form or - documentation, if provided along with the Derivative Works; or, - within a display generated by the Derivative Works, if and - wherever such third-party notices normally appear. The contents - of the NOTICE file are for informational purposes only and - do not modify the License. You may add Your own attribution - notices within Derivative Works that You distribute, alongside - or as an addendum to the NOTICE text from the Work, provided - that such additional attribution notices cannot be construed - as modifying the License. - - You may add Your own copyright statement to Your modifications and - may provide additional or different license terms and conditions - for use, reproduction, or distribution of Your modifications, or - for any such Derivative Works as a whole, provided Your use, - reproduction, and distribution of the Work otherwise complies with - the conditions stated in this License. - - 5. Submission of Contributions. Unless You explicitly state otherwise, - any Contribution intentionally submitted for inclusion in the Work - by You to the Licensor shall be under the terms and conditions of - this License, without any additional terms or conditions. - Notwithstanding the above, nothing herein shall supersede or modify - the terms of any separate license agreement you may have executed - with Licensor regarding such Contributions. - - 6. Trademarks. This License does not grant permission to use the trade - names, trademarks, service marks, or product names of the Licensor, - except as required for reasonable and customary use in describing the - origin of the Work and reproducing the content of the NOTICE file. - - 7. Disclaimer of Warranty. Unless required by applicable law or - agreed to in writing, Licensor provides the Work (and each - Contributor provides its Contributions) on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or - implied, including, without limitation, any warranties or conditions - of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A - PARTICULAR PURPOSE. You are solely responsible for determining the - appropriateness of using or redistributing the Work and assume any - risks associated with Your exercise of permissions under this License. - - 8. Limitation of Liability. In no event and under no legal theory, - whether in tort (including negligence), contract, or otherwise, - unless required by applicable law (such as deliberate and grossly - negligent acts) or agreed to in writing, shall any Contributor be - liable to You for damages, including any direct, indirect, special, - incidental, or consequential damages of any character arising as a - result of this License or out of the use or inability to use the - Work (including but not limited to damages for loss of goodwill, - work stoppage, computer failure or malfunction, or any and all - other commercial damages or losses), even if such Contributor - has been advised of the possibility of such damages. - - 9. Accepting Warranty or Additional Liability. While redistributing - the Work or Derivative Works thereof, You may choose to offer, - and charge a fee for, acceptance of support, warranty, indemnity, - or other liability obligations and/or rights consistent with this - License. However, in accepting such obligations, You may act only - on Your own behalf and on Your sole responsibility, not on behalf - of any other Contributor, and only if You agree to indemnify, - defend, and hold each Contributor harmless for any liability - incurred by, or claims asserted against, such Contributor by reason - of your accepting any such warranty or additional liability. - - END OF TERMS AND CONDITIONS - - APPENDIX: How to apply the Apache License to your work. - - To apply the Apache License to your work, attach the following - boilerplate notice, with the fields enclosed by brackets "[]" - replaced with your own identifying information. (Don't include - the brackets!) The text should be enclosed in the appropriate - comment syntax for the file format. We also recommend that a - file or class name and description of purpose be included on the - same "printed page" as the copyright notice for easier - identification within third-party archives. - - Copyright [yyyy] [name of copyright owner] - - Licensed under the Apache License, Version 2.0 (the "License"); - you may not use this file except in compliance with the License. - You may obtain a copy of the License at - - http://www.apache.org/licenses/LICENSE-2.0 - - Unless required by applicable law or agreed to in writing, software - distributed under