mirror of
https://github.com/pgsty/minio.git
synced 2026-08-09 07:43:29 +03:00
16b78eb4e5
Bundle mcli RELEASE.2026-08-06T00-00-00Z in the container image (pin and both architecture digests; interop with the new server was verified end to end during release acceptance) and align the CI fixture default in install-mcli.sh. Point the Helm chart defaults at the first real silo image tag: docker.io/pgsty/silo is a fresh repository, so the inherited RELEASE.2026-08-04 default could never pull. Chart version moves to 7.0.1 with appVersion RELEASE.2026-08-06T00-00-00Z; the packaging tripwire in verify-helm-migration.sh follows. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
105 lines
4.3 KiB
Docker
105 lines
4.3 KiB
Docker
FROM golang:1.26.5-alpine AS build
|
|
|
|
ARG TARGETARCH
|
|
|
|
ENV GOPATH=/go
|
|
ENV CGO_ENABLED=0
|
|
|
|
ARG MC_REPO=pgsty/mc
|
|
ARG MC_VERSION=RELEASE.2026-08-06T00-00-00Z
|
|
ARG MC_AMD64_SHA256=4b488bd30af54ad4214e5b654746677c79cd93dc6cad4be3aa2d09dbb48370ff
|
|
ARG MC_ARM64_SHA256=83f6fedb16ed9c1e8efa8aea6776203dff132bc474214543d5c0767ed2066c2f
|
|
|
|
RUN apk add -U --no-cache \
|
|
ca-certificates \
|
|
bash \
|
|
curl \
|
|
jq && \
|
|
case "${TARGETARCH}" in \
|
|
amd64) MC_ARCH=amd64; MC_PINNED_SHA256="${MC_AMD64_SHA256}" ;; \
|
|
arm64) MC_ARCH=arm64; MC_PINNED_SHA256="${MC_ARM64_SHA256}" ;; \
|
|
*) echo "Unsupported TARGETARCH=${TARGETARCH}"; exit 1 ;; \
|
|
esac && \
|
|
if [ "${MC_VERSION}" = "latest" ]; then \
|
|
MC_RELEASE_URL="https://api.github.com/repos/${MC_REPO}/releases/latest"; \
|
|
else \
|
|
MC_RELEASE_URL="https://api.github.com/repos/${MC_REPO}/releases/tags/${MC_VERSION}"; \
|
|
fi && \
|
|
curl -fsSL "${MC_RELEASE_URL}" -o /tmp/mc-release.json && \
|
|
MC_ARCHIVE_URL=$(jq -r --arg arch "${MC_ARCH}" \
|
|
'.assets[] | select(.name | endswith("_linux_" + $arch + ".tar.gz")) | .browser_download_url' \
|
|
/tmp/mc-release.json | head -n 1) && \
|
|
MC_CHECKSUM_URL=$(jq -r \
|
|
'.assets[] | select(.name | endswith("_checksums.txt")) | .browser_download_url' \
|
|
/tmp/mc-release.json | head -n 1) && \
|
|
[ -n "${MC_ARCHIVE_URL}" ] || { echo "Cannot find mcli archive for linux/${MC_ARCH}"; exit 1; } && \
|
|
[ -n "${MC_CHECKSUM_URL}" ] || { echo "Cannot find mcli checksums file"; exit 1; } && \
|
|
ARCHIVE_NAME=$(basename "${MC_ARCHIVE_URL}") && \
|
|
echo "Downloading ${ARCHIVE_NAME} ..." && \
|
|
curl -fsSL "${MC_ARCHIVE_URL}" -o /tmp/mcli.tar.gz && \
|
|
curl -fsSL "${MC_CHECKSUM_URL}" -o /tmp/mcli_checksums.txt && \
|
|
EXPECTED=$(grep " ${ARCHIVE_NAME}$" /tmp/mcli_checksums.txt | awk '{print $1}') && \
|
|
