gdo image: trust the registry's key instead of skipping the check
deploy / deploy (push) Failing after 3s
deploy / deploy (push) Failing after 3s
This commit is contained in:
+18
-1
@@ -4,7 +4,23 @@
|
||||
# is built from that instead.
|
||||
FROM archlinux:base
|
||||
ARG GDO_RELEASE
|
||||
RUN printf '%s\n' \
|
||||
|
||||
# The registry's signing key, vendored beside this file. A fresh
|
||||
# container trusts nothing, and the key is on no public keyserver, so
|
||||
# `pacman-key --recv-keys` cannot find it - which is why this is here
|
||||
# rather than fetched. It is a public key: checked in, not a secret.
|
||||
#
|
||||
# Vendored rather than turning the signature check off: the packages
|
||||
# come over HTTPS from a host we run, and it would be easy to call that
|
||||
# good enough, but then nothing would notice a package that host did
|
||||
# not sign. Locally signed, the check stays real.
|
||||
COPY uhhm-registry.asc /tmp/uhhm-registry.asc
|
||||
RUN pacman-key --init \
|
||||
&& pacman-key --populate archlinux \
|
||||
&& pacman-key --add /tmp/uhhm-registry.asc \
|
||||
&& pacman-key --lsign-key 1BCBE90F04AD9859D7BCC9BB53CBF90AA4C56211 \
|
||||
&& rm /tmp/uhhm-registry.asc \
|
||||
&& printf '%s\n' \
|
||||
'[uhhm]' \
|
||||
'SigLevel = Required DatabaseOptional' \
|
||||
'Server = https://project.uhhm.no/api/packages/bl/arch/$repo/$arch' \
|
||||
@@ -12,6 +28,7 @@ RUN printf '%s\n' \
|
||||
&& pacman -Sy --noconfirm --needed ca-certificates gdo \
|
||||
&& pacman -Scc --noconfirm \
|
||||
&& rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/*
|
||||
|
||||
# A non-root user; gdo writes nothing and holds no state - what it has
|
||||
# not yet delivered is on the stream, not on disk.
|
||||
RUN useradd --system --no-create-home gdo
|
||||
|
||||
Reference in New Issue
Block a user