mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-08-22 07:06:51 +00:00
* docker: upgrade libcrypto3/libssl3 to clear Trivy HIGH Trivy gate on ghcr.io/seaweedfs/seaweedfs:latest-amd64 flagged CVE-2026-28390 in libcrypto3 3.5.5-r0 (fixed in 3.5.6-r0) on the alpine 3.23.3 base. Add libcrypto3/libssl3 to the existing apk upgrade so rebuilt images pick up the patched openssl without waiting for a new alpine base tag. * docker: apk add libcrypto3/libssl3 so they install at patched version Per review, apk upgrade <pkg> is a no-op when the package isn't already installed. libcrypto3/libssl3 come in transitively via curl, so list them in apk add to guarantee installation at the latest (patched) version from the alpine repo.
92 lines
3.5 KiB
Docker
92 lines
3.5 KiB
Docker
FROM golang:1.25-alpine AS builder
|
|
RUN apk add git g++ fuse
|
|
RUN mkdir -p /go/src/github.com/seaweedfs/
|
|
ARG BRANCH=${BRANCH:-master}
|
|
# Clone with full history and all tags to ensure all commits are available
|
|
RUN git clone --no-single-branch --tags https://github.com/seaweedfs/seaweedfs /go/src/github.com/seaweedfs/seaweedfs
|
|
ARG TAGS
|
|
RUN cd /go/src/github.com/seaweedfs/seaweedfs && \
|
|
(git checkout $BRANCH || \
|
|
(echo "Checkout failed, fetching all history..." && \
|
|
git fetch --all --tags --prune && \
|
|
git checkout $BRANCH) || \
|
|
(echo "ERROR: Branch/commit $BRANCH not found in repository" && \
|
|
echo "Available branches:" && git branch -a && exit 1))
|
|
RUN cd /go/src/github.com/seaweedfs/seaweedfs/weed \
|
|
&& export LDFLAGS="-X github.com/seaweedfs/seaweedfs/weed/util/version.COMMIT=$(git rev-parse --short HEAD)" \
|
|
&& CGO_ENABLED=0 go install -tags "$TAGS" -ldflags "-extldflags -static ${LDFLAGS}"
|
|
|
|
# Rust volume server: use pre-built binary from CI when available (placed in
|
|
# weed-volume-prebuilt/ by the build-rust-binaries job), otherwise compile
|
|
# from source. Pre-building avoids a multi-hour QEMU-emulated cargo build
|
|
# for non-native architectures.
|
|
FROM alpine:3.23 as rust_builder
|
|
ARG TARGETARCH
|
|
ARG TAGS
|
|
COPY weed-volume-prebuilt/ /prebuilt/
|
|
COPY --from=builder /go/src/github.com/seaweedfs/seaweedfs/seaweed-volume /build/seaweed-volume
|
|
COPY --from=builder /go/src/github.com/seaweedfs/seaweedfs/weed /build/weed
|
|
WORKDIR /build/seaweed-volume
|
|
RUN if [ -f "/prebuilt/weed-volume-${TARGETARCH}" ]; then \
|
|
echo "Using pre-built Rust binary for ${TARGETARCH}" && \
|
|
cp "/prebuilt/weed-volume-${TARGETARCH}" /weed-volume; \
|
|
elif [ "$TARGETARCH" = "amd64" ] || [ "$TARGETARCH" = "arm64" ]; then \
|
|
apk add --no-cache musl-dev openssl-dev protobuf-dev git rust cargo; \
|
|
if [ "$TAGS" = "5BytesOffset" ]; then \
|
|
cargo build --release; \
|
|
else \
|
|
cargo build --release --no-default-features; \
|
|
fi && \
|
|
cp target/release/weed-volume /weed-volume; \
|
|
else \
|
|
echo "Skipping Rust build for $TARGETARCH (unsupported)" && \
|
|
touch /weed-volume; \
|
|
fi
|
|
|
|
FROM alpine AS final
|
|
LABEL author="Chris Lu"
|
|
COPY --from=builder /go/bin/weed /usr/bin/
|
|
# Copy Rust volume server binary (real binary on amd64/arm64, empty placeholder on other platforms)
|
|
COPY --from=rust_builder /weed-volume /usr/bin/weed-volume
|
|
RUN mkdir -p /etc/seaweedfs
|
|
COPY --from=builder /go/src/github.com/seaweedfs/seaweedfs/docker/filer.toml /etc/seaweedfs/filer.toml
|
|
COPY --from=builder /go/src/github.com/seaweedfs/seaweedfs/docker/entrypoint.sh /entrypoint.sh
|
|
|
|
# FIPS 140-3 mode is ON by default (Go 1.24+)
|
|
# To disable: docker run -e GODEBUG=fips140=off ...
|
|
|
|
# Install dependencies and create non-root user
|
|
RUN apk upgrade --no-cache zlib && \
|
|
apk add --no-cache fuse curl su-exec libgcc libcrypto3 libssl3 && \
|
|
addgroup -g 1000 seaweed && \
|
|
adduser -D -u 1000 -G seaweed seaweed
|
|
|
|
# volume server gprc port
|
|
EXPOSE 18080
|
|
# volume server http port
|
|
EXPOSE 8080
|
|
# filer server gprc port
|
|
EXPOSE 18888
|
|
# filer server http port
|
|
EXPOSE 8888
|
|
# master server shared gprc port
|
|
EXPOSE 19333
|
|
# master server shared http port
|
|
EXPOSE 9333
|
|
# s3 server http port
|
|
EXPOSE 8333
|
|
# webdav server http port
|
|
EXPOSE 7333
|
|
|
|
# Create data directory and set proper ownership for seaweed user
|
|
RUN mkdir -p /data/filerldb2 && \
|
|
chown -R seaweed:seaweed /data && \
|
|
chown -R seaweed:seaweed /etc/seaweedfs && \
|
|
chmod 755 /entrypoint.sh
|
|
|
|
VOLUME /data
|
|
WORKDIR /data
|
|
|
|
# Entrypoint will handle permission fixes and user switching
|
|
ENTRYPOINT ["/entrypoint.sh"]
|