Compare commits

..

1 commit

Author SHA1 Message Date
Petr Kubat
c77c5cbcde Pull changes from upstream and rebase for: rebuild for latest f30 2019-04-10 09:27:06 +02:00
15 changed files with 540 additions and 1 deletions

69
Dockerfile Normal file
View file

@ -0,0 +1,69 @@
# This image is the base image for all s2i configurable container images.
FROM registry.fedoraproject.org/fedora:30
ENV SUMMARY="Base image which allows using of source-to-image." \
DESCRIPTION="The s2i-core image provides any images layered on top of it \
with all the tools needed to use source-to-image functionality while keeping \
the image size as small as possible." \
NAME=s2i-core \
VERSION=0 \
ARCH=x86_64
LABEL summary="$SUMMARY" \
description="$DESCRIPTION" \
io.k8s.description="$DESCRIPTION" \
io.k8s.display-name="s2i core" \
io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \
io.s2i.scripts-url=image:///usr/libexec/s2i \
com.redhat.component="$NAME" \
name="$FGC/$NAME" \
version="$VERSION" \
usage="This image is supposed to be used as a base image for other images that support source-to-image" \
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
ENV \
# DEPRECATED: Use above LABEL instead, because this will be removed in future versions.
STI_SCRIPTS_URL=image:///usr/libexec/s2i \
# Path to be used in other layers to place s2i scripts into
STI_SCRIPTS_PATH=/usr/libexec/s2i \
APP_ROOT=/opt/app-root \
# The $HOME is not set by default, but some applications needs this variable
HOME=/opt/app-root/src \
PATH=/opt/app-root/src/bin:/opt/app-root/bin:$PATH \
PLATFORM="fedora"
# This is the list of basic dependencies that all language container image can
# consume.
# Also setup the 'openshift' user that is used for the build execution and for the
# application runtime execution.
# TODO: Use better UID and GID values
RUN INSTALL_PKGS="bsdtar \
findutils \
gettext \
groff-base \
tar \
unzip" && \
mkdir -p ${HOME}/.pki/nssdb && \
chown -R 1001:0 ${HOME}/.pki && \
dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \
rpm -V $INSTALL_PKGS && \
dnf clean all -y
# Copy extra files to the image.
COPY ./root/ /
# Create a platform-python symlink if it does not exist already
RUN [ -e /usr/libexec/platform-python ] || ln -s /usr/libexec/system-python /usr/libexec/platform-python
# Directory with the sources is set as the working directory so all STI scripts
# can execute relative to this path.
WORKDIR ${HOME}
ENTRYPOINT ["container-entrypoint"]
CMD ["base-usage"]
# Reset permissions of modified directories and add default user
RUN rpm-file-permissions && \
useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \
-c "Default Application User" default && \
chown -R 1001:0 ${APP_ROOT}

1
Dockerfile.fedora Symbolic link
View file

@ -0,0 +1 @@
Dockerfile

87
README.md Normal file
View file

@ -0,0 +1,87 @@
OpenShift base images (core variant)
========================================
This repository contains Dockerfiles for images which can be used as base images
to add support for [source-to-image](https://github.com/openshift/source-to-image)
without installing several development libraries.
Description
--------------------------------
OpenShift S2I images use [Software Collections](https://www.softwarecollections.org/en/)
packages to provide the latest versions of various software.
The SCL packages are released more frequently than the RHEL or CentOS systems,
which are unlikely to change for several years.
We rely on RHEL and CentOS for base images, on the other hand,
because those are stable, supported, and secure platforms.
Normally, SCL requires manual operation to enable the collection you want to use.
This is burdensome and can be prone to error.
The OpenShift S2I approach is to set Bash environment variables that
serve to automatically enable the desired collection:
* `BASH_ENV`: enables the collection for all non-interactive Bash sessions
* `ENV`: enables the collection for all invocations of `/bin/sh`
* `PROMPT_COMMAND`: enables the collection in interactive shell
Two examples:
* If you specify `BASH_ENV`, then all your `#!/bin/bash` scripts
do not need to call `scl enable`.
* If you specify `PROMPT_COMMAND`, then on execution of the
`podman exec ... /bin/bash` command, the collection will be automatically enabled.
*Note*:
Executables in Software Collections packages (e.g., `ruby`)
are not directly in a directory named in the `PATH` environment variable.
This means that you cannot do:
$ podman exec <cid> ... ruby
but must instead do:
$ podman exec <cid> ... /bin/bash -c ruby
The `/bin/bash -c`, along with the setting the appropriate environment variable,
ensures the correct `ruby` executable is found and invoked.
Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments
Usage
------------------------
Choose either the CentOS7 or RHEL7 base image:
* **RHEL7 base image**
To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine.
```
$ git clone --recursive https://github.com/sclorg/s2i-base-container.git
$ cd s2i-base-container
$ make build VERSIONS=core TARGET=rhel7
```
* **CentOS7 base image**
This image is available on DockerHub. To download it run:
```console
podman pull sclorg/s2i-core-centos7
```
To build a Base image from scratch run:
```
$ git clone --recursive https://github.com/sclorg/s2i-base-container.git
$ cd s2i-base-container
$ make build VERSIONS=core
```
**Notice: By omitting the `VERSION` parameter, the build/test action will be performed
on all provided versions of s2i image.**
See also
--------
Dockerfile and other sources are available on https://github.com/sclorg/s2i-base-container.
In that repository you also can find another variants of S2I Base Dockerfiles.
The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7,
the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora.

