From afb7bace110da1a442589966e21c91f92a945f6d Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Wed, 30 Sep 2026 13:35:40 +0400 Subject: [PATCH 1/8] docker: install only the vCenter bindings instead of all of vcf-sdk vcf-sdk is a meta package that pulls every VMware Cloud Foundation binding (NSX, SDDC Manager, Operations, Fleet LCM, Installer, vSAN data protection). netbox-sync only needs create_vsphere_client and the tagging client, which come from vmware-vcenter and the vapi runtime and common client it depends on. Install vmware-vcenter pinned to the version vcf-sdk resolves to today, so a rebuild of the same tag gets the same SDK, and drop the apt-get line that installed nothing. Built from the same development commit: 339 MB -> 248 MB uncompressed, 58 MB -> 52 MB gzipped. All 552 Python files under vmware/ and com/ in the new image are byte-identical to the current one; the 155 files that are no longer installed belong to SDDC Manager, the VCF installer and snapservice. pyvmomi, vmware-vapi-runtime, vmware-vapi-common-client and vmware-vcenter stay at 9.1.1.0, --help works and the process still runs as uid 1000. --- Dockerfile | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 2445d318..52d58873 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,12 +5,10 @@ COPY requirements.txt . ARG VENV=/opt/netbox-sync/venv # Install dependencies -RUN apt-get update && \ - rm -rf /var/lib/apt/lists/* && \ - python3 -m venv $VENV && \ +RUN python3 -m venv $VENV && \ $VENV/bin/python3 -m pip install --upgrade pip && \ $VENV/bin/pip install -r requirements.txt && \ - $VENV/bin/pip install --upgrade vcf-sdk && \ + $VENV/bin/pip install vmware-vcenter==9.1.1.0 && \ find $VENV -type d -name "__pycache__" -print0 | xargs -0 -n1 rm -rf FROM python:3.14-slim AS netbox-sync From 7e6690da2fa4e90317006dcf291527b5229de390 Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Wed, 30 Sep 2026 13:40:35 +0400 Subject: [PATCH 2/8] docker: keep the code read-only and give the cache a writable directory The application files were copied with the service user as owner, so the running process could rewrite its own code, while /app itself stayed owned by root, so the default cache directory (/app/cache) could not be created and every container run logged "NetBox caching DISABLED" and fetched all objects from NetBox again. Copy the code as root, read-only for the service user, and create /app/cache owned by the service user and group 0 with mode 0770, which also covers platforms that run the image with an arbitrary uid in group 0. Checked with --read-only --cap-drop ALL --security-opt no-new-privileges and a volume on /app/cache: the cache is writable, the code is not, --help works, and an arbitrary uid in group 0 can write the cache. Before this change the same checks failed on the cache and succeeded on writing the code. --- Dockerfile | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 52d58873..a8962f74 100644 --- a/Dockerfile +++ b/Dockerfile @@ -23,11 +23,14 @@ RUN groupadd --gid 1000 netbox-sync && \ useradd --uid 1000 --gid netbox-sync --shell /bin/sh \ --no-create-home --system netbox-sync -USER netbox-sync - -# Prepare the application +# Prepare the application: the code belongs to root and is read-only for the +# service user; only the cache directory is writable (group 0 as well, so an +# arbitrary uid in group 0 can use it) WORKDIR /app -COPY --chown=netbox-sync:netbox-sync . . +COPY . . +RUN mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache + +USER netbox-sync # Use virtual env packages and allow timezone setup ENV PATH=$VENV/bin:$PATH From d9386cffffaa5d885c2c3cedc47efa83a62f402c Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Fri, 2 Oct 2026 01:23:09 +0400 Subject: [PATCH 3/8] docker: install pending Debian security updates in the final stage --- Dockerfile | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Dockerfile b/Dockerfile index a8962f74..00262864 100644 --- a/Dockerfile +++ b/Dockerfile @@ -15,6 +15,11 @@ FROM python:3.14-slim AS netbox-sync ARG VENV=/opt/netbox-sync/venv +# Install the security updates published since the base image was built +RUN apt-get update && \ + apt-get dist-upgrade -y && \ + rm -rf /var/lib/apt/lists/* + # Copy installed packages COPY --from=builder $VENV $VENV From 874fda8cbc1f58ac3b6153c0112c262d7258cfcf Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Fri, 2 Oct 2026 02:10:34 +0400 Subject: [PATCH 4/8] docker: drop pip from the runtime image --- Dockerfile | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 00262864..517a1d23 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,16 +9,19 @@ RUN python3 -m venv $VENV && \ $VENV/bin/python3 -m pip install --upgrade pip && \ $VENV/bin/pip install -r requirements.txt && \ $VENV/bin/pip install vmware-vcenter==9.1.1.0 && \ + $VENV/bin/python3 -m pip uninstall -y pip && \ find $VENV -type d -name "__pycache__" -print0 | xargs -0 -n1 rm -rf FROM python:3.14-slim AS netbox-sync ARG VENV=/opt/netbox-sync/venv -# Install the security updates published since the base image was built +# Install the security updates published since the base image was built and +# drop pip, which is not needed at runtime RUN apt-get update && \ apt-get dist-upgrade -y && \ - rm -rf /var/lib/apt/lists/* + rm -rf /var/lib/apt/lists/* && \ + python3 -m pip uninstall -y pip # Copy installed packages COPY --from=builder $VENV $VENV From bbb8118f9e5bec9d12ae3659976a18f92616ec1a Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Fri, 2 Oct 2026 02:10:34 +0400 Subject: [PATCH 5/8] ci: build the image when the Dockerfile changes --- .github/workflows/docker-image.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 546eb274..c7b5b82b 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -7,7 +7,9 @@ on: branches: - development paths: + - .dockerignore - .github/** + - Dockerfile - module/** - netbox-sync.py - requirements.txt From 15b968ed1ba05738754de11b9d119476ac51b1ac Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Fri, 2 Oct 2026 02:10:34 +0400 Subject: [PATCH 6/8] docs: mount a volume for the NetBox cache in the docker example --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 684a1448..8eb9365d 100644 --- a/README.md +++ b/README.md @@ -217,6 +217,7 @@ so switch the pull address to `ghcr.io/bb-ricardo/netbox-sync`. * The application working directory is ```/app``` * Required to mount your ```settings.ini``` +* The NetBox cache is written to ```/app/cache```, mount a volume there to keep it between runs To build it by yourself just run: ```shell @@ -225,7 +226,7 @@ docker build -t ghcr.io/bb-ricardo/netbox-sync:latest . To start the container just use: ```shell -docker run --rm -it -v $(pwd)/settings.ini:/app/settings.ini ghcr.io/bb-ricardo/netbox-sync:latest +docker run --rm -it -v $(pwd)/settings.ini:/app/settings.ini -v netbox-sync-cache:/app/cache ghcr.io/bb-ricardo/netbox-sync:latest ``` ## Kubernetes From d63c307fa013ff52587932c7069586b32bd53b28 Mon Sep 17 00:00:00 2001 From: Ricardo Bartels Date: Fri, 2 Oct 2026 14:37:45 +0200 Subject: [PATCH 7/8] reworks Dockerfile to reduce the amount of container layers Signed-off-by: Ricardo Bartels --- Dockerfile | 25 +++++++++++-------------- 1 file changed, 11 insertions(+), 14 deletions(-) diff --git a/Dockerfile b/Dockerfile index 517a1d23..bb474d42 100644 --- a/Dockerfile +++ b/Dockerfile @@ -16,27 +16,24 @@ FROM python:3.14-slim AS netbox-sync ARG VENV=/opt/netbox-sync/venv -# Install the security updates published since the base image was built and -# drop pip, which is not needed at runtime -RUN apt-get update && \ - apt-get dist-upgrade -y && \ - rm -rf /var/lib/apt/lists/* && \ - python3 -m pip uninstall -y pip - # Copy installed packages COPY --from=builder $VENV $VENV -# Add netbox-sync user -RUN groupadd --gid 1000 netbox-sync && \ - useradd --uid 1000 --gid netbox-sync --shell /bin/sh \ - --no-create-home --system netbox-sync +# Copy application files +WORKDIR /app +COPY . . +# Install the security updates published since the base image was built and +# Add netbox-sync user # Prepare the application: the code belongs to root and is read-only for the # service user; only the cache directory is writable (group 0 as well, so an # arbitrary uid in group 0 can use it) -WORKDIR /app -COPY . . -RUN mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache +RUN apt-get update && \ + apt-get dist-upgrade -y && \ + rm -rf /var/lib/apt/lists/* && \ + groupadd --gid 1000 netbox-sync && \ + useradd --uid 1000 --gid netbox-sync --shell /bin/sh --no-create-home --system netbox-sync && \ + mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache USER netbox-sync From a2114010418a7cb37607c8d770a3e8216a92c06e Mon Sep 17 00:00:00 2001 From: Sergey Sannikov Date: Fri, 2 Oct 2026 16:43:51 +0400 Subject: [PATCH 8/8] docker: drop pip again in the combined layer --- Dockerfile | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/Dockerfile b/Dockerfile index bb474d42..0852fa81 100644 --- a/Dockerfile +++ b/Dockerfile @@ -23,14 +23,15 @@ COPY --from=builder $VENV $VENV WORKDIR /app COPY . . -# Install the security updates published since the base image was built and -# Add netbox-sync user -# Prepare the application: the code belongs to root and is read-only for the -# service user; only the cache directory is writable (group 0 as well, so an -# arbitrary uid in group 0 can use it) +# Install the security updates published since the base image was built, +# drop pip (not needed at runtime) and add the netbox-sync user. +# The code belongs to root and is read-only for the service user; only the +# cache directory is writable (group 0 as well, so an arbitrary uid in group 0 +# can use it) RUN apt-get update && \ apt-get dist-upgrade -y && \ rm -rf /var/lib/apt/lists/* && \ + python3 -m pip uninstall -y --root-user-action=ignore pip && \ groupadd --gid 1000 netbox-sync && \ useradd --uid 1000 --gid netbox-sync --shell /bin/sh --no-create-home --system netbox-sync && \ mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache