-
Notifications
You must be signed in to change notification settings - Fork 594
/
Dockerfile-dind-rootless.template
46 lines (41 loc) · 1.33 KB
/
Dockerfile-dind-rootless.template
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
{{ include "shared" -}}
FROM docker:{{ env.version }}-dind
# busybox "ip" is insufficient:
# [rootlesskit:child ] error: executing [[ip tuntap add name tap0 mode tap] [ip link set tap0 address 02:50:00:00:00:01]]: exit status 1
RUN apk add --no-cache iproute2 fuse-overlayfs
# "/run/user/UID" will be used by default as the value of XDG_RUNTIME_DIR
RUN mkdir /run/user && chmod 1777 /run/user
# create a default user preconfigured for running rootless dockerd
RUN set -eux; \
adduser -h /home/rootless -g 'Rootless' -D -u 1000 rootless; \
echo 'rootless:100000:65536' >> /etc/subuid; \
echo 'rootless:100000:65536' >> /etc/subgid
RUN set -eux; \
\
{{
download({
arches: .arches,
urlKey: "rootlessExtrasUrl",
# TODO sha256Key (once Docker publishes them 😭)
target: "rootless.tgz",
})
}}; \
\
tar --extract \
--file rootless.tgz \
--strip-components 1 \
--directory /usr/local/bin/ \
'docker-rootless-extras/rootlesskit' \
'docker-rootless-extras/rootlesskit-docker-proxy' \
'docker-rootless-extras/vpnkit' \
; \
rm rootless.tgz; \
\
rootlesskit --version; \
vpnkit --version
# pre-create "/var/lib/docker" for our rootless user
RUN set -eux; \
mkdir -p /home/rootless/.local/share/docker; \
chown -R rootless:rootless /home/rootless/.local/share/docker
VOLUME /home/rootless/.local/share/docker
USER rootless