nextcloud: declare docker:cli as a pinned build.on base
build refused to reach docker:cli implicitly (novox/hq ADR 0097); pin it by digest and thread it through as DOCKER_CLI, redeclared in the final stage since args declared before the first FROM don't carry past it
This commit is contained in:
@@ -9,6 +9,7 @@
|
|||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
||||||
ARG BUILD_BASE
|
ARG BUILD_BASE
|
||||||
ARG RUNTIME_BASE
|
ARG RUNTIME_BASE
|
||||||
|
ARG DOCKER_CLI
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
FROM ${BUILD_BASE} AS build
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
||||||
@@ -21,12 +22,15 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts
|
|||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
FROM ${RUNTIME_BASE}
|
||||||
|
# ARGs declared before the first FROM are out of scope past it; redeclared here so COPY --from
|
||||||
|
# below can see it.
|
||||||
|
ARG DOCKER_CLI
|
||||||
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
|
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
|
||||||
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
|
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
|
||||||
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client
|
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client
|
||||||
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
|
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
|
||||||
# systemd unit, no package manager tree pulled in for it).
|
# systemd unit, no package manager tree pulled in for it).
|
||||||
COPY --from=docker:cli /usr/local/bin/docker /usr/local/bin/docker
|
COPY --from=${DOCKER_CLI} /usr/local/bin/docker /usr/local/bin/docker
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
||||||
|
|||||||
@@ -132,6 +132,10 @@
|
|||||||
"arg": "RUNTIME_BASE",
|
"arg": "RUNTIME_BASE",
|
||||||
"module": "mesh-tools",
|
"module": "mesh-tools",
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"arg": "DOCKER_CLI",
|
||||||
|
"image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
|
|||||||
Reference in New Issue
Block a user