1
core Symbolic link
View file

@ -0,0 +1 @@
.

View file

@ -1 +0,0 @@
container sources not used for building fedora containers anymore

1
help.md Symbolic link
View file

@ -0,0 +1 @@
README.md

128
root/help.1 Normal file
View file

@ -0,0 +1,128 @@
.TH OpenShift base images (core variant)
.PP
This repository contains Dockerfiles for images which can be used as base images
to add support for source\-to\-image
\[la]https://github.com/openshift/source-to-image\[ra]
without installing several development libraries.
.SH Description
.PP
OpenShift S2I images use Software Collections
\[la]https://www.softwarecollections.org/en/\[ra]
packages to provide the latest versions of various software.
The SCL packages are released more frequently than the RHEL or CentOS systems,
which are unlikely to change for several years.
We rely on RHEL and CentOS for base images, on the other hand,
because those are stable, supported, and secure platforms.
.PP
Normally, SCL requires manual operation to enable the collection you want to use.
This is burdensome and can be prone to error.
The OpenShift S2I approach is to set Bash environment variables that
serve to automatically enable the desired collection:
.IP \(bu 2
\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions
.IP \(bu 2
\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR
.IP \(bu 2
\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell
.PP
Two examples:
* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts
do not need to call \fB\fCscl enable\fR\&.
* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the
\fB\fCpodman exec ... /bin/bash\fR command, the collection will be automatically enabled.
.PP
\fINote\fP:
Executables in Software Collections packages (e.g., \fB\fCruby\fR)
are not directly in a directory named in the \fB\fCPATH\fR environment variable.
This means that you cannot do:
.PP
.RS
.nf
$ podman exec <cid> ... ruby
.fi
.RE
.PP
but must instead do:
.PP
.RS
.nf
$ podman exec <cid> ... /bin/bash \-c ruby
.fi
.RE
.PP
The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable,
ensures the correct \fB\fCruby\fR executable is found and invoked.
.PP
Note: while the examples in this README are calling \fB\fCpodman\fR, you can replace any such calls by \fB\fCdocker\fR with the same arguments
.SH Usage
.PP
Choose either the CentOS7 or RHEL7 base image:
* \fBRHEL7 base image\fP
.PP
To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine.
.PP
.RS
.nf
$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git
$ cd s2i\-base\-container
$ make build VERSIONS=core TARGET=rhel7
.fi
.RE
.IP \(bu 2
\fBCentOS7 base image\fP
.PP
This image is available on DockerHub. To download it run:
.PP
.RS
.nf
podman pull sclorg/s2i\-core\-centos7
.fi
.RE
.PP
To build a Base image from scratch run:
.PP
.RS
.nf
$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git
$ cd s2i\-base\-container
$ make build VERSIONS=core
.fi
.RE
.PP
\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed
on all provided versions of s2i image.\fP
.SH See also
.PP
Dockerfile and other sources are available on
\[la]https://github.com/sclorg/s2i-base-container\[ra]\&.
In that repository you also can find another variants of S2I Base Dockerfiles.
The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7,
the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora.

