Compare commits

..

6 commits

Author SHA1 Message Date
Lumir Balhar
e4ca616d3f Update from the upstream Github repository 2020-11-25 11:33:58 +01:00
Lumir Balhar
0e8c5ef59c Update from upstream Github repository 2020-07-16 07:28:20 +02:00
Lumir Balhar
eb12462323 Revert "Temporary fix for OSBS tags"
This reverts commit 344dc9a034.
2020-07-16 07:27:13 +02:00
Lumir Balhar
344dc9a034 Temporary fix for OSBS tags 2020-07-16 07:18:34 +02:00
Petr "Stone" Hracek
fb5d633b7d Add Sync upstream s2i-core repository to Fedora land
Signed-off-by: Petr "Stone" Hracek <phracek@redhat.com>
2020-04-14 17:00:18 +02:00
Lumir Balhar
899a09a024 Update from upstream and switch to branched F32 2020-03-06 10:25:57 +01:00
16 changed files with 642 additions and 1 deletions

71
Dockerfile Normal file
View file

@ -0,0 +1,71 @@
# This image is the base image for all s2i configurable container images.
FROM registry.fedoraproject.org/fedora:32
ENV SUMMARY="Base image which allows using of source-to-image." \
DESCRIPTION="The s2i-core image provides any images layered on top of it \
with all the tools needed to use source-to-image functionality while keeping \
the image size as small as possible." \
NAME=s2i-core \
VERSION=0 \
ARCH=x86_64
LABEL summary="$SUMMARY" \
description="$DESCRIPTION" \
io.k8s.description="$DESCRIPTION" \
io.k8s.display-name="s2i core" \
io.openshift.s2i.scripts-url=image:///usr/libexec/s2i \
io.s2i.scripts-url=image:///usr/libexec/s2i \
com.redhat.component="$NAME" \
name="$FGC/$NAME" \
version="$VERSION" \
usage="This image is supposed to be used as a base image for other images that support source-to-image" \
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
ENV \
# DEPRECATED: Use above LABEL instead, because this will be removed in future versions.
STI_SCRIPTS_URL=image:///usr/libexec/s2i \
# Path to be used in other layers to place s2i scripts into
STI_SCRIPTS_PATH=/usr/libexec/s2i \
APP_ROOT=/opt/app-root \
# The $HOME is not set by default, but some applications needs this variable
HOME=/opt/app-root/src \
PATH=/opt/app-root/src/bin:/opt/app-root/bin:$PATH \
PLATFORM="fedora"
# This is the list of basic dependencies that all language container image can
# consume.
# Also setup the 'openshift' user that is used for the build execution and for the
# application runtime execution.
# TODO: Use better UID and GID values
RUN INSTALL_PKGS="bsdtar \
findutils \
gettext \
glibc-langpack-en \
groff-base \
rsync \
tar \
unzip" && \
mkdir -p ${HOME}/.pki/nssdb && \
chown -R 1001:0 ${HOME}/.pki && \
dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \
rpm -V $INSTALL_PKGS && \
dnf clean all -y
# Copy extra files to the image.
COPY ./root/ /
# Create a platform-python symlink if it does not exist already
RUN [ -e /usr/libexec/platform-python ] || ln -s /usr/bin/python3 /usr/libexec/platform-python
# Directory with the sources is set as the working directory so all STI scripts
# can execute relative to this path.
WORKDIR ${HOME}
ENTRYPOINT ["container-entrypoint"]
CMD ["base-usage"]
# Reset permissions of modified directories and add default user
RUN rpm-file-permissions && \
useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \
-c "Default Application User" default && \
chown -R 1001:0 ${APP_ROOT}

