mirror of
https://github.com/phusion/baseimage-docker.git
synced 2026-09-21 08:48:10 +00:00
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
012fe6b1fc | ||
|
|
abf78de0f2 |
@@ -27,15 +27,13 @@ jobs:
|
||||
TAGS="${DOCKER_IMAGE}:${GIT_BRANCH}, ghcr.io/${{ github.repository_owner }}/baseimage:${GIT_BRANCH}"
|
||||
|
||||
# Determine BASE_IMAGE from release tag prefix (e.g. noble-1.0.2 -> ubuntu:24.04)
|
||||
if [[ "${GIT_BRANCH}" == resolute-* ]]; then
|
||||
BASE_IMAGE="ubuntu:26.04"
|
||||
elif [[ "${GIT_BRANCH}" == noble-* ]]; then
|
||||
if [[ "${GIT_BRANCH}" == noble-* ]]; then
|
||||
BASE_IMAGE="ubuntu:24.04"
|
||||
elif [[ "${GIT_BRANCH}" == jammy-* ]]; then
|
||||
BASE_IMAGE="ubuntu:22.04"
|
||||
else
|
||||
# Default to noble (latest LTS) for unrecognised tag prefixes
|
||||
echo "::warning::Unrecognized release tag prefix '${GIT_BRANCH}'. Expected it to start with 'resolute-', 'noble-', or 'jammy-'. Defaulting BASE_IMAGE to ubuntu:24.04 (Noble)."
|
||||
echo "::warning::Unrecognized release tag prefix '${GIT_BRANCH}'. Expected it to start with 'noble-' or 'jammy-'. Defaulting BASE_IMAGE to ubuntu:24.04 (Noble)."
|
||||
BASE_IMAGE="ubuntu:24.04"
|
||||
fi
|
||||
|
||||
|
||||
@@ -8,8 +8,6 @@ on:
|
||||
permissions:
|
||||
contents: write
|
||||
packages: write
|
||||
id-token: write
|
||||
pull-requests: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
@@ -17,14 +15,10 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
packages: write
|
||||
id-token: write
|
||||
pull-requests: read
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- ubuntu_codename: resolute
|
||||
base_image: ubuntu:26.04
|
||||
- ubuntu_codename: noble
|
||||
base_image: ubuntu:24.04
|
||||
- ubuntu_codename: jammy
|
||||
@@ -35,43 +29,34 @@ jobs:
|
||||
run: |
|
||||
LATEST_TAG=$(gh release list \
|
||||
--repo ${{ github.repository }} \
|
||||
--limit 100 \
|
||||
--exclude-pre-releases \
|
||||
--exclude-drafts \
|
||||
--json tagName \
|
||||
--jq "[.[] | select(.tagName | startswith(\"${{ matrix.ubuntu_codename }}-\"))] | first | .tagName // empty")
|
||||
|
||||
--jq '[.[] | select(.tagName | startswith("${{ matrix.ubuntu_codename }}-"))] | first | .tagName')
|
||||
if [ -z "${LATEST_TAG}" ]; then
|
||||
echo "No release found for ${{ matrix.ubuntu_codename }} track. Skipping."
