Add the building blocks the provisioning CLI renders per site. Base images (site-templates/images): - php-fpm: non-root (www-data) php:<ver>-fpm-alpine with pdo_mysql, mysqli, gd, intl, zip, opcache, exif; tuned php.ini + pool; built per PHP version. - nginx: hardened nginx:1.27-alpine with shared security + fastcgi snippets; per-site server block mounted at runtime. - build.sh: build + Trivy-scan (+ optional push) for both images. Profile templates (site-templates/profiles), Jinja2 rendered: - static, redirect (tiny nginx 301/302), custom-php (nginx + our php-fpm, optional DB), wordpress (nginx + official wordpress-fpm, DB required, upload-exec denied). Only nginx carries Traefik labels and joins proxy; php-fpm uses the private <slug>_net and joins platform only when a DB is needed. Secrets stay in a git-ignored .env, not the compose. CI: .forgejo/workflows/images.yml builds/scans images (gitleaks + Trivy). README documents the render context and the Phase 4 web-root ownership item. Templates validated: all profiles render to valid compose YAML across the database on/off branches and single/multi-domain host rules. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
38 lines
1.2 KiB
Bash
Executable file
38 lines
1.2 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Build (and optionally scan/push) the heleos base images.
|
|
#
|
|
# REGISTRY=git.example.com/heleos ./build.sh # build + Trivy scan
|
|
# REGISTRY=git.example.com/heleos PUSH=1 ./build.sh # also push
|
|
#
|
|
# PHP_VERSIONS controls which php-fpm tags are built.
|
|
set -euo pipefail
|
|
|
|
REGISTRY="${REGISTRY:-heleos}" # e.g. git.example.com/heleos
|
|
PUSH="${PUSH:-0}"
|
|
SCAN="${SCAN:-1}" # run Trivy if available
|
|
PHP_VERSIONS="${PHP_VERSIONS:-8.3 8.2}"
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
|
|
scan() {
|
|
if [ "$SCAN" = "1" ] && command -v trivy >/dev/null 2>&1; then
|
|
trivy image --severity HIGH,CRITICAL --exit-code 1 --no-progress "$1"
|
|
else
|
|
echo " (skipping Trivy scan for $1)"
|
|
fi
|
|
}
|
|
|
|
maybe_push() { [ "$PUSH" = "1" ] && docker push "$1" || true; }
|
|
|
|
echo "==> nginx"
|
|
docker build -t "${REGISTRY}/nginx:latest" "${HERE}/nginx"
|
|
scan "${REGISTRY}/nginx:latest"
|
|
maybe_push "${REGISTRY}/nginx:latest"
|
|
|
|
for v in $PHP_VERSIONS; do
|
|
echo "==> php-fpm ${v}"
|
|
docker build --build-arg "PHP_VERSION=${v}" -t "${REGISTRY}/php-fpm:${v}" "${HERE}/php-fpm"
|
|
scan "${REGISTRY}/php-fpm:${v}"
|
|
maybe_push "${REGISTRY}/php-fpm:${v}"
|
|
done
|
|
|
|
echo "Done."
|