the License is distributed on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - See the License for the specific language governing permissions and - limitations under the License. \ No newline at end of file diff --git a/base b/base new file mode 120000 index 0000000..945c9b4 --- /dev/null +++ b/base @@ -0,0 +1 @@ +. \ No newline at end of file diff --git a/help.md b/help.md new file mode 120000 index 0000000..42061c0 --- /dev/null +++ b/help.md @@ -0,0 +1 @@ +README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..887acd7 --- /dev/null +++ b/root/help.1 @@ -0,0 +1,153 @@ +.TH OpenShift base images +.PP +This repository contains Dockerfiles for images which serve as base images with all the +essential libraries and tools needed for OpenShift language images, for example: +.IP \(bu 2 +s2i\-ruby +\[la]https://github.com/sclorg/s2i-ruby-container\[ra] +.IP \(bu 2 +s2i\-nodejs +\[la]https://github.com/sclorg/s2i-nodejs-container\[ra] +.IP \(bu 2 +s2i\-python +\[la]https://github.com/sclorg/s2i-python-container\[ra] +.IP \(bu 2 +s2i\-perl +\[la]https://github.com/sclorg/s2i-perl-container\[ra] +.IP \(bu 2 +s2i\-php +\[la]https://github.com/sclorg/s2i-php-container\[ra] + +.PP +This container image also installs several development libraries, that are +often required in the builder images above. It also includes NPM package manager. +Sharing those development packages in a common layer saves disk space and +improves pulling speed. + +.PP +NPM, a package manager for Node.js, offers a pleasant way to install JavaScript +libraries, that are often needed as static files for various web applications. +In order to offer good experience for web developers, the NPM package manager +is also installed in the image. + +.PP +For containers where the development libraries and NPM package manager are not +necessary, users are advised to use the s2i\-core variant of this container image. + +.SH Description +.PP +OpenShift S2I images use Software Collections +\[la]https://www.softwarecollections.org/en/\[ra] +packages to provide the latest versions of various software. +The SCL packages are released more frequently than the RHEL or CentOS systems, +which are unlikely to change for several years. +We rely on RHEL and CentOS for base images, on the other hand, +because those are stable, supported, and secure platforms. + +.PP +Normally, SCL requires manual operation to enable the collection you want to use. +This is burdensome and can be prone to error. +The OpenShift S2I approach is to set Bash environment variables that +serve to automatically enable the desired collection: +.IP \(bu 2 +\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions +.IP \(bu 2 +\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR +.IP \(bu 2 +\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell + +.PP +Two examples: +* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts +do not need to call \fB\fCscl enable\fR\&. +* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the +\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. + +.PP +\fINote\fP: +Executables in Software Collections packages (e.g., \fB\fCruby\fR) +are not directly in a directory named in the \fB\fCPATH\fR environment variable. +This means that you cannot do: + +.PP +.RS + +.nf +$ docker exec ... ruby + +.fi +.RE + +.PP +but must instead do: + +.PP +.RS + +.nf +$ docker exec ... /bin/bash \-c ruby + +.fi +.RE + +.PP +The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, +ensures the correct \fB\fCruby\fR executable is found and invoked. + +.SH Usage +.PP +Choose either the CentOS7 or RHEL7 base image: +* \fBRHEL7 base image\fP + +.PP +To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=base TARGET=rhel7 + +.fi +.RE +.IP \(bu 2 +\fBCentOS7 base image\fP + +.PP +This image is available on DockerHub. To download it run: + +.PP +.RS + +.nf +docker pull sclorg/s2i\-base\-centos7 + +.fi +.RE + +.PP +To build a Base image from scratch run: + +.PP +.RS + +.nf +$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git +$ cd s2i\-base\-container +$ make build VERSIONS=base + +.fi +.RE + +.PP +\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed +on all provided versions of s2i image.\fP + +.SH See also +.PP +Dockerfile and other sources are available on +\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. +In that repository you also can find another variants of S2I base Dockerfiles. +Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/sources b/sources deleted file mode 100644 index e69de29..0000000 From 1c6503b128d0a426f2e1ac01b5a8f4805b49bbf6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jakub=20=C4=8Cajka?= Date: Wed, 26 Jun 2019 14:23:32 +0200 Subject: [PATCH 25/30] postgresql-devel moved in to libpq-devel --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index be89a8e..945494e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -38,7 +38,7 @@ RUN INSTALL_PKGS="autoconf \ npm \ openssl-devel \ patch \ - postgresql-devel \ + libpq-devel \ procps-ng \ sqlite-devel \ unzip \ From eb7621e006a9dbb748e40b9f15ba6e34b1d8245e Mon Sep 17 00:00:00 2001 From: Lumir Balhar Date: Wed, 6 Nov 2019 15:10:23 +0100 Subject: [PATCH 26/30] Update to F32 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 945494e..57429ff 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f30/s2i-core:latest +FROM registry.fedoraproject.org/f32/s2i-core:latest ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From ab9154554914c6ab3539abd9077d0b2c2db8bf3f Mon Sep 17 00:00:00 2001 From: Lumir Balhar Date: Wed, 18 Mar 2020 08:49:59 +0100 Subject: [PATCH 27/30] Update from upstream and switch to new rawhide (f33) --- Dockerfile | 4 ++-- README.md | 12 +++++++----- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/Dockerfile b/Dockerfile index 57429ff..ce3bc16 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f32/s2i-core:latest +FROM registry.fedoraproject.org/f33/s2i-core:latest ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ @@ -30,6 +30,7 @@ RUN INSTALL_PKGS="autoconf \ gdb \ git \ libcurl-devel \ + libpq-devel \ libxml2-devel \ libxslt-devel \ lsof \ @@ -38,7 +39,6 @@ RUN INSTALL_PKGS="autoconf \ npm \ openssl-devel \ patch \ - libpq-devel \ procps-ng \ sqlite-devel \ unzip \ diff --git a/README.md b/README.md index 13e4efe..7b4156a 100644 --- a/README.md +++ b/README.md @@ -47,22 +47,23 @@ Two examples: * If you specify `BASH_ENV`, then all your `#!/bin/bash` scripts do not need to call `scl enable`. * If you specify `PROMPT_COMMAND`, then on execution of the -`docker exec ... /bin/bash` command, the collection will be automatically enabled. +`podman exec ... /bin/bash` command, the collection will be automatically enabled. *Note*: Executables in Software Collections packages (e.g., `ruby`) are not directly in a directory named in the `PATH` environment variable. This means that you cannot do: - $ docker exec ... ruby + $ podman exec ... ruby but must instead do: - $ docker exec ... /bin/bash -c ruby + $ podman exec ... /bin/bash -c ruby The `/bin/bash -c`, along with the setting the appropriate environment variable, ensures the correct `ruby` executable is found and invoked. +Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments Usage ------------------------ @@ -82,7 +83,7 @@ $ make build VERSIONS=base TARGET=rhel7 This image is available on DockerHub. To download it run: ```console -docker pull sclorg/s2i-base-centos7 +podman pull sclorg/s2i-base-centos7 ``` To build a Base image from scratch run: @@ -101,4 +102,5 @@ See also -------- Dockerfile and other sources are available on https://github.com/sclorg/s2i-base-container. In that repository you also can find another variants of S2I base Dockerfiles. -Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. +The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7, +the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora. From d00360044dfae66ac1bccf9aa5a626c27e3e08b9 Mon Sep 17 00:00:00 2001 From: "Petr \"Stone\" Hracek" Date: Tue, 21 Apr 2020 15:17:07 +0200 Subject: [PATCH 28/30] Add bot-cfg.yml file sync upstream s2i-core repository to Fedora land This commit adds support for syncing upstream repository to Fedora land Signed-off-by: Petr "Stone" Hracek --- bot-cfg.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 bot-cfg.yml diff --git a/bot-cfg.yml b/bot-cfg.yml new file mode 100644 index 0000000..6067f0e --- /dev/null +++ b/bot-cfg.yml @@ -0,0 +1,26 @@ +version: "1" + +betka: + # is betka enabled for this repository + # optional - defaults to false + enabled: true + + # optional + notifications: + email_addresses: [phracek@redhat.com] + + # Specify if master branch in upstream repository is synced + master_checker: true + # Should pull requests be synced? + # optional + pr_checker: false + # Either 'upstream_branch_name' or 'upstream_git_path' has to be specified + # Branch name which is used for sync + upstream_branch_name: master + # Path to directory with dockerfile withing upstream repository + upstream_git_path: "base" + # Github comment message to enforce sync of a pull request + # required if pr_checker is true otherwise optional + pr_comment_message: "[test]" + # optional + image_url: quay.io/rhscl/cwt-generator From 5704f4271e82ed787be554d9f80895923c00645d Mon Sep 17 00:00:00 2001 From: Petr Kubat Date: Tue, 8 Dec 2020 16:51:03 +0100 Subject: [PATCH 29/30] move to F34 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index ce3bc16..815aac9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f33/s2i-core:latest +FROM registry.fedoraproject.org/f34/s2i-core:latest ENV SUMMARY="Base image with essential libraries and tools used as a base for \ builder images like perl, python, ruby, etc." \ From 888171c1893f17346ebdee284368ed56e8ff30ff Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 8 Jul 2025 17:40:41 +0200 Subject: [PATCH 30/30] container sources not used for building fedora containers anymore --- .gitignore | 0 Dockerfile | 50 --------------- Dockerfile.fedora | 1 - README.md | 106 -------------------------------- base | 1 - bot-cfg.yml | 26 -------- dead.package | 1 + help.md | 1 - root/help.1 | 153 ---------------------------------------------- test/run | 26 -------- 10 files changed, 1 insertion(+), 364 deletions(-) delete mode 100644 .gitignore delete mode 100644 Dockerfile delete mode 120000 Dockerfile.fedora delete mode 100644 README.md delete mode 120000 base delete mode 100644 bot-cfg.yml create mode 100644 dead.package delete mode 120000 help.md delete mode 100644 root/help.1 delete mode 100755 test/run diff --git a/.gitignore b/.gitignore deleted file mode 100644 index e69de29..0000000 diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 815aac9..0000000 --- a/Dockerfile +++ /dev/null @@ -1,50 +0,0 @@ -# This image is the base image for all OpenShift v3 language container images. -FROM registry.fedoraproject.org/f34/s2i-core:latest - -ENV SUMMARY="Base image with essential libraries and tools used as a base for \ -builder images like perl, python, ruby, etc." \ - DESCRIPTION="The s2i-base image, being built upon s2i-core, provides any \ -images layered on top of it with all the tools needed to use source-to-image \ -functionality. Additionally, s2i-base also contains various libraries needed for \ -it to serve as a base for other builder images, like s2i-python or s2i-ruby." \ - NAME=s2i-base \ - VERSION=1 \ - ARCH=x86_64 - -LABEL summary="$SUMMARY" \ - description="$DESCRIPTION" \ - io.k8s.description="$DESCRIPTION" \ - io.k8s.display-name="s2i base" \ - com.redhat.component="$NAME" \ - name="$FGC/$NAME" \ - version="$VERSION" \ - maintainer="SoftwareCollections.org " - -# This is the list of basic dependencies that all language container image can -# consume. -RUN INSTALL_PKGS="autoconf \ - automake \ - bzip2 \ - gcc-c++ \ - gd-devel \ - gdb \ - git \ - libcurl-devel \ - libpq-devel \ - libxml2-devel \ - libxslt-devel \ - lsof \ - make \ - mariadb-connector-c-devel \ - npm \ - openssl-devel \ - patch \ - procps-ng \ - sqlite-devel \ - unzip \ - wget \ - which \ - zlib-devel" && \ - dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ - rpm -V $INSTALL_PKGS && \ - dnf clean all -y diff --git a/Dockerfile.fedora b/Dockerfile.fedora deleted file mode 120000 index 1d1fe94..0000000 --- a/Dockerfile.fedora +++ /dev/null @@ -1 +0,0 @@ -Dockerfile \ No newline at end of file diff --git a/README.md b/README.md deleted file mode 100644 index 7b4156a..0000000 --- a/README.md +++ /dev/null @@ -1,106 +0,0 @@ -OpenShift base images -======================================== - -This repository contains Dockerfiles for images which serve as base images with all the -essential libraries and tools needed for OpenShift language images, for example: - -* [s2i-ruby](https://github.com/sclorg/s2i-ruby-container) -* [s2i-nodejs](https://github.com/sclorg/s2i-nodejs-container) -* [s2i-python](https://github.com/sclorg/s2i-python-container) -* [s2i-perl](https://github.com/sclorg/s2i-perl-container) -* [s2i-php](https://github.com/sclorg/s2i-php-container) - -This container image also installs several development libraries, that are -often required in the builder images above. It also includes NPM package manager. -Sharing those development packages in a common layer saves disk space and -improves pulling speed. - -NPM, a package manager for Node.js, offers a pleasant way to install JavaScript -libraries, that are often needed as static files for various web applications. -In order to offer good experience for web developers, the NPM package manager -is also installed in the image. - -For containers where the development libraries and NPM package manager are not -necessary, users are advised to use the s2i-core variant of this container image. - - -Description ------------ - -OpenShift S2I images use [Software Collections](https://www.softwarecollections.org/en/) -packages to provide the latest versions of various software. -The SCL packages are released more frequently than the RHEL or CentOS systems, -which are unlikely to change for several years. -We rely on RHEL and CentOS for base images, on the other hand, -because those are stable, supported, and secure platforms. - -Normally, SCL requires manual operation to enable the collection you want to use. -This is burdensome and can be prone to error. -The OpenShift S2I approach is to set Bash environment variables that -serve to automatically enable the desired collection: - -* `BASH_ENV`: enables the collection for all non-interactive Bash sessions -* `ENV`: enables the collection for all invocations of `/bin/sh` -* `PROMPT_COMMAND`: enables the collection in interactive shell - -Two examples: -* If you specify `BASH_ENV`, then all your `#!/bin/bash` scripts -do not need to call `scl enable`. -* If you specify `PROMPT_COMMAND`, then on execution of the -`podman exec ... /bin/bash` command, the collection will be automatically enabled. - -*Note*: -Executables in Software Collections packages (e.g., `ruby`) -are not directly in a directory named in the `PATH` environment variable. -This means that you cannot do: - - $ podman exec ... ruby - -but must instead do: - - $ podman exec ... /bin/bash -c ruby - -The `/bin/bash -c`, along with the setting the appropriate environment variable, -ensures the correct `ruby` executable is found and invoked. - -Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments - -Usage ------------------------- -Choose either the CentOS7 or RHEL7 base image: -* **RHEL7 base image** - -To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. - -``` -$ git clone --recursive https://github.com/sclorg/s2i-base-container.git -$ cd s2i-base-container -$ make build VERSIONS=base TARGET=rhel7 -``` - -* **CentOS7 base image** - -This image is available on DockerHub. To download it run: - -```console -podman pull sclorg/s2i-base-centos7 -``` - -To build a Base image from scratch run: - -``` -$ git clone --recursive https://github.com/sclorg/s2i-base-container.git -$ cd s2i-base-container -$ make build VERSIONS=base -``` - -**Notice: By omitting the `VERSION` parameter, the build/test action will be performed -on all provided versions of s2i image.** - - -See also --------- -Dockerfile and other sources are available on https://github.com/sclorg/s2i-base-container. -In that repository you also can find another variants of S2I base Dockerfiles. -The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7, -the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora. diff --git a/base b/base deleted file mode 120000 index 945c9b4..0000000 --- a/base +++ /dev/null @@ -1 +0,0 @@ -. \ No newline at end of file diff --git a/bot-cfg.yml b/bot-cfg.yml deleted file mode 100644 index 6067f0e..0000000 --- a/bot-cfg.yml +++ /dev/null @@ -1,26 +0,0 @@ -version: "1" - -betka: - # is betka enabled for this repository - # optional - defaults to false - enabled: true - - # optional - notifications: - email_addresses: [phracek@redhat.com] - - # Specify if master branch in upstream repository is synced - master_checker: true - # Should pull requests be synced? - # optional - pr_checker: false - # Either 'upstream_branch_name' or 'upstream_git_path' has to be specified - # Branch name which is used for sync - upstream_branch_name: master - # Path to directory with dockerfile withing upstream repository - upstream_git_path: "base" - # Github comment message to enforce sync of a pull request - # required if pr_checker is true otherwise optional - pr_comment_message: "[test]" - # optional - image_url: quay.io/rhscl/cwt-generator diff --git a/dead.package b/dead.package new file mode 100644 index 0000000..7290702 --- /dev/null +++ b/dead.package @@ -0,0 +1 @@ +container sources not used for building fedora containers anymore diff --git a/help.md b/help.md deleted file mode 120000 index 42061c0..0000000 --- a/help.md +++ /dev/null @@ -1 +0,0 @@ -README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 deleted file mode 100644 index 887acd7..0000000 --- a/root/help.1 +++ /dev/null @@ -1,153 +0,0 @@ -.TH OpenShift base images -.PP -This repository contains Dockerfiles for images which serve as base images with all the -essential libraries and tools needed for OpenShift language images, for example: -.IP \(bu 2 -s2i\-ruby -\[la]https://github.com/sclorg/s2i-ruby-container\[ra] -.IP \(bu 2 -s2i\-nodejs -\[la]https://github.com/sclorg/s2i-nodejs-container\[ra] -.IP \(bu 2 -s2i\-python -\[la]https://github.com/sclorg/s2i-python-container\[ra] -.IP \(bu 2 -s2i\-perl -\[la]https://github.com/sclorg/s2i-perl-container\[ra] -.IP \(bu 2 -s2i\-php -\[la]https://github.com/sclorg/s2i-php-container\[ra] - -.PP -This container image also installs several development libraries, that are -often required in the builder images above. It also includes NPM package manager. -Sharing those development packages in a common layer saves disk space and -improves pulling speed. - -.PP -NPM, a package manager for Node.js, offers a pleasant way to install JavaScript -libraries, that are often needed as static files for various web applications. -In order to offer good experience for web developers, the NPM package manager -is also installed in the image. - -.PP -For containers where the development libraries and NPM package manager are not -necessary, users are advised to use the s2i\-core variant of this container image. - -.SH Description -.PP -OpenShift S2I images use Software Collections -\[la]https://www.softwarecollections.org/en/\[ra] -packages to provide the latest versions of various software. -The SCL packages are released more frequently than the RHEL or CentOS systems, -which are unlikely to change for several years. -We rely on RHEL and CentOS for base images, on the other hand, -because those are stable, supported, and secure platforms. - -.PP -Normally, SCL requires manual operation to enable the collection you want to use. -This is burdensome and can be prone to error. -The OpenShift S2I approach is to set Bash environment variables that -serve to automatically enable the desired collection: -.IP \(bu 2 -\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions -.IP \(bu 2 -\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR -.IP \(bu 2 -\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell - -.PP -Two examples: -* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts -do not need to call \fB\fCscl enable\fR\&. -* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the -\fB\fCdocker exec ... /bin/bash\fR command, the collection will be automatically enabled. - -.PP -\fINote\fP: -Executables in Software Collections packages (e.g., \fB\fCruby\fR) -are not directly in a directory named in the \fB\fCPATH\fR environment variable. -This means that you cannot do: - -.PP -.RS - -.nf -$ docker exec ... ruby - -.fi -.RE - -.PP -but must instead do: - -.PP -.RS - -.nf -$ docker exec ... /bin/bash \-c ruby - -.fi -.RE - -.PP -The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable, -ensures the correct \fB\fCruby\fR executable is found and invoked. - -.SH Usage -.PP -Choose either the CentOS7 or RHEL7 base image: -* \fBRHEL7 base image\fP - -.PP -To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine. - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=base TARGET=rhel7 - -.fi -.RE -.IP \(bu 2 -\fBCentOS7 base image\fP - -.PP -This image is available on DockerHub. To download it run: - -.PP -.RS - -.nf -docker pull sclorg/s2i\-base\-centos7 - -.fi -.RE - -.PP -To build a Base image from scratch run: - -.PP -.RS - -.nf -$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git -$ cd s2i\-base\-container -$ make build VERSIONS=base - -.fi -.RE - -.PP -\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed -on all provided versions of s2i image.\fP - -.SH See also -.PP -Dockerfile and other sources are available on -\[la]https://github.com/sclorg/s2i-base-container\[ra]\&. -In that repository you also can find another variants of S2I base Dockerfiles. -Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7. diff --git a/test/run b/test/run deleted file mode 100755 index a745d6d..0000000 --- a/test/run +++ /dev/null @@ -1,26 +0,0 @@ -#!/bin/bash -# -# The 'run' performs a simple test that verifies that STI image. -# The main focus is that the image prints out the base-usage properly. -# -# IMAGE_NAME specifies a name of the candidate image used for testing. -# The image has to be available before this script is executed. -# -IMAGE_NAME=${IMAGE_NAME-centos/s2i-base-centos7-candidate} - -test_docker_run_usage() { - echo "Testing 'docker run' usage..." - docker run --rm ${IMAGE_NAME} &>/dev/null -} - -check_result() { - local result="$1" - if [[ "$result" != "0" ]]; then - echo "STI image '${IMAGE_NAME}' test FAILED (exit code: ${result})" - exit $result - fi -} - -# Verify the 'usage' script is working properly when running the base image with 'docker run ...' -test_docker_run_usage -check_result $?