2021-04-06 23:20:21 +02:00
|
|
|
package docker
|
|
|
|
|
|
|
|
import (
|
|
|
|
"dagger.io/dagger"
|
|
|
|
"dagger.io/dagger/op"
|
|
|
|
)
|
|
|
|
|
|
|
|
// Build a Docker image from source, using included Dockerfile
|
2021-05-01 09:14:36 +02:00
|
|
|
#Build: {
|
2021-05-26 12:23:44 +02:00
|
|
|
source: dagger.#Artifact @dagger(input)
|
2021-04-06 23:20:21 +02:00
|
|
|
|
|
|
|
#up: [
|
|
|
|
op.#DockerBuild & {
|
|
|
|
context: source
|
|
|
|
},
|
|
|
|
]
|
2021-05-01 09:14:36 +02:00
|
|
|
|
2021-04-06 23:20:21 +02:00
|
|
|
}
|
|
|
|
|
2021-05-06 08:53:04 +02:00
|
|
|
// Pull a docker container
|
|
|
|
#Pull: {
|
|
|
|
// Remote ref (example: "index.docker.io/alpine:latest")
|
2021-05-26 12:23:44 +02:00
|
|
|
from: string @dagger(input)
|
2021-04-06 23:20:21 +02:00
|
|
|
|
|
|
|
#up: [
|
2021-05-06 08:53:04 +02:00
|
|
|
op.#FetchContainer & {ref: from},
|
2021-04-06 23:20:21 +02:00
|
|
|
]
|
|
|
|
}
|
|
|
|
|
2021-05-13 18:52:22 +02:00
|
|
|
// Push a docker image
|
|
|
|
#Push: {
|
|
|
|
// Remote ref (example: "index.docker.io/alpine:latest")
|
2021-05-26 12:23:44 +02:00
|
|
|
ref: string @dagger(input)
|
2021-05-13 18:52:22 +02:00
|
|
|
|
|
|
|
// Image
|
2021-05-26 12:23:44 +02:00
|
|
|
source: dagger.#Artifact @dagger(input)
|
2021-05-13 18:52:22 +02:00
|
|
|
|
|
|
|
#up: [
|
|
|
|
op.#Load & {from: source},
|
|
|
|
op.#PushContainer & {"ref": ref},
|
|
|
|
]
|
|
|
|
}
|
|
|
|
|
2021-05-20 19:25:44 +02:00
|
|
|
#Run: {
|
|
|
|
// Remote host
|
2021-05-21 17:18:30 +02:00
|
|
|
host: string @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Remote user
|
2021-05-21 17:18:30 +02:00
|
|
|
user: string @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Ssh remote port
|
2021-05-21 17:18:30 +02:00
|
|
|
port: *22 | int @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Ssh private key
|
2021-06-03 13:59:22 +02:00
|
|
|
key: dagger.#Secret @dagger(input)
|
2021-05-21 17:18:30 +02:00
|
|
|
|
|
|
|
// User fingerprint
|
|
|
|
fingerprint?: string @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Ssh passphrase
|
2021-06-03 13:59:22 +02:00
|
|
|
passphrase?: dagger.#Secret @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Image reference (e.g: nginx:alpine)
|
2021-05-21 17:18:30 +02:00
|
|
|
ref: string @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Container name
|
2021-05-21 17:18:30 +02:00
|
|
|
name?: string @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
// Image registry
|
|
|
|
registry?: {
|
2021-05-20 19:26:24 +02:00
|
|
|
target: string
|
2021-05-20 19:25:44 +02:00
|
|
|
username: string
|
|
|
|
secret: dagger.#Secret
|
2021-05-21 17:18:30 +02:00
|
|
|
} @dagger(input)
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
#code: #"""
|
2021-05-21 17:18:30 +02:00
|
|
|
export DOCKER_HOST="ssh://$DOCKER_USERNAME@$DOCKER_HOSTNAME:\#(port)"
|
|
|
|
|
|
|
|
# Start ssh-agent
|
|
|
|
eval $(ssh-agent) > /dev/null
|
|
|
|
|
|
|
|
# Add key
|
|
|
|
message="$(ssh-keygen -y -f /key < /dev/null 2>&1)" || {
|
|
|
|
>&2 echo "$message"
|
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
|
|
|
|
ssh-add /key > /dev/null
|
|
|
|
if [ "$?" != 0 ]; then
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [[ ! -z $FINGERPRINT ]]; then
|
|
|
|
mkdir -p "$HOME"/.ssh
|
2021-05-20 19:25:44 +02:00
|
|
|
|
2021-05-21 17:18:30 +02:00
|
|
|
# Add user's fingerprint to known hosts
|
|
|
|
echo "$FINGERPRINT" >> "$HOME"/.ssh/known_hosts
|
|
|
|
else
|
|
|
|
# Add host to known hosts
|
|
|
|
ssh -i /key -o "UserKnownHostsFile "$HOME"/.ssh/known_hosts" -o "StrictHostKeyChecking accept-new" -p \#(port) "$DOCKER_USERNAME"@"$DOCKER_HOSTNAME" /bin/true > /dev/null 2>&1
|
|
|
|
fi
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
|
2021-05-21 17:18:30 +02:00
|
|
|
# Run detach container
|
|
|
|
OPTS=""
|
2021-05-20 19:25:44 +02:00
|
|
|
|
2021-05-21 17:18:30 +02:00
|
|
|
if [ ! -z "$CONTAINER_NAME" ]; then
|
|
|
|
OPTS="$OPTS --name $CONTAINER_NAME"
|
|
|
|
fi
|
2021-05-20 19:25:44 +02:00
|
|
|
|
2021-05-21 17:18:30 +02:00
|
|
|
docker container run -d $OPTS \#(ref)
|
2021-05-20 19:25:44 +02:00
|
|
|
"""#
|
|
|
|
|
|
|
|
#up: [
|
2021-05-21 16:55:51 +02:00
|
|
|
op.#Load & {from: #Client},
|
2021-05-20 19:25:44 +02:00
|
|
|
|
|
|
|
if registry != _|_ {
|
|
|
|
op.#DockerLogin & {registry}
|
|
|
|
},
|
|
|
|
|
2021-05-21 17:18:30 +02:00
|
|
|
if passphrase != _|_ {
|
|
|
|
op.#WriteFile & {
|
|
|
|
content: #"""
|
|
|
|
#!/bin/bash
|
|
|
|
cat /passphrase
|
|
|
|
"""#
|
|
|
|
dest: "/get_passphrase"
|
|
|
|
mode: 0o500
|
2021-05-20 19:25:44 +02:00
|
|
|
}
|
|
|
|
},
|
|
|
|
|
|
|
|
op.#WriteFile & {
|
|
|
|
content: #code
|
|
|
|
dest: "/entrypoint.sh"
|
|
|
|
},
|
|
|
|
|
|
|
|
op.#Exec & {
|
|
|
|
always: true
|
|
|
|
args: [
|
|
|
|
"/bin/sh",
|
|
|
|
"--noprofile",
|
|
|
|
"--norc",
|
|
|
|
"-eo",
|
|
|
|
"pipefail",
|
|
|
|
"/entrypoint.sh",
|
|
|
|
]
|
|
|
|
env: {
|
2021-05-21 17:18:30 +02:00
|
|
|
DOCKER_HOSTNAME: host
|
|
|
|
DOCKER_USERNAME: user
|
2021-05-20 19:25:44 +02:00
|
|
|
if passphrase != _|_ {
|
2021-05-21 17:18:30 +02:00
|
|
|
SSH_ASKPASS: "/get_passphrase"
|
|
|
|
DISPLAY: "1"
|
2021-05-20 19:25:44 +02:00
|
|
|
}
|
|
|
|
if name != _|_ {
|
|
|
|
CONTAINER_NAME: name
|
|
|
|
}
|
2021-05-21 17:18:30 +02:00
|
|
|
if fingerprint != _|_ {
|
|
|
|
FINGERPRINT: fingerprint
|
|
|
|
}
|
2021-05-20 19:25:44 +02:00
|
|
|
}
|
2021-06-03 13:59:22 +02:00
|
|
|
mount: {
|
|
|
|
"/key": secret: key
|
|
|
|
if passphrase != _|_ {
|
|
|
|
"/passphrase": secret: passphrase
|
|
|
|
}
|
|
|
|
}
|
2021-05-20 19:25:44 +02:00
|
|
|
},
|
|
|
|
]
|
|
|
|
}
|
2021-05-06 08:53:04 +02:00
|
|
|
|
2021-04-06 23:20:21 +02:00
|
|
|
// Build a Docker image from the provided Dockerfile contents
|
2021-05-06 08:53:04 +02:00
|
|
|
// FIXME: incorporate into #Build
|
2021-04-06 23:20:21 +02:00
|
|
|
#ImageFromDockerfile: {
|
2021-05-26 12:28:24 +02:00
|
|
|
dockerfile: string @dagger(input)
|
2021-05-26 12:23:44 +02:00
|
|
|
context: dagger.#Artifact @dagger(input)
|
2021-04-06 23:20:21 +02:00
|
|
|
|
|
|
|
#up: [
|
|
|
|
op.#DockerBuild & {
|
|
|
|
"context": context
|
|
|
|
"dockerfile": dockerfile
|
|
|
|
},
|
|
|
|
]
|
|
|
|
}
|