Auto-Deploy on Push / verify-and-notify (push) Canceled after 0s
Almost every tracked file in the repo had drifted to mode 777 on disk (only files created fresh this session were unaffected), and a chunk of that drift had already been committed as spurious +x bits on plain YAML/Markdown files (authentik.yaml, kustomization.yaml, coturn.yaml, element-server-suite.yaml, TASKS.md, install.md, etc.) - none of these need to be executable. Restored to 644 for regular files, 755 only for actual scripts (postCreateCommand.sh, docker-init.sh, install-hooks.sh, pre-commit hook, element-setup-linux.sh). Also found element-setup-macos.command was missing +x despite having a shebang and being meant for double-click execution on macOS - fixed. Added .gitignore for .DS_Store and .claude/ and stopped tracking the five .DS_Store files that had been committed by accident. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
75 lines
3.3 KiB
Docker
75 lines
3.3 KiB
Docker
FROM debian:bookworm-slim
|
|
|
|
# Install base tools
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
curl \
|
|
wget \
|
|
git \
|
|
ca-certificates \
|
|
gnupg \
|
|
lsb-release \
|
|
apt-transport-https \
|
|
vim \
|
|
nano \
|
|
jq \
|
|
yq \
|
|
zsh \
|
|
sudo \
|
|
openssh-client \
|
|
gosu \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install kubectl (apt.kubernetes.io was deprecated/shut down by Google in 2023;
|
|
# pkgs.k8s.io is the current community-owned repo, versioned per k8s minor release)
|
|
RUN mkdir -p /etc/apt/keyrings && \
|
|
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.34/deb/Release.key | gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg && \
|
|
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.34/deb/ /" | tee /etc/apt/sources.list.d/kubernetes.list && \
|
|
apt-get update && apt-get install -y kubectl && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install Helm
|
|
RUN curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
|
|
|
# Install Flux CLI
|
|
RUN curl -s https://fluxcd.io/install.sh | bash
|
|
|
|
# Install sops (arch resolved at build time, same reasoning as the Docker CLI step below)
|
|
RUN SOPS_ARCH=$(dpkg --print-architecture) && \
|
|
SOPS_VERSION=$(curl -s https://api.github.com/repos/getsops/sops/releases/latest | grep tag_name | cut -d '"' -f 4) && \
|
|
curl -sL -o /usr/local/bin/sops https://github.com/getsops/sops/releases/download/${SOPS_VERSION}/sops-${SOPS_VERSION}.linux.${SOPS_ARCH} && \
|
|
chmod +x /usr/local/bin/sops
|
|
|
|
# Install age
|
|
RUN apt-get update && apt-get install -y age && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install Docker CLI (for interacting with Docker daemon)
|
|
# arch is resolved at build time so this works on both amd64 (cloud/CI) and arm64 (Apple Silicon) hosts
|
|
RUN curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg && \
|
|
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null && \
|
|
apt-get update && apt-get install -y docker-ce-cli && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# Create a non-root user 'vscode' for development
|
|
# groupadd is needed because only the Docker CLI (not the daemon) is installed above,
|
|
# so the 'docker' group is never created as a package side effect
|
|
RUN groupadd docker && \
|
|
useradd -m -s /bin/zsh -G docker vscode && \
|
|
echo "vscode ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers.d/vscode
|
|
|
|
# Install oh-my-zsh for better shell experience
|
|
RUN curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -o /tmp/install-omz.sh && \
|
|
su - vscode -c "sh /tmp/install-omz.sh --unattended" && \
|
|
rm /tmp/install-omz.sh
|
|
|
|
# Entrypoint runs as root to reconcile the docker group's GID against the mounted
|
|
# socket (see docker-init.sh), then drops to 'vscode' for the actual session/command.
|
|
# Stays root-owned at the PID 1 level; VS Code's own `docker exec -u vscode` sessions
|
|
# and the entrypoint's `gosu vscode` both end up correctly grouped either way.
|
|
COPY docker-init.sh /usr/local/bin/docker-init.sh
|
|
RUN chmod +x /usr/local/bin/docker-init.sh
|
|
|
|
WORKDIR /workspace
|
|
ENTRYPOINT ["/usr/local/bin/docker-init.sh"]
|
|
CMD ["/bin/zsh"]
|