View file

@ -0,0 +1,2 @@
# This file contains automatic SCL enablement.
unset BASH_ENV PROMPT_COMMAND ENV

24
root/usr/bin/base-usage Executable file
View file

@ -0,0 +1,24 @@
#!/bin/sh -e
cat <<EOF
This image serves as the base image for all OpenShift v3 S2I builder images.
It provides all essential libraries and development tools needed to
successfully build and run an application.
To use this image as a base image, you need to have 's2i/bin' directory in the
same directory as your S2I image Dockerfile. This directory should contain S2I
scripts.
This base image also provides the default user you should use to run your
application. Your Dockerfile should include this instruction after you finish
installing software:
USER default
The default directory for installing your application sources is
'/opt/app-root/src' and the WORKDIR and HOME for the 'default' user is set
to this directory as well. In your S2I scripts, you don't have to use absolute
path, but rather rely on the relative path.
To learn more about S2I visit: https://github.com/openshift/source-to-image
EOF

92
root/usr/bin/cgroup-limits Executable file
View file

@ -0,0 +1,92 @@
#!/usr/libexec/platform-python
"""
Script for parsing cgroup information
This script will read some limits from the cgroup system and parse
them, printing out "VARIABLE=VALUE" on each line for every limit that is
successfully read. Output of this script can be directly fed into
bash's export command. Recommended usage from a bash script:
set -o errexit
export_vars=$(cgroup-limits) ; export $export_vars
Variables currently supported:
MAX_MEMORY_LIMIT_IN_BYTES
Maximum possible limit MEMORY_LIMIT_IN_BYTES can have. This is
currently constant value of 9223372036854775807.
MEMORY_LIMIT_IN_BYTES
Maximum amount of user memory in bytes. If this value is set
to the same value as MAX_MEMORY_LIMIT_IN_BYTES, it means that
there is no limit set. The value is taken from
/sys/fs/cgroup/memory/memory.limit_in_bytes
NUMBER_OF_CORES
Number of detected CPU cores that can be used. This value is
calculated from /sys/fs/cgroup/cpuset/cpuset.cpus
NO_MEMORY_LIMIT
Set to "true" if MEMORY_LIMIT_IN_BYTES is so high that the caller
can act as if no memory limit was set. Undefined otherwise.
"""
from __future__ import print_function
import sys
def _read_file(path):
try:
with open(path, 'r') as f:
return f.read().strip()
except IOError:
return None
def get_memory_limit():
"""
Read memory limit, in bytes.
"""
limit = _read_file('/sys/fs/cgroup/memory/memory.limit_in_bytes')
if limit is None or not limit.isdigit():
print("Warning: Can't detect memory limit from cgroups",
file=sys.stderr)
return None
return int(limit)
def get_number_of_cores():
"""
Read number of CPU cores.
"""
core_count = 0
line = _read_file('/sys/fs/cgroup/cpuset/cpuset.cpus')
if line is None:
print("Warning: Can't detect number of CPU cores from cgroups",
file=sys.stderr)
return None
for group in line.split(','):
core_ids = list(map(int, group.split('-')))
if len(core_ids) == 2:
core_count += core_ids[1] - core_ids[0] + 1
else:
core_count += 1
return core_count
if __name__ == "__main__":
env_vars = {
"MAX_MEMORY_LIMIT_IN_BYTES": 9223372036854775807,
"MEMORY_LIMIT_IN_BYTES": get_memory_limit(),
"NUMBER_OF_CORES": get_number_of_cores()
}
env_vars = {k: v for k, v in env_vars.items() if v is not None}
if env_vars.get("MEMORY_LIMIT_IN_BYTES", 0) >= 92233720368547:
env_vars["NO_MEMORY_LIMIT"] = "true"
for key, value in env_vars.items():
print("{0}={1}".format(key, value))

View file

@ -0,0 +1,2 @@
#!/bin/bash
exec "$@"

