diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 546eb27..c7b5b82 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -7,7 +7,9 @@ on: branches: - development paths: + - .dockerignore - .github/** + - Dockerfile - module/** - netbox-sync.py - requirements.txt diff --git a/Dockerfile b/Dockerfile index 2445d31..0852fa8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,12 +5,11 @@ COPY requirements.txt . ARG VENV=/opt/netbox-sync/venv # Install dependencies -RUN apt-get update && \ - rm -rf /var/lib/apt/lists/* && \ - python3 -m venv $VENV && \ +RUN python3 -m venv $VENV && \ $VENV/bin/python3 -m pip install --upgrade pip && \ $VENV/bin/pip install -r requirements.txt && \ - $VENV/bin/pip install --upgrade vcf-sdk && \ + $VENV/bin/pip install vmware-vcenter==9.1.1.0 && \ + $VENV/bin/python3 -m pip uninstall -y pip && \ find $VENV -type d -name "__pycache__" -print0 | xargs -0 -n1 rm -rf FROM python:3.14-slim AS netbox-sync @@ -20,16 +19,24 @@ ARG VENV=/opt/netbox-sync/venv # Copy installed packages COPY --from=builder $VENV $VENV -# Add netbox-sync user -RUN groupadd --gid 1000 netbox-sync && \ - useradd --uid 1000 --gid netbox-sync --shell /bin/sh \ - --no-create-home --system netbox-sync +# Copy application files +WORKDIR /app +COPY . . -USER netbox-sync +# Install the security updates published since the base image was built, +# drop pip (not needed at runtime) and add the netbox-sync user. +# The code belongs to root and is read-only for the service user; only the +# cache directory is writable (group 0 as well, so an arbitrary uid in group 0 +# can use it) +RUN apt-get update && \ + apt-get dist-upgrade -y && \ + rm -rf /var/lib/apt/lists/* && \ + python3 -m pip uninstall -y --root-user-action=ignore pip && \ + groupadd --gid 1000 netbox-sync && \ + useradd --uid 1000 --gid netbox-sync --shell /bin/sh --no-create-home --system netbox-sync && \ + mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache -# Prepare the application -WORKDIR /app -COPY --chown=netbox-sync:netbox-sync . . +USER netbox-sync # Use virtual env packages and allow timezone setup ENV PATH=$VENV/bin:$PATH diff --git a/README.md b/README.md index 684a144..8eb9365 100644 --- a/README.md +++ b/README.md @@ -217,6 +217,7 @@ so switch the pull address to `ghcr.io/bb-ricardo/netbox-sync`. * The application working directory is ```/app``` * Required to mount your ```settings.ini``` +* The NetBox cache is written to ```/app/cache```, mount a volume there to keep it between runs To build it by yourself just run: ```shell @@ -225,7 +226,7 @@ docker build -t ghcr.io/bb-ricardo/netbox-sync:latest . To start the container just use: ```shell -docker run --rm -it -v $(pwd)/settings.ini:/app/settings.ini ghcr.io/bb-ricardo/netbox-sync:latest +docker run --rm -it -v $(pwd)/settings.ini:/app/settings.ini -v netbox-sync-cache:/app/cache ghcr.io/bb-ricardo/netbox-sync:latest ``` ## Kubernetes