1
Dockerfile.fedora Symbolic link
View file

@ -0,0 +1 @@
Dockerfile

87
README.md Normal file
View file

@ -0,0 +1,87 @@
OpenShift base images (core variant)
========================================
This repository contains Dockerfiles for images which can be used as base images
to add support for [source-to-image](https://github.com/openshift/source-to-image)
without installing several development libraries.
Description
--------------------------------
OpenShift S2I images use [Software Collections](https://www.softwarecollections.org/en/)
packages to provide the latest versions of various software.
The SCL packages are released more frequently than the RHEL or CentOS systems,
which are unlikely to change for several years.
We rely on RHEL and CentOS for base images, on the other hand,
because those are stable, supported, and secure platforms.
Normally, SCL requires manual operation to enable the collection you want to use.
This is burdensome and can be prone to error.
The OpenShift S2I approach is to set Bash environment variables that
serve to automatically enable the desired collection:
* `BASH_ENV`: enables the collection for all non-interactive Bash sessions
* `ENV`: enables the collection for all invocations of `/bin/sh`
* `PROMPT_COMMAND`: enables the collection in interactive shell
Two examples:
* If you specify `BASH_ENV`, then all your `#!/bin/bash` scripts
do not need to call `scl enable`.
* If you specify `PROMPT_COMMAND`, then on execution of the
`podman exec ... /bin/bash` command, the collection will be automatically enabled.
*Note*:
Executables in Software Collections packages (e.g., `ruby`)
are not directly in a directory named in the `PATH` environment variable.
This means that you cannot do:
$ podman exec <cid> ... ruby
but must instead do:
$ podman exec <cid> ... /bin/bash -c ruby
The `/bin/bash -c`, along with the setting the appropriate environment variable,
ensures the correct `ruby` executable is found and invoked.
Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments
Usage
------------------------
Choose either the CentOS7 or RHEL7 base image:
* **RHEL7 base image**
To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine.
```
$ git clone --recursive https://github.com/sclorg/s2i-base-container.git
$ cd s2i-base-container
$ make build VERSIONS=core TARGET=rhel7
```
* **CentOS7 base image**
This image is available on Quay.io. To download it run:
```console
podman pull quay.io/centos7/s2i-core-centos7
```
To build a Base image from scratch run:
```
$ git clone --recursive https://github.com/sclorg/s2i-base-container.git
$ cd s2i-base-container
$ make build VERSIONS=core
```
**Notice: By omitting the `VERSION` parameter, the build/test action will be performed
on all provided versions of s2i image.**
See also
--------
Dockerfile and other sources are available on https://github.com/sclorg/s2i-base-container.
In that repository you also can find another variants of S2I Base Dockerfiles.
The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7,
the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora.

26
bot-cfg.yml Normal file
View file

@ -0,0 +1,26 @@
version: "1"
betka:
# is betka enabled for this repository
# optional - defaults to false
enabled: true
# optional
notifications:
email_addresses: [phracek@redhat.com]
# Specify if master branch in upstream repository is synced
master_checker: true
# Should pull requests be synced?
# optional
pr_checker: false
# Either 'upstream_branch_name' or 'upstream_git_path' has to be specified
# Branch name which is used for sync
upstream_branch_name: master
# Path to directory with dockerfile withing upstream repository
upstream_git_path: "core"
# Github comment message to enforce sync of a pull request
# required if pr_checker is true otherwise optional
pr_comment_message: "[test]"
# optional
image_url: quay.io/rhscl/cwt-generator

1
core Symbolic link
View file

@ -0,0 +1 @@
.