27
root/usr/bin/fix-permissions Executable file
View file

@ -0,0 +1,27 @@
#!/bin/sh
# Allow this script to fail without failing a build
set +e
SYMLINK_OPT=${2:--L}
# Fix permissions on the given directory or file to allow group read/write of
# regular files and execute of directories.
[ $(id -u) -ne 0 ] && CHECK_OWNER=" -uid $(id -u)"
# If argument does not exist, script will still exit with 0,
# but at least we'll see something went wrong in the log
if ! [ -e "$1" ] ; then
echo "ERROR: File or directory $1 does not exist." >&2
# We still want to end successfully
exit 0
fi
find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -gid 0 -exec chgrp 0 {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -perm -g+rw -exec chmod g+rw {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} -perm /u+x -a \! -perm /g+x -exec chmod g+x {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} -type d \! -perm /g+x -exec chmod g+x {} +
# Always end successfully
exit 0

View file

@ -0,0 +1,59 @@
#!/bin/bash
# This script is used to prepare yum repositories, that are given as arguments.
# It is no-op if user also mounts the repo file(s) into the container during
# image build. This can be done by one of those commands:
#
# docker build -v /some/repo/file:/etc/yum.repos.d/sclorg_custom.repo
# docker build -v /some/repo/directory:/etc/yum.repos.d
# make CUSTOM_REPO=/some/repo/file/or/directory
#
# The last one works for projects where we have Makefile with the
# container-common-scripts support.
set -ex
# DEFAULT_REPOS and SKIP_REPOS_{ENABLE,DISABLE} are intentionally undocumented,
# but might be used if we need to change this behaviour.
# Once we realize there are real use cases for using those variables, we should
# document them properly.
DEFAULT_REPOS=${DEFAULT_REPOS:-"rhel-7-server-rpms rhel-7-server-optional-rpms"}
SKIP_REPOS_ENABLE=${SKIP_REPOS_ENABLE:-false}
SKIP_REPOS_DISABLE=${SKIP_REPOS_DISABLE:-false}
function is_subscribed() {
for f in /run/secrets/etc-pki-entitlement/*.pem ; do
[ -e "$f" ] && return 0
break
done
return 1
}
# DEBUGGING CASE! Mostly for 'make CUSTOM_REPO=/some/file/or/dir'.
test ! -f /etc/yum.repos.d/sclorg_custom.repo && \
! mountpoint /etc/yum.repos.d \
|| exit 0
# install yum-utils for yum-config-manager
yum install -y yum-utils
if [ "$SKIP_REPOS_DISABLE" = false ] && is_subscribed; then
# Disable only repos that might come from subscribed host, because there
# might be other repos provided by user or build system
disable_repos=
# Lines look like: "Repo-id : dist-tag-override/x86_64"
while IFS=' /' read -r _ _ repo_id _; do
case $repo_id in rhel-*)
disable_repos+=" $repo_id" ;;
esac
done <<<"$(yum repolist -v 2>/dev/null | grep Repo-id)"
if test -n "$disable_repos"; then
yum-config-manager --disable $disable_repos &> /dev/null
fi
fi
if [ ${SKIP_REPOS_ENABLE} = false ] && [ -n "${DEFAULT_REPOS}" -o $# -gt 0 ] ; then
yum-config-manager --enable ${DEFAULT_REPOS} "$@"
fi

View file

@ -0,0 +1,21 @@
#!/bin/sh
CHECK_DIRS="/ /opt /etc /usr /usr/bin /usr/lib /usr/lib64 /usr/share /usr/libexec"
rpm_format="[%{FILESTATES:fstate} %7{FILEMODES:octal} %{FILENAMES:shescape}\n]"
rpm -q --qf "$rpm_format" filesystem | while read line
do
eval "set -- $line"
case $1 in
normal) ;;
*) continue ;;
esac
case " $CHECK_DIRS " in
*" $3 "*)
chmod "${2: -4}" "$3"
;;
esac
done

26
test/run Executable file
View file

@ -0,0 +1,26 @@
#!/bin/bash
#
# The 'run' performs a simple test that verifies that STI image.
# The main focus is that the image prints out the base-usage properly.
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
IMAGE_NAME=${IMAGE_NAME-centos/s2i-core-centos7-candidate}
test_docker_run_usage() {
echo "Testing 'docker run' usage..."
docker run --rm ${IMAGE_NAME} &>/dev/null
}
check_result() {
local result="$1"
if [[ "$result" != "0" ]]; then
echo "STI image '${IMAGE_NAME}' test FAILED (exit code: ${result})"
exit $result
fi
}
# Verify the 'usage' script is working properly when running the base image with 'docker run ...'
test_docker_run_usage
check_result $?