|
||||
echo "should_build=false" >> $GITHUB_OUTPUT
|
||||
exit 0
|
||||
echo "No release found for ${{ matrix.ubuntu_codename }} track" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Extract version and bump patch: noble-1.0.2 -> noble-1.0.3
|
||||
if ! echo "${LATEST_TAG}" | grep -qE '^[a-z]+-[0-9]+\.[0-9]+\.[0-9]+$'; then
|
||||
echo "Tag '${LATEST_TAG}' does not match expected format <codename>-<major>.<minor>.<patch>" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
PREFIX="${LATEST_TAG%.*}" # noble-1.0
|
||||
PATCH="${LATEST_TAG##*.}" # 2
|
||||
NEXT_PATCH=$((PATCH + 1))
|
||||
NEXT_TAG="${PREFIX}.${NEXT_PATCH}" # noble-1.0.3
|
||||
|
||||
echo "current_tag=${LATEST_TAG}" >> $GITHUB_OUTPUT
|
||||
echo "next_tag=${NEXT_TAG}" >> $GITHUB_OUTPUT
|
||||
echo "should_build=true" >> $GITHUB_OUTPUT
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Checkout release tag
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ steps.release.outputs.current_tag }}
|
||||
|
||||
- name: Prepare
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
id: prep
|
||||
run: |
|
||||
DOCKER_IMAGE=phusion/baseimage
|
||||
@@ -85,13 +70,11 @@ jobs:
|
||||
echo "platforms=${PLATFORMS}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Set up QEMU
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: docker/setup-qemu-action@v3
|
||||
with:
|
||||
platforms: ${{ steps.prep.outputs.platforms }}
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: docker/setup-buildx-action@v3
|
||||
with:
|
||||
install: true
|
||||
@@ -99,22 +82,19 @@ jobs:
|
||||
driver-opts: image=moby/buildkit:latest
|
||||
|
||||
- name: Login to GHCR (Github Container Registry)
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.actor }}
|
||||
password: ${{ github.token }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Login to Docker Hub
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
|
||||
- name: Build and Push
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: image
|
||||
@@ -124,57 +104,18 @@ jobs:
|
||||
build-args: BASE_IMAGE=${{ matrix.base_image }}
|
||||
no-cache: true
|
||||
|
||||
- name: Check gh auth status
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
run: gh auth status
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
|
||||
- name: Create GitHub Release
|
||||
if: steps.release.outputs.should_build == 'true'
|
||||
run: |
|
||||
cat <<EOF > release_notes.md
|
||||
Automated weekly security rebuild of \`${{ steps.release.outputs.current_tag }}\` with latest \`${{ matrix.base_image }}\` packages.
|
||||
gh release create "${{ steps.release.outputs.next_tag }}" \
|
||||
--repo "${{ github.repository }}" \
|
||||
--target "${{ steps.release.outputs.current_tag }}" \
|
||||
--title "${{ steps.release.outputs.next_tag }}" \
|
||||
--notes "Automated weekly security rebuild of \`${{ steps.release.outputs.current_tag }}\` with latest \`${{ matrix.base_image }}\` packages.
|
||||
|
||||
Images pushed:
|
||||
- \`phusion/baseimage:${{ steps.release.outputs.next_tag }}\`
|
||||
- \`phusion/baseimage:${{ matrix.ubuntu_codename }}\`
|
||||
- \`ghcr.io/${{ github.repository_owner }}/baseimage:${{ steps.release.outputs.next_tag }}\`
|
||||
- \`ghcr.io/${{ github.repository_owner }}/baseimage:${{ matrix.ubuntu_codename }}\`
|
||||
EOF
|
||||
|
||||
set +e
|
||||
GH_RELEASE_OUTPUT=$(gh release create "${{ steps.release.outputs.next_tag }}" \
|
||||
--repo "${{ github.repository }}" \
|
||||
--target "$(git rev-parse HEAD)" \
|
||||
--title "${{ steps.release.outputs.next_tag }}" \
|
||||
--notes-file release_notes.md 2>&1)
|
||||
GH_RELEASE_EXIT_CODE=$?
|
||||
set -e
|
||||
|
||||
if [ "${GH_RELEASE_EXIT_CODE}" -ne 0 ]; then
|
||||
RELEASE_PERMISSION_WARNING="Skipping GitHub release creation for ${{ steps.release.outputs.next_tag }} because the workflow token cannot create releases."
|
||||
IS_PERMISSION_DENIED=false
|
||||
PERMISSION_PATTERN_MATCH=false
|
||||
if echo "${GH_RELEASE_OUTPUT}" | grep -Eqi "HTTP 403|Resource not accessible by integration|permission|denied"; then
|
||||
PERMISSION_PATTERN_MATCH=true
|
||||
fi
|
||||
|
||||
if [ "${GH_RELEASE_EXIT_CODE}" -eq 4 ] || [ "${PERMISSION_PATTERN_MATCH}" = "true" ]; then
|
||||
IS_PERMISSION_DENIED=true
|
||||
fi
|
||||
|
||||
if [ "${IS_PERMISSION_DENIED}" = "true" ]; then
|
||||
MAX_RELEASE_OUTPUT_SUMMARY_LENGTH=500
|
||||
GH_RELEASE_OUTPUT_SINGLE_LINE="${GH_RELEASE_OUTPUT//$'\n'/ }"
|
||||
GH_RELEASE_OUTPUT_SUMMARY="${GH_RELEASE_OUTPUT_SINGLE_LINE:0:${MAX_RELEASE_OUTPUT_SUMMARY_LENGTH}}"
|
||||
echo "::warning::${RELEASE_PERMISSION_WARNING}. gh output: ${GH_RELEASE_OUTPUT_SUMMARY}"
|
||||
else
|
||||
echo "::error::${GH_RELEASE_OUTPUT}"
|
||||
exit ${GH_RELEASE_EXIT_CODE}
|
||||
fi
|
||||
else
|
||||
echo "${GH_RELEASE_OUTPUT}"
|
||||
fi
|
||||
- \`ghcr.io/${{ github.repository_owner }}/baseimage:${{ matrix.ubuntu_codename }}\`"
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
@@ -71,8 +71,7 @@ You can configure the stock `ubuntu` image yourself from your Dockerfile, so why
|
||||
* [Using your own key](#using_your_own_key)
|
||||
* [The `docker-ssh` tool](#docker_ssh)
|
||||
* [Building the image yourself](#building)
|
||||
* [Removing optional services](#removing_optional_services)
|
||||
* [Ubuntu 26.04 LTS: Rust Coreutils](#ubuntu_2604_rust)
|
||||
* [Removing optional services](#removing_optional_services)
|
||||
* [Conclusion](#conclusion)
|
||||
|
||||
-----------------------------------------
|
||||
@@ -87,7 +86,7 @@ You can configure the stock `ubuntu` image yourself from your Dockerfile, so why
|
||||
|
||||
| Component | Why is it included? / Remarks |
|
||||
| ---------------- | ------------------- |
|
||||
| Ubuntu 26.04 LTS (Resolute) or 24.04 LTS (Noble) | The base system. Ubuntu 26.04 "Resolute" is the latest LTS; 24.04 "Noble" and 22.04 "Jammy" tracks are also maintained. **Note:** Ubuntu 26.04 ships [Rust Coreutils (uutils coreutils)](#ubuntu_2604_rust) instead of GNU Coreutils. See the [dedicated section](#ubuntu_2604_rust) for details and alternatives. |
|
||||
| Ubuntu 24.04 LTS | The base system. |
|
||||
| A **correct** init process | _Main article: [Docker and the PID 1 zombie reaping problem](http://blog.phusion.nl/2015/01/20/docker-and-the-pid-1-zombie-reaping-problem/)._ <br><br>According to the Unix process model, [the init process](https://en.wikipedia.org/wiki/Init) -- PID 1 -- inherits all [orphaned child processes](https://en.wikipedia.org/wiki/Orphan_process) and must [reap them](https://en.wikipedia.org/wiki/Wait_(system_call)). Most Docker containers do not have an init process that does this correctly. As a result, their containers become filled with [zombie processes](https://en.wikipedia.org/wiki/Zombie_process) over time. <br><br>Furthermore, `docker stop` sends SIGTERM to the init process, which stops all services. Unfortunately most init systems don't do this correctly within Docker since they're built for hardware shutdowns instead. This causes processes to be hard killed with SIGKILL, which doesn't give them a chance to correctly deinitialize things. This can cause file corruption. <br><br>Baseimage-docker comes with an init process `/sbin/my_init` that performs both of these tasks correctly. |
|
||||
| Fixes APT incompatibilities with Docker | See https://github.com/dotcloud/docker/issues/1024. |
|
||||
| syslog-ng | A syslog daemon is necessary so that many services - including the kernel itself - can correctly log to /var/log/syslog. If no syslog daemon is running, a lot of important messages are silently swallowed. <br><br>Only listens locally. All syslog messages are forwarded to "docker logs".<br><br>Why syslog-ng?<br>I've had bad experience with rsyslog. I regularly run into bugs with rsyslog, and once in a while it takes my log host down by entering a 100% CPU loop in which it can't do anything. Syslog-ng seems to be much more stable. |
|
||||
@@ -637,59 +636,6 @@ You can also set them directly as shown in the following example, to prevent `ss
|
||||
|
||||
Then you can proceed with `make build` command.
