Files
personal_tekton_catalog/task/buildah-rootless-daemonless/0.1/buildah-rootless-daemonless.yaml
Tom Alexander 64bee2bb1b Use overlay.
2026-09-07 18:10:38 -04:00

187 lines
6.0 KiB
YAML

apiVersion: tekton.dev/v1
kind: Task
metadata:
name: buildah
labels:
app.kubernetes.io/version: "0.1"
annotations:
tekton.dev/categories: Image Build
tekton.dev/pipelines.minVersion: "0.12.1"
tekton.dev/tags: image-build
tekton.dev/displayName: "Build a docker image with buildah."
tekton.dev/platforms: "linux/amd64"
container.apparmor.security.beta.kubernetes.io/step-build-and-push: unconfined
spec:
description: >-
This task will build a docker image using buildah and push the result to an image registry.
workspaces:
- name: source
mountPath: /source
readOnly: true
- name: dockerconfig
description: Includes credentials for the docker image registry.
optional: true
mountPath: /home/build/.docker
params:
- name: OUTPUT
type: string
description: Argument to output flag for `buildctl build`
# Examples:
# type=image,name=harbor.mydomain.example/private/foo:3.45,push=true,compression=zstd,compression-level=22
# type=image,"name=harbor.mydomain.example/private/foo:latest,harbor.mydomain.example/private/foo:3.45",push=true,compression=zstd,compression-level=22,oci-mediatypes=true
- name: CONTEXT
type: string
description: Path to the docker context.
default: "."
- name: DOCKERFILE
type: string
description: Path to the Dockerfile relative to the context.
default: "Dockerfile"
- name: BUILDER_IMAGE
type: string
description: Docker image containing Buildah.
default: "quay.io/buildah/stable:v1"
- name: EXTRA_ARGS
type: array
description: Arguments passed to the build command.
default: []
- name: REGISTRIES_CONF
type: string
description: Contents of registries.conf.
default: ""
results:
- name: IMAGE_DIGEST
description: Digest of the docker image.
- name: IMAGE_URL
description: Full URL to the docker image.
type: array
volumes:
- name: config-containers
emptyDir: {}
- name: metadata-out
emptyDir: {}
steps:
- name: write-config
image: $(params.BUILDER_IMAGE)
workingDir: "$(workspaces.source.path)"
script: |
#!/usr/bin/env sh
set -euo pipefail
echo ""
# ls -l /home/build/.local/share/containers
echo ""
tee /home/build/.config/containers/registries.conf <<EOF
$(params.REGISTRIES_CONF)
EOF
cat > /home/build/.config/containers/entrypoint.sh <<EOF
#!/usr/bin/env sh
#
set -xeuo pipefail
echo "Running as `id`"
# mkdir -p /home/build/.local/share/containers
# ln -s /workspace/buildah-storage /home/build/.local/share/containers/storage
# ln -s $(workspaces.buildah-storage.path) /home/build/.local/share/containers/storage
# ls -lR /home/build/.local/share/containers
cp /home/build/.config/containers_mount/registries.conf /home/build/.config/containers/
additional_args=(--source-date-epoch 100
--layers
--storage-driver overlay)
if [ -n "\$(find /tekton/creds/.ssh -maxdepth 1 -name 'id_*' -print -quit)" ]; then
eval \$(ssh-agent)
ssh-add /tekton/creds/.ssh/id_*
additional_args+=(--ssh default=\$SSH_AUTH_SOCK)
fi
exec buildah build "\${additional_args[@]}" "\${@}"
EOF
chmod +x /home/build/.config/containers/entrypoint.sh
volumeMounts:
- name: config-containers
mountPath: /home/build/.config/containers
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
- name: build-and-push
image: $(params.BUILDER_IMAGE)
workingDir: "$(workspaces.source.path)"
command: ["/home/build/.config/containers_mount/entrypoint.sh"]
args:
- --file
- $(params.DOCKERFILE)
- --tag
- $(params.OUTPUT)
- --iidfile
- /home/build/.metadata/image_id
- $(params.EXTRA_ARGS)
- $(workspaces.source.path)/$(params.CONTEXT)
volumeMounts:
- name: config-containers
mountPath: /home/build/.config/containers_mount
readOnly: true
- name: metadata-out
mountPath: /home/build/.metadata
# computeResources:
# requests:
# # cpu: 10m
# # memory: 600Mi
# ephemeral-storage: 100Mi
securityContext:
seccompProfile:
type: Unconfined
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
# capabilities:
# add:
# - all
# # - SETUID
# # - SETGID
# # - SYS_CHROOT
# # - SETFCAP
# appArmorProfile:
# type: Unconfined
computeResources:
requests:
ephemeral-storage: 1200Mi
env:
- name: DOCKER_CONFIG
value: $(workspaces.dockerconfig.path)
# - name: BUILDAH_ISOLATION
# value: chroot
- name: STORAGE_DRIVER
value: overlay
# value: vfs
- name: read-metadata
image: python:3.13-alpine3.20
workingDir: "$(workspaces.source.path)"
script: |
#!/usr/bin/env bash
cat /home/build/.metadata/image_id
echo "---"
#!/usr/bin/env python
import json
with open("/home/build/.metadata/build.json", "r") as f:
meta_body = f.read()
print(meta_body)
meta = json.loads(meta_body)
with open("$(results.IMAGE_DIGEST.path)", "w") as f:
print(meta["containerimage.digest"], file=f, end="")
with open("$(results.IMAGE_URL.path)", "w") as f:
print(json.dumps(meta["image.name"].split(",")), file=f, end="")
volumeMounts:
- name: metadata-out
mountPath: /home/build/.metadata
readOnly: true
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000