View file

@ -1 +0,0 @@
container sources not used for building fedora containers anymore

1
help.md Symbolic link
View file

@ -0,0 +1 @@
README.md

128
root/help.1 Normal file
View file

@ -0,0 +1,128 @@
.TH OpenShift base images (core variant)
.PP
This repository contains Dockerfiles for images which can be used as base images
to add support for source\-to\-image
\[la]https://github.com/openshift/source-to-image\[ra]
without installing several development libraries.
.SH Description
.PP
OpenShift S2I images use Software Collections
\[la]https://www.softwarecollections.org/en/\[ra]
packages to provide the latest versions of various software.
The SCL packages are released more frequently than the RHEL or CentOS systems,
which are unlikely to change for several years.
We rely on RHEL and CentOS for base images, on the other hand,
because those are stable, supported, and secure platforms.
.PP
Normally, SCL requires manual operation to enable the collection you want to use.
This is burdensome and can be prone to error.
The OpenShift S2I approach is to set Bash environment variables that
serve to automatically enable the desired collection:
.IP \(bu 2
\fB\fCBASH\_ENV\fR: enables the collection for all non\-interactive Bash sessions
.IP \(bu 2
\fB\fCENV\fR: enables the collection for all invocations of \fB\fC/bin/sh\fR
.IP \(bu 2
\fB\fCPROMPT\_COMMAND\fR: enables the collection in interactive shell
.PP
Two examples:
* If you specify \fB\fCBASH\_ENV\fR, then all your \fB\fC#!/bin/bash\fR scripts
do not need to call \fB\fCscl enable\fR\&.
* If you specify \fB\fCPROMPT\_COMMAND\fR, then on execution of the
\fB\fCpodman exec ... /bin/bash\fR command, the collection will be automatically enabled.
.PP
\fINote\fP:
Executables in Software Collections packages (e.g., \fB\fCruby\fR)
are not directly in a directory named in the \fB\fCPATH\fR environment variable.
This means that you cannot do:
.PP
.RS
.nf
$ podman exec <cid> ... ruby
.fi
.RE
.PP
but must instead do:
.PP
.RS
.nf
$ podman exec <cid> ... /bin/bash \-c ruby
.fi
.RE
.PP
The \fB\fC/bin/bash \-c\fR, along with the setting the appropriate environment variable,
ensures the correct \fB\fCruby\fR executable is found and invoked.
.PP
Note: while the examples in this README are calling \fB\fCpodman\fR, you can replace any such calls by \fB\fCdocker\fR with the same arguments
.SH Usage
.PP
Choose either the CentOS7 or RHEL7 base image:
* \fBRHEL7 base image\fP
.PP
To build a RHEL7 based image, you need to build it on properly subscribed RHEL machine.
.PP
.RS
.nf
$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git
$ cd s2i\-base\-container
$ make build VERSIONS=core TARGET=rhel7
.fi
.RE
.IP \(bu 2
\fBCentOS7 base image\fP
.PP
This image is available on DockerHub. To download it run:
.PP
.RS
.nf
podman pull sclorg/s2i\-core\-centos7
.fi
.RE
.PP
To build a Base image from scratch run:
.PP
.RS
.nf
$ git clone \-\-recursive https://github.com/sclorg/s2i\-base\-container.git
$ cd s2i\-base\-container
$ make build VERSIONS=core
.fi
.RE
.PP
\fBNotice: By omitting the \fB\fCVERSION\fR parameter, the build/test action will be performed
on all provided versions of s2i image.\fP
.SH See also
.PP
Dockerfile and other sources are available on
\[la]https://github.com/sclorg/s2i-base-container\[ra]\&.
In that repository you also can find another variants of S2I Base Dockerfiles.
The Dockerfile for CentOS is called Dockerfile, the Dockerfile for RHEL7 is called Dockerfile.rhel7,
the Dockerfile for RHEL8 is called Dockerfile.rhel8 and the Dockerfile for Fedora is Dockerfile.fedora.

