# gdo, the mailer, from the [uhhm] Arch registry - the same package the # bare-metal hosts install. Arch base rather than Debian because that is # how every uhhm binary is published; portal ships a release tarball and # is built from that instead. FROM archlinux:base ARG GDO_RELEASE # The registry's signing key, vendored beside this file. A fresh # container trusts nothing, and the key is on no public keyserver, so # `pacman-key --recv-keys` cannot find it - which is why this is here # rather than fetched. It is a public key: checked in, not a secret. # # Vendored rather than turning the signature check off: the packages # come over HTTPS from a host we run, and it would be easy to call that # good enough, but then nothing would notice a package that host did # not sign. Locally signed, the check stays real. COPY uhhm-registry.asc /tmp/uhhm-registry.asc RUN pacman-key --init \ && pacman-key --populate archlinux \ && pacman-key --add /tmp/uhhm-registry.asc \ && pacman-key --lsign-key 1BCBE90F04AD9859D7BCC9BB53CBF90AA4C56211 \ && rm /tmp/uhhm-registry.asc \ && printf '%s\n' \ '[uhhm]' \ 'SigLevel = Required DatabaseOptional' \ 'Server = https://project.uhhm.no/api/packages/bl/arch/$repo/$arch' \ >> /etc/pacman.conf \ && pacman -Sy --noconfirm --needed ca-certificates gdo \ && pacman -Scc --noconfirm \ && rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/* # A non-root user; gdo writes nothing and holds no state - what it has # not yet delivered is on the stream, not on disk. RUN useradd --system --no-create-home gdo USER gdo CMD ["/usr/bin/gdo"]