Merge pull request #187 from ellerbrock/best-practices

build(docker): add docker best practices
This commit is contained in:
Thomas Sjögren 2017-01-26 14:29:50 +01:00 committed by GitHub
commit 8fdb514dba
2 changed files with 20 additions and 40 deletions

View file

@ -4,29 +4,19 @@ LABEL org.label-schema.name="docker-bench-security" \
org.label-schema.url="https://dockerbench.com" \ org.label-schema.url="https://dockerbench.com" \
org.label-schema.vcs-url="https://github.com/docker/docker-bench-security.git" org.label-schema.vcs-url="https://github.com/docker/docker-bench-security.git"
ENV VERSION 1.12.6 RUN \
ENV SHA256 cadc6025c841e034506703a06cf54204e51d0cadfae4bae62628ac648d82efdd apk add --no-cache \
docker \
dumb-init && \
rm -rf /usr/bin/docker-* /usr/bin/dockerd && \
mkdir /usr/local/bin/tests
WORKDIR /usr/bin COPY ./*.sh /usr/local/bin/
RUN apk update && \ COPY ./tests/*.sh /usr/local/bin/tests/
apk upgrade && \
apk --update add coreutils wget ca-certificates && \
wget https://get.docker.com/builds/Linux/x86_64/docker-$VERSION.tgz && \
wget https://get.docker.com/builds/Linux/x86_64/docker-$VERSION.tgz.sha256 && \
sha256sum -c docker-$VERSION.tgz.sha256 && \
echo "$SHA256 docker-$VERSION.tgz" | sha256sum -c - && \
tar -xzvf docker-$VERSION.tgz -C /tmp && \
mv /tmp/docker/docker . && \
chmod u+x docker* && \
rm -rf /tmp/docker* && \
apk del wget ca-certificates && \
rm -rf /var/cache/apk/* docker-$VERSION.tgz docker-$VERSION.tgz.sha256
RUN mkdir /docker-bench-security
COPY . /docker-bench-security WORKDIR /usr/local/bin
WORKDIR /docker-bench-security ENTRYPOINT [ "/usr/bin/dumb-init", "docker-bench-security.sh" ]
ENTRYPOINT ["/bin/sh", "docker-bench-security.sh"]

View file

@ -4,29 +4,19 @@ LABEL org.label-schema.name="docker-bench-security" \
org.label-schema.url="https://dockerbench.com" \ org.label-schema.url="https://dockerbench.com" \
org.label-schema.vcs-url="https://github.com/docker/docker-bench-security.git" org.label-schema.vcs-url="https://github.com/docker/docker-bench-security.git"
ENV VERSION 1.12.6 RUN \
ENV SHA256 cadc6025c841e034506703a06cf54204e51d0cadfae4bae62628ac648d82efdd apk add --no-cache \
docker \
dumb-init && \
rm -rf /usr/bin/docker-* /usr/bin/dockerd && \
mkdir /usr/local/bin/tests
WORKDIR /usr/bin COPY ./*.sh /usr/local/bin/
RUN apk update && \ COPY ./tests/*.sh /usr/local/bin/tests/
apk upgrade && \
apk --update add coreutils wget ca-certificates && \
wget https://get.docker.com/builds/Linux/x86_64/docker-$VERSION.tgz && \
wget https://get.docker.com/builds/Linux/x86_64/docker-$VERSION.tgz.sha256 && \
sha256sum -c docker-$VERSION.tgz.sha256 && \
echo "$SHA256 docker-$VERSION.tgz" | sha256sum -c - && \
tar -xzvf docker-$VERSION.tgz -C /tmp && \
mv /tmp/docker/docker . && \
chmod u+x docker* && \
rm -rf /tmp/docker* && \
apk del wget ca-certificates && \
rm -rf /var/cache/apk/* docker-$VERSION.tgz docker-$VERSION.tgz.sha256
RUN mkdir /docker-bench-security
COPY . /docker-bench-security WORKDIR /usr/local/bin
WORKDIR /docker-bench-security ENTRYPOINT [ "/usr/bin/dumb-init", "docker-bench-security.sh" ]
ENTRYPOINT ["/bin/sh", "docker-bench-security.sh"]