View file

@ -0,0 +1,2 @@
# This file contains automatic SCL enablement.
unset BASH_ENV PROMPT_COMMAND ENV

24
root/usr/bin/base-usage Executable file
View file

@ -0,0 +1,24 @@
#!/bin/sh -e
cat <<EOF
This image serves as the base image for all OpenShift v3 S2I builder images.
It provides all essential libraries and development tools needed to
successfully build and run an application.
To use this image as a base image, you need to have 's2i/bin' directory in the
same directory as your S2I image Dockerfile. This directory should contain S2I
scripts.
This base image also provides the default user you should use to run your
application. Your Dockerfile should include this instruction after you finish
installing software:
USER default
The default directory for installing your application sources is
'/opt/app-root/src' and the WORKDIR and HOME for the 'default' user is set
to this directory as well. In your S2I scripts, you don't have to use absolute
path, but rather rely on the relative path.
To learn more about S2I visit: https://github.com/openshift/source-to-image
EOF

102
root/usr/bin/cgroup-limits Executable file
View file

@ -0,0 +1,102 @@
#!/usr/libexec/platform-python
"""
Script for parsing cgroup information
This script will read some limits from the cgroup system and parse
them, printing out "VARIABLE=VALUE" on each line for every limit that is
successfully read. Output of this script can be directly fed into
bash's export command. Recommended usage from a bash script:
set -o errexit
export_vars=$(cgroup-limits) ; export $export_vars
Variables currently supported:
MAX_MEMORY_LIMIT_IN_BYTES
Maximum possible limit MEMORY_LIMIT_IN_BYTES can have. This is
currently constant value of 9223372036854775807.
MEMORY_LIMIT_IN_BYTES
Maximum amount of user memory in bytes. If this value is set
to the same value as MAX_MEMORY_LIMIT_IN_BYTES, it means that
there is no limit set. The value is taken from
/sys/fs/cgroup/memory/memory.limit_in_bytes for cgroups v1
and from /sys/fs/cgroup/memory.max for cgroups v2
NUMBER_OF_CORES
Number of detected CPU cores that can be used. This value is
calculated from /sys/fs/cgroup/cpuset/cpuset.cpus for cgroups v1
and from /sys/fs/cgroup/cpuset.cpus.effective for cgroups v2
NO_MEMORY_LIMIT
Set to "true" if MEMORY_LIMIT_IN_BYTES is so high that the caller
can act as if no memory limit was set. Undefined otherwise.
"""
from __future__ import print_function
import sys
def _read_file(path):
try:
with open(path, 'r') as f:
return f.read().strip()
except IOError:
return None
def get_memory_limit():
"""
Read memory limit, in bytes.
"""
limit = _read_file('/sys/fs/cgroup/memory/memory.limit_in_bytes')
# If first file does not exist, try cgroups v2 file
limit = limit or _read_file('/sys/fs/cgroup/memory.max')
if limit is None or not limit.isdigit():
if limit == 'max':
return 9223372036854775807
print("Warning: Can't detect memory limit from cgroups",
file=sys.stderr)
return None
return int(limit)
def get_number_of_cores():
"""
Read number of CPU cores.
"""
core_count = 0
line = _read_file('/sys/fs/cgroup/cpuset/cpuset.cpus')
# If first file does not exist, try cgroups v2 file
line = line or _read_file('/sys/fs/cgroup/cpuset.cpus.effective')
if line is None:
# None of the files above exists when running podman as non-root,
# so in that case, this warning is printed every-time
print("Warning: Can't detect number of CPU cores from cgroups",
file=sys.stderr)
return None
for group in line.split(','):
core_ids = list(map(int, group.split('-')))
if len(core_ids) == 2:
core_count += core_ids[1] - core_ids[0] + 1
else:
core_count += 1
return core_count
if __name__ == "__main__":
env_vars = {
"MAX_MEMORY_LIMIT_IN_BYTES": 9223372036854775807,
"MEMORY_LIMIT_IN_BYTES": get_memory_limit(),
"NUMBER_OF_CORES": get_number_of_cores()
}
env_vars = {k: v for k, v in env_vars.items() if v is not None}
if env_vars.get("MEMORY_LIMIT_IN_BYTES", 0) >= 92233720368547:
env_vars["NO_MEMORY_LIMIT"] = "true"
for key, value in env_vars.items():
print("{0}={1}".format(key, value))

View file

@ -0,0 +1,2 @@
#!/bin/bash
exec "$@"

27
root/usr/bin/fix-permissions Executable file
View file

@ -0,0 +1,27 @@
#!/bin/sh
# Allow this script to fail without failing a build
set +e
SYMLINK_OPT=${2:--L}
# Fix permissions on the given directory or file to allow group read/write of
# regular files and execute of directories.
[ $(id -u) -ne 0 ] && CHECK_OWNER=" -uid $(id -u)"
# If argument does not exist, script will still exit with 0,
# but at least we'll see something went wrong in the log
if ! [ -e "$1" ] ; then
echo "ERROR: File or directory $1 does not exist." >&2
# We still want to end successfully
exit 0
fi
find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -gid 0 -exec chgrp 0 {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} \! -perm -g+rw -exec chmod g+rw {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} -perm /u+x -a \! -perm /g+x -exec chmod g+x {} +
find $SYMLINK_OPT "$1" ${CHECK_OWNER} -type d \! -perm /g+x -exec chmod g+x {} +
# Always end successfully
exit 0

View file

@ -0,0 +1,59 @@
#!/bin/bash
# This script is used to prepare yum repositories, that are given as arguments.
# It is no-op if user also mounts the repo file(s) into the container during
# image build. This can be done by one of those commands:
#
# docker build -v /some/repo/file:/etc/yum.repos.d/sclorg_custom.repo
# docker build -v /some/repo/directory:/etc/yum.repos.d
# make CUSTOM_REPO=/some/repo/file/or/directory
#
# The last one works for projects where we have Makefile with the
# container-common-scripts support.
set -ex
# DEFAULT_REPOS and SKIP_REPOS_{ENABLE,DISABLE} are intentionally undocumented,
# but might be used if we need to change this behaviour.
# Once we realize there are real use cases for using those variables, we should
# document them properly.
DEFAULT_REPOS=${DEFAULT_REPOS:-"rhel-7-server-rpms rhel-7-server-optional-rpms"}
SKIP_REPOS_ENABLE=${SKIP_REPOS_ENABLE:-false}
SKIP_REPOS_DISABLE=${SKIP_REPOS_DISABLE:-false}
function is_subscribed() {
for f in /run/secrets/etc-pki-entitlement/*.pem ; do
[ -e "$f" ] && return 0
break
done
return 1
}
# DEBUGGING CASE! Mostly for 'make CUSTOM_REPO=/some/file/or/dir'.
test ! -f /etc/yum.repos.d/sclorg_custom.repo && \
! mountpoint /etc/yum.repos.d \
|| exit 0
# install yum-utils for yum-config-manager
yum install -y yum-utils
if [ "$SKIP_REPOS_DISABLE" = false ] && is_subscribed; then
# Disable only repos that might come from subscribed host, because there
# might be other repos provided by user or build system
disable_repos=
# Lines look like: "Repo-id : dist-tag-override/x86_64"
while IFS=' /' read -r _ _ repo_id _; do
case $repo_id in rhel-*)
disable_repos+=" $repo_id" ;;
esac
done <<<"$(yum repolist -v 2>/dev/null | grep Repo-id)"
if test -n "$disable_repos"; then
yum-config-manager --disable $disable_repos &> /dev/null
fi
fi
if [ ${SKIP_REPOS_ENABLE} = false ] && [ -n "${DEFAULT_REPOS}" -o $# -gt 0 ] ; then
yum-config-manager --enable ${DEFAULT_REPOS} "$@"
fi

View file

@ -0,0 +1,21 @@
#!/bin/sh
CHECK_DIRS="/ /opt /etc /usr /usr/bin /usr/lib /usr/lib64 /usr/share /usr/libexec"
rpm_format="[%{FILESTATES:fstate} %7{FILEMODES:octal} %{FILENAMES:shescape}\n]"
rpm -q --qf "$rpm_format" filesystem | while read line
do
eval "set -- $line"
case $1 in
normal) ;;
*) continue ;;
esac
case " $CHECK_DIRS " in
*" $3 "*)
chmod "${2: -4}" "$3"
;;
esac
done

