diff --git a/CHANGELOG.md b/CHANGELOG.md index 885e6a0..38045a5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,8 +5,7 @@ - Begin using a new SQLite database file in `/var/lib/headplane/hp_persist.db`. - The database is created automatically if it does not exist. - It currently stores SSH connection details and will migrate older data. -- The docker container now runs in a non-root, distroless image (closes [#255](https://github.com/tale/headplane/issues/255)). - - You may need to run `chown -R 65532:65532 ` on your data directory to ensure the container can write to it. +- The docker container now runs in a distroless image (closes [#255](https://github.com/tale/headplane/issues/255)). - A debug version of the container that runs as root and has a shell is available as `ghcr.io/tale/headplane:-shell`. - Removing a Split DNS record will no longer make the split domain unresolvable by clients (closes [#231](https://github.com/tale/headplane/issues/231)). - Reintroduce the toggle for overriding local DNS settings in the Headscale config (closes [#236](https://github.com/tale/headplane/issues/236)). diff --git a/Dockerfile b/Dockerfile index c0dea12..8bcfa66 100644 --- a/Dockerfile +++ b/Dockerfile @@ -36,16 +36,16 @@ ARG IMAGE_TAG RUN IMAGE_TAG=$IMAGE_TAG pnpm run build RUN mkdir -p /var/lib/headplane/agent -FROM gcr.io/distroless/nodejs22-debian12:nonroot AS final -COPY --from=js-build --chown=nonroot:nonroot /build/build/ /app/build/ -COPY --from=js-build --chown=nonroot:nonroot /build/drizzle /app/drizzle/ -COPY --from=js-build --chown=nonroot:nonroot /var/lib/headplane /var/lib/headplane -COPY --from=js-build --chown=nonroot:nonroot /build/node_modules/ /app/node_modules/ -COPY --from=go-build --chown=nonroot:nonroot /build/build/hp_agent /usr/libexec/headplane/agent +FROM gcr.io/distroless/nodejs22-debian12:latest AS final +COPY --from=js-build /build/build/ /app/build/ +COPY --from=js-build /build/drizzle /app/drizzle/ +COPY --from=js-build /var/lib/headplane /var/lib/headplane +COPY --from=js-build /build/node_modules/ /app/node_modules/ +COPY --from=go-build /build/build/hp_agent /usr/libexec/headplane/agent # Fake shell to inform the user that they should use the debug image -COPY --from=go-build --chown=nonroot:nonroot /build/build/sh /bin/sh -COPY --from=go-build --chown=nonroot:nonroot /build/build/sh /bin/bash +COPY --from=go-build /build/build/sh /bin/sh +COPY --from=go-build /build/build/sh /bin/bash WORKDIR /app CMD [ "/app/build/server/index.js" ] @@ -53,11 +53,11 @@ CMD [ "/app/build/server/index.js" ] FROM node:22-alpine AS debug-shell RUN apk add --no-cache bash curl git -COPY --from=js-build --chown=nonroot:nonroot /build/build/ /app/build/ -COPY --from=js-build --chown=nonroot:nonroot /build/drizzle /app/drizzle/ -COPY --from=js-build --chown=nonroot:nonroot /var/lib/headplane /var/lib/headplane -COPY --from=js-build --chown=nonroot:nonroot /build/node_modules/ /app/node_modules/ -COPY --from=go-build --chown=nonroot:nonroot /build/build/hp_agent /usr/libexec/headplane/agent +COPY --from=js-build /build/build/ /app/build/ +COPY --from=js-build /build/drizzle /app/drizzle/ +COPY --from=js-build /var/lib/headplane /var/lib/headplane +COPY --from=js-build /build/node_modules/ /app/node_modules/ +COPY --from=go-build /build/build/hp_agent /usr/libexec/headplane/agent WORKDIR /app CMD [ "node", "/app/build/server/index.js" ]