build: harden image build inputs

This commit is contained in:
2026-08-04 16:33:39 +02:00
parent d42fdf4b71
commit e2264ee295
7 changed files with 52 additions and 28 deletions
+30
View File
@@ -18,6 +18,36 @@ export THT_WORKSPACE_GIT_REMOTE="https://git.example.invalid/thothii/workspaces.
export THOTH_CORE_HTTP_PORT=0
export THOTH_HTTP_PORT=0
context_check="$tmp/build-context"
mkdir -p "$context_check/deploy"
cp .dockerignore "$context_check/.dockerignore"
printf '%s\n' 'task-5-context-sentinel' >"$context_check/deploy/thothii.env"
cat >"$context_check/Dockerfile" <<'EOF'
FROM scratch
COPY deploy/thothii.env /sentinel
EOF
if docker build --quiet -f "$context_check/Dockerfile" "$context_check" >"$tmp/context-check.out" 2>&1; then
echo "deploy/thothii.env entered the Docker build context" >&2
exit 1
fi
if ! awk '
$1 == "FROM" && $2 !~ /^[^@]+@sha256:[0-9a-f]{64}$/ {
print FILENAME ":" FNR ": unpinned base image: " $0 > "/dev/stderr"
bad = 1
}
END { exit bad }
' docker/core.Dockerfile docker/frontend.Dockerfile; then
echo "every production FROM reference must use tag@sha256" >&2
exit 1
fi
while IFS= read -r base_image; do
manifest=$(docker buildx imagetools inspect "$base_image")
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/amd64'
printf '%s\n' "$manifest" | grep -Eq 'Platform:[[:space:]]+linux/arm64'
done < <(awk '$1 == "FROM" { print $2 }' docker/core.Dockerfile docker/frontend.Dockerfile | sort -u)
docker compose --project-name "$project" -f compose.yaml -f deploy/compose.local.yaml build --pull
core_label=$(docker image inspect --format '{{ index .Config.Labels "io.thothii.pi.version" }}' thothii-core:local)