|
||||
|
||||
<a name="ubuntu_2604_rust"></a>
|
||||
### Ubuntu 26.04 LTS: Rust Coreutils
|
||||
|
||||
Ubuntu 26.04 LTS introduced two significant changes compared to earlier Ubuntu releases:
|
||||
|
||||
1. **Rust Coreutils (`uutils coreutils`)** — Ubuntu 26.04 ships [uutils coreutils](https://github.com/uutils/coreutils), a Rust-based reimplementation of the GNU Core Utilities (`ls`, `cp`, `mv`, `cat`, etc.), as the default `coreutils` package. This replaces the traditional [GNU Coreutils](https://www.gnu.org/software/coreutils/).
|
||||
|
||||
2. **sudo-rs** — Ubuntu 26.04 ships [sudo-rs](https://github.com/trifectatechfoundation/sudo-rs), a memory-safe Rust reimplementation of `sudo`, as the default `sudo` provider. (This is absent in official Docker image)
|
||||
|
||||
#### Why this matters
|
||||
|
||||
| Concern | Details |
|
||||
|---------|---------|
|
||||
| **Compatibility** | `uutils coreutils` aims for GNU Coreutils compatibility but may have subtle behavioral differences that can break scripts relying on specific GNU flags or output formats. Test your Dockerfiles and scripts carefully when upgrading to the 26.04 base image. |
|
||||
| **Security** | Rust's memory-safety guarantees eliminate whole classes of memory-related vulnerabilities (buffer overflows, use-after-free, etc.). This is generally considered an improvement for security. However, the Rust implementations are newer and have had less real-world exposure than their GNU counterparts. |
|
||||
| **Licensing** | `uutils coreutils` and GNU Coreutils are licensed under different terms: `uutils coreutils` uses the **MIT license**, whereas GNU Coreutils is **GPL-3.0**. Users or organizations with specific license requirements should review these changes. |
|
||||
| **Maturity** | `uutils coreutils` is a newer project. Some edge cases, rarely-used options, or locale-sensitive behavior may differ from the GNU originals. |
|
||||
|
||||
#### Alternatives
|
||||
|
||||
**Option 1: Use the Ubuntu 24.04 LTS base image (recommended if you need GNU tooling)**
|
||||
|
||||
The 24.04 "Noble Numbat" track is fully supported and ships GNU Coreutils:
|
||||
|
||||
```Dockerfile
|
||||
FROM phusion/baseimage:noble-1.0.2
|
||||
```
|
||||
|
||||
Or build the image yourself targeting Ubuntu 24.04:
|
||||
|
||||
```bash
|
||||
make build BASE_IMAGE=ubuntu:24.04
|
||||
```
|
||||
|
||||
**Option 2: Replace Rust Coreutils with GNU Coreutils on Ubuntu 26.04**
|
||||
|
||||
When building baseimage-docker from source, you can set `INSTALL_GNU_COREUTILS=1` to replace `uutils coreutils` with GNU Coreutils:
|
||||
|
||||
```bash
|
||||
docker build --build-arg BASE_IMAGE=ubuntu:26.04 --build-arg INSTALL_GNU_COREUTILS=1 image/
|
||||
```
|
||||
|
||||
Alternatively, you can install GNU Coreutils in your own Dockerfile that derives from a 26.04-based baseimage by removing `uutils coreutils`:
|
||||
|
||||
```Dockerfile
|
||||
FROM phusion/baseimage:<ubuntu-26.04-version>
|
||||
|
||||
# Replace uutils coreutils with GNU Coreutils.
|
||||
RUN apt-get update && \
|
||||
apt-get remove -y --allow-remove-essential coreutils-from-uutils && \
|
||||
apt-get clean && rm -rf /var/lib/apt/lists/*
|
||||
```
|
||||
|
||||
<a name="conclusion"></a>
|
||||
## Conclusion
|
||||
|
||||
|
||||
+1
-6
@@ -4,14 +4,9 @@ FROM $BASE_IMAGE
|
||||
ARG QEMU_ARCH
|
||||
#ADD x86_64_qemu-${QEMU_ARCH}-static.tar.gz /usr/bin
|
||||
|
||||
# Ubuntu 26.04+ ships uutils-coreutils (Rust) by default.
|
||||
# Set INSTALL_GNU_COREUTILS=1 to replace them with GNU Coreutils.
|
||||
# Has no effect on Ubuntu releases prior to 26.04.
|
||||
ARG INSTALL_GNU_COREUTILS=0
|
||||
|
||||
COPY . /bd_build
|
||||
|
||||
RUN INSTALL_GNU_COREUTILS=$INSTALL_GNU_COREUTILS /bd_build/prepare.sh && \
|
||||
RUN /bd_build/prepare.sh && \
|
||||
/bd_build/system_services.sh && \
|
||||
/bd_build/utilities.sh && \
|
||||
/bd_build/cleanup.sh
|
||||
|
||||
@@ -7,8 +7,3 @@ minimal_apt_get_install='apt-get install -y --no-install-recommends'
|
||||
export DISABLE_SYSLOG=${DISABLE_SYSLOG:-0}
|
||||
export DISABLE_SSH=${DISABLE_SSH:-0}
|
||||
export DISABLE_CRON=${DISABLE_CRON:-0}
|
||||
|
||||
# Ubuntu 26.04+ ships uutils-coreutils (Rust) by default.
|
||||
# Set INSTALL_GNU_COREUTILS=1 to replace them with GNU Coreutils.
|
||||
# Has no effect on Ubuntu releases prior to 26.04.
|
||||
export INSTALL_GNU_COREUTILS=${INSTALL_GNU_COREUTILS:-0}
|
||||
|
||||
+3
-54
@@ -12,21 +12,9 @@ echo -n no > /etc/container_environment/INITRD
|
||||
|
||||
## Enable Ubuntu Universe, Multiverse, and deb-src for main.
|
||||
if grep -E '^ID=' /etc/os-release | grep -q ubuntu; then
|
||||
UBUNTU_VERSION=$(grep '^VERSION_ID=' /etc/os-release | cut -d'"' -f2)
|
||||
# Ubuntu 24.04+ uses DEB822 format (.sources files); older releases use sources.list
|
||||
if dpkg --compare-versions "$UBUNTU_VERSION" ge "24.04" 2>/dev/null && \
|
||||
compgen -G '/etc/apt/sources.list.d/*.sources' > /dev/null; then
|
||||
# DEB822 format: enable universe and multiverse components
|
||||
for f in /etc/apt/sources.list.d/*.sources; do
|
||||
sed -i 's/^Components: main$/Components: main restricted universe multiverse/' "$f"
|
||||
sed -i 's/^Components: main restricted$/Components: main restricted universe multiverse/' "$f"
|
||||
done
|
||||
else
|
||||
# Legacy sources.list format (Ubuntu < 24.04)
|
||||
sed -i 's/^#\s*\(deb.*main restricted\)$/\1/g' /etc/apt/sources.list
|
||||
sed -i 's/^#\s*\(deb.*universe\)$/\1/g' /etc/apt/sources.list
|
||||
sed -i 's/^#\s*\(deb.*multiverse\)$/\1/g' /etc/apt/sources.list
|
||||
fi
|
||||
sed -i 's/^#\s*\(deb.*main restricted\)$/\1/g' /etc/apt/sources.list
|
||||
sed -i 's/^#\s*\(deb.*universe\)$/\1/g' /etc/apt/sources.list
|
||||
sed -i 's/^#\s*\(deb.*multiverse\)$/\1/g' /etc/apt/sources.list
|
||||
fi
|
||||
|
||||
apt-get update
|
||||
@@ -55,45 +43,6 @@ $minimal_apt_get_install software-properties-common
|
||||
## Upgrade all packages.
|
||||
apt-get dist-upgrade -y --no-install-recommends -o Dpkg::Options::="--force-confold"
