24 lines
1.2 KiB
Docker
24 lines
1.2 KiB
Docker
# nftables' runtime: the tool runtime, carrying the packet filter's tools and the binaries they speak.
|
|
#
|
|
# Built from this module's own directory and nothing else (novox/hq ADR 0069). Two bases, named in
|
|
# module.json's `build.on`: the image this is compiled in and the image it runs in.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
WORKDIR /app/modules/nftables
|
|
COPY . .
|
|
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
# The filter's own tools: nft for the machine's ruleset and the mesh's table, iptables for the
|
|
# legacy filter and the tables iptables-nft manages — a predecessor's rules live there (ADR 0168).
|
|
# The container runs on the machine's network with NET_ADMIN (ADR 0170), so these act on the
|
|
# machine's packet filter, not on a namespace of their own.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends nftables iptables \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
COPY --from=build /app/modules/nftables/dist /app/modules/nftables/dist
|
|
ENV MESH_TOOL_MODULES=/app/modules/nftables/dist/tools/index.js
|