ACTUAL=$(sha256sum /tmp/mcli.tar.gz | awk '{print $1}') && \
|
|
[ -n "${EXPECTED}" ] || { echo "Checksum entry not found for ${ARCHIVE_NAME}"; exit 1; } && \
|
|
[ "${EXPECTED}" = "${MC_PINNED_SHA256}" ] || { echo "Published checksum drift for ${ARCHIVE_NAME}"; exit 1; } && \
|
|
[ "${MC_PINNED_SHA256}" = "${ACTUAL}" ] || { echo "Checksum mismatch: expected ${MC_PINNED_SHA256}, got ${ACTUAL}"; exit 1; } && \
|
|
echo "Checksum OK: ${ACTUAL}" && \
|
|
mkdir -p /tmp/mcli-extract && \
|
|
tar -xzf /tmp/mcli.tar.gz -C /tmp/mcli-extract/ && \
|
|
if [ -f /tmp/mcli-extract/mcli ]; then \
|
|
cp /tmp/mcli-extract/mcli /go/bin/mcli; \
|
|
elif [ -f /tmp/mcli-extract/mc ]; then \
|
|
cp /tmp/mcli-extract/mc /go/bin/mcli; \
|
|
else \
|
|
echo "No mc or mcli binary found in archive:"; ls -la /tmp/mcli-extract/; exit 1; \
|
|
fi && \
|
|
chmod +x /go/bin/mcli && \
|
|
ln -sf mcli /go/bin/mc
|
|
|
|
COPY dockerscripts/download-static-curl.sh /build/download-static-curl
|
|
RUN chmod +x /build/download-static-curl && \
|
|
/build/download-static-curl
|
|
|
|
FROM registry.access.redhat.com/ubi9/ubi:latest AS certs
|
|
RUN dnf -y install ca-certificates && \
|
|
update-ca-trust && \
|
|
cp /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem /tmp/ca-certificates.crt && \
|
|
dnf clean all && \
|
|
rm -rf /var/cache/dnf
|
|
|
|
FROM registry.access.redhat.com/ubi9/ubi-micro:latest
|
|
|
|
LABEL org.opencontainers.image.title="Silo" \
|
|
org.opencontainers.image.description="S3-Interface Libre Object Storage" \
|
|
org.opencontainers.image.url="https://silo.pgsty.com" \
|
|
org.opencontainers.image.source="https://github.com/pgsty/silo" \
|
|
org.opencontainers.image.licenses="AGPL-3.0-or-later" \
|
|
maintainer="PGSTY <https://silo.pgsty.com>"
|
|
|
|
ENV MINIO_ACCESS_KEY_FILE=access_key \
|
|
MINIO_SECRET_KEY_FILE=secret_key \
|
|
MINIO_ROOT_USER_FILE=access_key \
|
|
MINIO_ROOT_PASSWORD_FILE=secret_key \
|
|
MINIO_KMS_SECRET_KEY_FILE=kms_master_key \
|
|
MINIO_CONFIG_ENV_FILE=config.env \
|
|
HOME=/tmp \
|
|
MC_CONFIG_DIR=/tmp/.mc
|
|
|
|
COPY --from=certs /tmp/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
|
|
COPY silo /usr/bin/silo
|
|
COPY --from=build /go/bin/mcli /usr/bin/mcli
|
|
COPY --from=build /go/bin/curl* /usr/bin/
|
|
COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh
|
|
COPY LICENSE /licenses/LICENSE
|
|
COPY NOTICE /licenses/NOTICE
|
|
COPY CREDITS /licenses/CREDITS
|
|
|
|
RUN chmod +x /usr/bin/silo /usr/bin/mcli /usr/bin/docker-entrypoint.sh && \
|
|
ln -sf mcli /usr/bin/mc
|
|
|
|
EXPOSE 9000
|
|
VOLUME ["/data"]
|
|
|
|
ENTRYPOINT ["/usr/bin/docker-entrypoint.sh"]
|
|
CMD ["silo"]
|