90
test/run Executable file
View file

@ -0,0 +1,90 @@
#!/bin/bash
#
# The 'run' performs a simple test that verifies that S2I image.
# The main focus is that the image prints out the base-usage properly.
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
test -n "${IMAGE_NAME-}" || { echo 'make sure $IMAGE_NAME is defined'; exit 1; }
test_docker_run_usage() {
echo "Testing 'docker run' usage..."
docker run --rm ${IMAGE_NAME} &>/dev/null
}
test_cgroup_limits() {
echo "Testing 'cgroup limits' usage..."
if [ $EUID -eq 0 ]; then
echo " The test is running as root, all tests for cgroup limits will be run"
# check memory limited (only works when running as root)
echo " Testing 'limited memory' usage..."
if ! ( eval $(docker run --rm --memory=512M ${IMAGE_NAME} /usr/bin/cgroup-limits)
echo "MEMORY_LIMIT_IN_BYTES=$MEMORY_LIMIT_IN_BYTES"
[ "$MEMORY_LIMIT_IN_BYTES" -eq 536870912 ] ); then
echo "MEMORY_LIMIT_IN_BYTES not set to 536870912."
return 1
fi
# check cores number (only works when running as root)
echo " Testing 'NUMBER_OF_CORES' value..."
if ! ( eval $(docker run --rm ${IMAGE_NAME} /usr/bin/cgroup-limits)
echo "NUMBER_OF_CORES=$NUMBER_OF_CORES"
[ "$NUMBER_OF_CORES" -gt 0 ] ); then
echo "NUMBER_OF_CORES not set."
return 1
fi
# check cores number (only works when running as root)
echo " Testing 'NUMBER_OF_CORES' value with --cpuset-cpus=0..."
if ! ( eval $(docker run --rm --cpuset-cpus=0 ${IMAGE_NAME} /usr/bin/cgroup-limits)
echo "NUMBER_OF_CORES=$NUMBER_OF_CORES"
[ "$NUMBER_OF_CORES" -eq 1 ] ); then
echo "NUMBER_OF_CORES not set to 1 when set --cpuset-cpus=0."
return 1
fi
else
echo " The test is running as non-root, some tests for cgroup limits are skipped"
fi
# check NO_MEMORY_LIMIT when no limit is set
echo " Testing 'NO_MEMORY_LIMIT' value..."
if ! ( eval $(docker run --rm ${IMAGE_NAME} /usr/bin/cgroup-limits)
echo "NO_MEMORY_LIMIT=$NO_MEMORY_LIMIT"
[ "$NO_MEMORY_LIMIT" == 'true' ] ); then
echo "NO_MEMORY_LIMIT not set to true."
return 1
fi
# check default memory in bytes
echo " Testing 'MEMORY_LIMIT_IN_BYTES' value..."
if ! ( eval $(docker run --rm ${IMAGE_NAME} /usr/bin/cgroup-limits)
echo "MEMORY_LIMIT_IN_BYTES=$MEMORY_LIMIT_IN_BYTES"
# This value can be different, but it must be very big (comparing to 10TB)
[ "$MEMORY_LIMIT_IN_BYTES" -gt 10000000000000 ] ); then
echo "MEMORY_LIMIT_IN_BYTES not greater than 10000000000000."
return 1
fi
}
check_result() {
local result="$1"
if [[ "$result" != "0" ]]; then
echo "S2I image '${IMAGE_NAME}' test FAILED (exit code: ${result})"
exit $result
fi
}
# Verify the 'usage' script is working properly when running the base image with 'docker run ...'
test_docker_run_usage
check_result $?
# Verify the cgroup-limits script works as expected
test_cgroup_limits
check_result $?
echo "Tests for '${IMAGE_NAME}' succeeded."
# vim: set tabstop=2:shiftwidth=2:expandtab: