216 lines
7.0 KiB
YAML
216 lines
7.0 KiB
YAML
|
|
apiVersion: tekton.dev/v1
|
||
|
|
kind: Task
|
||
|
|
metadata:
|
||
|
|
name: buildah
|
||
|
|
labels:
|
||
|
|
app.kubernetes.io/version: "0.1"
|
||
|
|
annotations:
|
||
|
|
tekton.dev/categories: Image Build
|
||
|
|
tekton.dev/pipelines.minVersion: "0.12.1"
|
||
|
|
tekton.dev/tags: image-build
|
||
|
|
tekton.dev/displayName: "Build a docker image with buildah."
|
||
|
|
tekton.dev/platforms: "linux/amd64"
|
||
|
|
container.apparmor.security.beta.kubernetes.io/step-build-and-push: unconfined
|
||
|
|
spec:
|
||
|
|
description: >-
|
||
|
|
This task will build a docker image using buildah and push the result to an image registry.
|
||
|
|
workspaces:
|
||
|
|
- name: source
|
||
|
|
mountPath: /source
|
||
|
|
readOnly: true
|
||
|
|
- name: dockerconfig
|
||
|
|
description: Includes credentials for the docker image registry.
|
||
|
|
optional: true
|
||
|
|
mountPath: /home/build/.docker
|
||
|
|
- name: buildah-storage
|
||
|
|
description: buildah's container storage.
|
||
|
|
optional: true
|
||
|
|
mountPath: /storage
|
||
|
|
# mountPath: /home/build/.local/share/containers
|
||
|
|
# mountPath: /foo
|
||
|
|
params:
|
||
|
|
- name: OUTPUT
|
||
|
|
type: string
|
||
|
|
description: Argument to output flag for `buildctl build`
|
||
|
|
# Examples:
|
||
|
|
# type=image,name=harbor.mydomain.example/private/foo:3.45,push=true,compression=zstd,compression-level=22
|
||
|
|
# type=image,"name=harbor.mydomain.example/private/foo:latest,harbor.mydomain.example/private/foo:3.45",push=true,compression=zstd,compression-level=22,oci-mediatypes=true
|
||
|
|
- name: CONTEXT
|
||
|
|
type: string
|
||
|
|
description: Path to the docker context.
|
||
|
|
default: "."
|
||
|
|
- name: DOCKERFILE
|
||
|
|
type: string
|
||
|
|
description: Path to the Dockerfile relative to the context.
|
||
|
|
default: "Dockerfile"
|
||
|
|
- name: BUILDER_IMAGE
|
||
|
|
type: string
|
||
|
|
description: Docker image containing Buildah.
|
||
|
|
default: "quay.io/buildah/stable:v1"
|
||
|
|
- name: EXTRA_ARGS
|
||
|
|
type: array
|
||
|
|
description: Arguments passed to the build command.
|
||
|
|
default: []
|
||
|
|
- name: REGISTRIES_CONF
|
||
|
|
type: string
|
||
|
|
description: Contents of registries.conf.
|
||
|
|
default: ""
|
||
|
|
results:
|
||
|
|
- name: IMAGE_DIGEST
|
||
|
|
description: Digest of the docker image.
|
||
|
|
- name: IMAGE_URL
|
||
|
|
description: Full URL to the docker image.
|
||
|
|
type: array
|
||
|
|
volumes:
|
||
|
|
- name: config-containers
|
||
|
|
emptyDir: {}
|
||
|
|
- name: metadata-out
|
||
|
|
emptyDir: {}
|
||
|
|
steps:
|
||
|
|
# - name: set-permissions
|
||
|
|
# image: $(params.BUILDER_IMAGE)
|
||
|
|
# workingDir: "$(workspaces.source.path)"
|
||
|
|
# script: |
|
||
|
|
# #!/usr/bin/env sh
|
||
|
|
# set -euo pipefail
|
||
|
|
|
||
|
|
# # chown -R 1000:1000 /home/build/.local/share/containers
|
||
|
|
# securityContext:
|
||
|
|
# runAsNonRoot: false
|
||
|
|
# runAsUser: 0
|
||
|
|
# runAsGroup: 0
|
||
|
|
- name: write-config
|
||
|
|
image: $(params.BUILDER_IMAGE)
|
||
|
|
workingDir: "$(workspaces.source.path)"
|
||
|
|
script: |
|
||
|
|
#!/usr/bin/env sh
|
||
|
|
set -euo pipefail
|
||
|
|
echo ""
|
||
|
|
# ls -l /home/build/.local/share/containers
|
||
|
|
echo ""
|
||
|
|
tee /home/build/.config/containers/registries.conf <<EOF
|
||
|
|
$(params.REGISTRIES_CONF)
|
||
|
|
EOF
|
||
|
|
tee > /home/build/.config/containers/storage.conf <<EOF
|
||
|
|
[storage]
|
||
|
|
driver = "overlay"
|
||
|
|
runroot = "/storage/run/containers/storage"
|
||
|
|
graphroot = "/storage/.local/share/containers/storage"
|
||
|
|
rootless_storage_path = "/storage/.local/share/containers/storage"
|
||
|
|
[storage.options]
|
||
|
|
pull_options = {enable_partial_images = "true", use_hard_links = "false", ostree_repos=""}
|
||
|
|
EOF
|
||
|
|
|
||
|
|
cat > /home/build/.config/containers/entrypoint.sh <<EOF
|
||
|
|
#!/usr/bin/env sh
|
||
|
|
#
|
||
|
|
set -xeuo pipefail
|
||
|
|
|
||
|
|
echo "Running as `id`"
|
||
|
|
|
||
|
|
# mkdir -p /home/build/.local/share/containers
|
||
|
|
# ln -s /workspace/buildah-storage /home/build/.local/share/containers/storage
|
||
|
|
# ln -s $(workspaces.buildah-storage.path) /home/build/.local/share/containers/storage
|
||
|
|
# ls -lR /home/build/.local/share/containers
|
||
|
|
|
||
|
|
cp /home/build/.config/containers_mount/{registries.conf,storage.conf} /home/build/.config/containers/
|
||
|
|
|
||
|
|
additional_args=(--source-date-epoch 100
|
||
|
|
--layers
|
||
|
|
--storage-driver vfs
|
||
|
|
--isolation=chroot
|
||
|
|
--cap-add=all)
|
||
|
|
|
||
|
|
if [ -n "\$(find /tekton/creds/.ssh -maxdepth 1 -name 'id_*' -print -quit)" ]; then
|
||
|
|
eval \$(ssh-agent)
|
||
|
|
ssh-add /tekton/creds/.ssh/id_*
|
||
|
|
additional_args+=(--ssh default=\$SSH_AUTH_SOCK)
|
||
|
|
fi
|
||
|
|
|
||
|
|
exec buildah build "\${additional_args[@]}" "\${@}"
|
||
|
|
|
||
|
|
EOF
|
||
|
|
chmod +x /home/build/.config/containers/entrypoint.sh
|
||
|
|
volumeMounts:
|
||
|
|
- name: config-containers
|
||
|
|
mountPath: /home/build/.config/containers
|
||
|
|
securityContext:
|
||
|
|
runAsNonRoot: true
|
||
|
|
runAsUser: 1000
|
||
|
|
runAsGroup: 1000
|
||
|
|
- name: build-and-push
|
||
|
|
image: $(params.BUILDER_IMAGE)
|
||
|
|
workingDir: "$(workspaces.source.path)"
|
||
|
|
command: ["/home/build/.config/containers_mount/entrypoint.sh"]
|
||
|
|
args:
|
||
|
|
- --file
|
||
|
|
- $(params.DOCKERFILE)
|
||
|
|
- --tag
|
||
|
|
- $(params.OUTPUT)
|
||
|
|
- --iidfile
|
||
|
|
- /home/build/.metadata/image_id
|
||
|
|
- $(params.EXTRA_ARGS)
|
||
|
|
- $(workspaces.source.path)/$(params.CONTEXT)
|
||
|
|
volumeMounts:
|
||
|
|
- name: config-containers
|
||
|
|
mountPath: /home/build/.config/containers_mount
|
||
|
|
readOnly: true
|
||
|
|
- name: metadata-out
|
||
|
|
mountPath: /home/build/.metadata
|
||
|
|
# computeResources:
|
||
|
|
# requests:
|
||
|
|
# # cpu: 10m
|
||
|
|
# # memory: 600Mi
|
||
|
|
# ephemeral-storage: 100Mi
|
||
|
|
securityContext:
|
||
|
|
seccompProfile:
|
||
|
|
type: Unconfined
|
||
|
|
runAsNonRoot: true
|
||
|
|
runAsUser: 1000
|
||
|
|
runAsGroup: 1000
|
||
|
|
# capabilities:
|
||
|
|
# add:
|
||
|
|
# - all
|
||
|
|
# # - SETUID
|
||
|
|
# # - SETGID
|
||
|
|
# # - SYS_CHROOT
|
||
|
|
# # - SETFCAP
|
||
|
|
# appArmorProfile:
|
||
|
|
# type: Unconfined
|
||
|
|
computeResources:
|
||
|
|
requests:
|
||
|
|
ephemeral-storage: 1200Mi
|
||
|
|
env:
|
||
|
|
- name: DOCKER_CONFIG
|
||
|
|
value: $(workspaces.dockerconfig.path)
|
||
|
|
# - name: BUILDAH_ISOLATION
|
||
|
|
# value: chroot
|
||
|
|
- name: STORAGE_DRIVER
|
||
|
|
# value: overlay
|
||
|
|
value: vfs
|
||
|
|
- name: read-metadata
|
||
|
|
image: python:3.13-alpine3.20
|
||
|
|
workingDir: "$(workspaces.source.path)"
|
||
|
|
script: |
|
||
|
|
#!/usr/bin/env bash
|
||
|
|
cat /home/build/.metadata/image_id
|
||
|
|
echo "---"
|
||
|
|
#!/usr/bin/env python
|
||
|
|
import json
|
||
|
|
with open("/home/build/.metadata/build.json", "r") as f:
|
||
|
|
meta_body = f.read()
|
||
|
|
print(meta_body)
|
||
|
|
meta = json.loads(meta_body)
|
||
|
|
with open("$(results.IMAGE_DIGEST.path)", "w") as f:
|
||
|
|
print(meta["containerimage.digest"], file=f, end="")
|
||
|
|
with open("$(results.IMAGE_URL.path)", "w") as f:
|
||
|
|
print(json.dumps(meta["image.name"].split(",")), file=f, end="")
|
||
|
|
volumeMounts:
|
||
|
|
- name: metadata-out
|
||
|
|
mountPath: /home/build/.metadata
|
||
|
|
readOnly: true
|
||
|
|
securityContext:
|
||
|
|
runAsNonRoot: true
|
||
|
|
runAsUser: 1000
|
||
|
|
runAsGroup: 1000
|