build: harden image build inputs
This commit is contained in:
@@ -18,6 +18,36 @@ export THT_WORKSPACE_GIT_REMOTE="https://git.example.invalid/thothii/workspaces.
|
||||
export THOTH_CORE_HTTP_PORT=0
|
||||
export THOTH_HTTP_PORT=0
|
||||
|
||||
context_check="$tmp/build-context"
|
||||
mkdir -p "$context_check/deploy"
|
||||
cp .dockerignore "$context_check/.dockerignore"
|
||||
printf '%s\n' 'task-5-context-sentinel' >"$context_check/deploy/thothii.env"
|
||||
cat >"$context_check/Dockerfile" <<'EOF'
|
||||
FROM scratch
|
||||
COPY deploy/thothii.env /sentinel
|
||||
EOF
|
||||
if docker build --quiet -f "$context_check/Dockerfile" "$context_check" >"$tmp/context-check.out" 2>&1; then
|
||||
echo "deploy/thothii.env entered the Docker build context" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! awk '
|
||||
$1 == "FROM" && $2 !~ /^[^@]+@sha256:[0-9a-f]{64}$/ {
|
||||
print FILENAME ":" FNR ": unpinned base image: " $0 > "/dev/stderr"
|
||||
bad = 1
|
||||
}
|
||||
END { exit bad }
|
||||
' docker/core.Dockerfile docker/frontend.Dockerfile; then
|
||||
echo "every production FROM reference must use tag@sha256" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
while IFS= read -r base_image; do
|
||||
manifest=$(docker buildx imagetools inspect "$base_image")
|
||||
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/amd64'
|
||||
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/arm64'
|
||||
done < <(awk '$1 == "FROM" { print $2 }' docker/core.Dockerfile docker/frontend.Dockerfile | sort -u)
|
||||
|
||||
docker compose --project-name "$project" -f compose.yaml -f deploy/compose.local.yaml build --pull
|
||||
|
||||
core_label=$(docker image inspect --format '{{ index .Config.Labels "io.thothii.pi.version" }}' thothii-core:local)
|
||||
|
||||
@@ -3,6 +3,7 @@ set -eu
|
||||
|
||||
image=${1:?usage: test-vector-migration-image.sh IMAGE [PLATFORM]}
|
||||
platform=${2:-${PLATFORM:-linux/arm64}}
|
||||
repo_root=$(CDPATH= cd -- "$(dirname "$0")/.." && pwd)
|
||||
slug=$$
|
||||
network="thoth-vector-migration-$slug"
|
||||
database="thoth-vector-db-$slug"
|
||||
@@ -36,7 +37,12 @@ status=$(docker run --rm --platform "$platform" --network "$network" \
|
||||
--entrypoint /opt/venv/bin/tht -e THT_VECTOR_ADMIN_URL="$database_url" \
|
||||
"$image" vector migrate --status --json)
|
||||
|
||||
expected='{"applied": ["001", "002", "003"], "drifted": [], "pending": []}'
|
||||
expected_versions=$(find "$repo_root/harness/tht/migrations/vector" -type f -name '[0-9][0-9][0-9]_*.sql' \
|
||||
| sed 's|.*/||; s|_.*||' \
|
||||
| LC_ALL=C sort \
|
||||
| awk 'BEGIN { separator = ""; printf "[" } { printf "%s\"%s\"", separator, $0; separator = ", " } END { print "]" }')
|
||||
test "$expected_versions" != '[]'
|
||||
expected="{\"applied\": $expected_versions, \"drifted\": [], \"pending\": []}"
|
||||
test "$applied" = "$expected"
|
||||
test "$status" = "$expected"
|
||||
echo "core image vector migration discovery/status smoke passed"
|
||||
|
||||
@@ -25,17 +25,8 @@ test "$(docker image inspect --format '{{ index .Config.Labels "org.opencontaine
|
||||
docker run --rm --platform "$platform" --entrypoint /app/docker/smoke/core-smoke.sh \
|
||||
"$core_image"
|
||||
./scripts/test-vector-migration-image.sh "$core_image" "$platform"
|
||||
docker run --rm --platform "$platform" -e BACKEND_BASE_URL=/api \
|
||||
"$frontend_image" frontend-config-smoke
|
||||
docker run --rm --platform "$platform" -e BACKEND_BASE_URL= \
|
||||
"$frontend_image" frontend-config-smoke
|
||||
docker run --rm --platform "$platform" --entrypoint frontend-policy-smoke "$frontend_image"
|
||||
|
||||
if docker run --rm --platform "$platform" -e BACKEND_BASE_URL=/backend \
|
||||
"$frontend_image" frontend-config-smoke >/dev/null 2>&1; then
|
||||
echo "frontend accepted an unsupported BACKEND_BASE_URL" >&2
|
||||
exit 1
|
||||
fi
|
||||
docker run --rm --platform "$platform" "$frontend_image" frontend-config-smoke
|
||||
./docker/smoke/frontend-policy-smoke.sh
|
||||
if docker run --rm --platform "$platform" -e THOTH_PUBLIC_EXPOSURE=true -e AUTH_MODE=none \
|
||||
"$core_image" server >/dev/null 2>&1; then
|
||||
echo "core accepted public exposure without upstream authentication" >&2
|
||||
|
||||
Reference in New Issue
Block a user