|
||||
|
||||
## Ubuntu 26.04+ ships uutils-coreutils (Rust) by default.
|
||||
## Optionally replace them with GNU Coreutils when
|
||||
## INSTALL_GNU_COREUTILS=1 is set at build time.
|
||||
if grep -E '^ID=' /etc/os-release | grep -q ubuntu; then
|
||||
UBUNTU_VERSION=$(grep '^VERSION_ID=' /etc/os-release | cut -d'"' -f2)
|
||||
if dpkg --compare-versions "$UBUNTU_VERSION" ge "26.04" 2>/dev/null; then
|
||||
case "${INSTALL_GNU_COREUTILS:-0}" in
|
||||
0|1)
|
||||
INSTALL_GNU_COREUTILS_NORMALIZED="${INSTALL_GNU_COREUTILS:-0}"
|
||||
;;
|
||||
*)
|
||||
echo "*** Invalid value for INSTALL_GNU_COREUTILS: '${INSTALL_GNU_COREUTILS}'" >&2
|
||||
echo "*** Expected 0 or 1." >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
if [ "$INSTALL_GNU_COREUTILS_NORMALIZED" = "1" ]; then
|
||||
echo "*** Removing Rust to restore GNU Coreutils..."
|
||||
# GNU Coreutils can only be installed by removing `coreutils-from-uutils`
|
||||
apt-get remove -y --allow-remove-essential coreutils-from-uutils
|
||||
# Verify that GNU coreutils are now the active implementation on PATH.
|
||||
# Some packages may install binaries under a non-default path and rely on
|
||||
# update-alternatives; if so the replacement has not taken effect.
|
||||
if ! ls --version 2>&1 | grep -qi 'gnu coreutils'; then
|
||||
echo "*** ERROR: coreutils-from-gnu was installed but GNU coreutils are not active on PATH." >&2
|
||||
echo "*** 'ls --version' does not report 'GNU coreutils'." >&2
|
||||
echo "*** The package may place binaries outside the default PATH or require" >&2
|
||||
echo "*** manual update-alternatives configuration. Check Ubuntu 26.04 packaging." >&2
|
||||
exit 1
|
||||
fi
|
||||
LS_VER=$(ls --version | head -1)
|
||||
echo "*** GNU Coreutils are active ($LS_VER)."
|
||||
else
|
||||
echo "*** Ubuntu 26.04 detected: using default uutils-coreutils (Rust)."
|
||||
echo "*** Set INSTALL_GNU_COREUTILS=1 at build time to use GNU Coreutils instead."
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
## Fix locale.
|
||||
case $(lsb_release -is) in
|
||||
Ubuntu)
|
||||
|
||||
@@ -7,8 +7,8 @@ SSHD_BUILD_PATH=/bd_build/services/sshd
|
||||
|
||||
## Install the SSH server.
|
||||
$minimal_apt_get_install openssh-server
|
||||
mkdir -p /var/run/sshd
|
||||
mkdir -p /etc/service/sshd
|
||||
mkdir /var/run/sshd
|
||||
mkdir /etc/service/sshd
|
||||
touch /etc/service/sshd/down
|
||||
cp $SSHD_BUILD_PATH/sshd.runit /etc/service/sshd/run
|
||||
cp $SSHD_BUILD_PATH/sshd_config /etc/ssh/sshd_config
|
||||
|
||||
@@ -22,16 +22,10 @@ ln -s /etc/container_environment.sh /etc/profile.d/
|
||||
$minimal_apt_get_install runit
|
||||
|
||||
## Install a syslog daemon and logrotate.
|
||||
if [ "$DISABLE_SYSLOG" -eq 0 ]; then
|
||||
/bd_build/services/syslog-ng/syslog-ng.sh
|
||||
fi
|
||||
[ "$DISABLE_SYSLOG" -eq 0 ] && /bd_build/services/syslog-ng/syslog-ng.sh || true
|
||||
|
||||
## Install the SSH server.
|
||||
if [ "$DISABLE_SSH" -eq 0 ]; then
|
||||
/bd_build/services/sshd/sshd.sh
|
||||
fi
|
||||
[ "$DISABLE_SSH" -eq 0 ] && /bd_build/services/sshd/sshd.sh || true
|
||||
|
||||
## Install cron daemon.
|
||||
if [ "$DISABLE_CRON" -eq 0 ]; then
|
||||
/bd_build/services/cron/cron.sh
|
||||
fi
|
||||
[ "$DISABLE_CRON" -eq 0 ] && /bd_build/services/cron/cron.sh || true
|
||||
|
||||
Reference in New Issue
Block a user