Commits vergleichen
54 Commits
58178f28ab
...
fe4f2ef530
Autor | SHA1 | Datum | |
---|---|---|---|
fe4f2ef530 | |||
f8f0288137 | |||
4268d0ea7b | |||
55a4d6948c | |||
1a89489d11 | |||
d2d6374824 | |||
75fa33efd9 | |||
87c3a81ee9 | |||
3c3a0be3a6 | |||
d52ca5c0b3 | |||
a86949306c | |||
f4cd8f04d3 | |||
01cfafbc87 | |||
7d9fa942e3 | |||
72ad8b2b08 | |||
e778d763fa | |||
2b9cf8bb00 | |||
9e7def6b20 | |||
665cfd1f08 | |||
fe640319fe | |||
d7e174e892 | |||
ef7f87025b | |||
19db78eb83 | |||
c3c388a146 | |||
169f6b0bad | |||
e540c55960 | |||
ed2476a139 | |||
8378f1b4ed | |||
1d3ade3e23 | |||
7bb1ec868d | |||
24f0f87220 | |||
9b0a3f8619 | |||
fb83eadc84 | |||
da7dfbeb80 | |||
f6353a44de | |||
275fa13a27 | |||
8efff905bd | |||
dad86c677e | |||
d3ba58d157 | |||
ab6183f12c | |||
17180c52a6 | |||
63be3e5bdf | |||
916fb39046 | |||
eb604cad37 | |||
72e382ddb2 | |||
6f7691593a | |||
775c05462e | |||
ea661930e2 | |||
8e7873e050 | |||
0810cd85ac | |||
9407ce3822 | |||
5b54f30e52 | |||
1b98b91b84 | |||
70c5367397 |
3 geänderte Dateien mit 62 neuen und 34 gelöschten Zeilen
27
.forgejo/workflows/container-build.yml
Normale Datei
27
.forgejo/workflows/container-build.yml
Normale Datei
|
@ -0,0 +1,27 @@
|
|||
---
|
||||
on:
|
||||
push:
|
||||
workflow_dispatch:
|
||||
|
||||
|
||||
jobs:
|
||||
container_build:
|
||||
runs-on: private-vault
|
||||
steps:
|
||||
- name: Fetch repo
|
||||
uses: actions/checkout@v3
|
||||
- name: Container build
|
||||
run: "./build_container.sh"
|
||||
- name: Container push
|
||||
env:
|
||||
REGISTRY_AUTH_FILE: ${{env.RUNNER_TEMP}}/auth.json
|
||||
run: |
|
||||
skopeo login -u 'user' -p "${{ secrets.DOCKER_TOKEN }}" ${GITHUB_SERVER_URL}
|
||||
server=${GITHUB_SERVER_URL//https:/docker:}
|
||||
for tag in latest $GITHUB_RUN_NUMBER ; do
|
||||
echo pushing image to "${server}/${GITHUB_REPOSITORY}:${tag}"
|
||||
skopeo copy -q -a --dest-precompute-digests dir:image "${server}/${GITHUB_REPOSITORY}:${tag}"
|
||||
done
|
||||
- name: Cleanup
|
||||
run: |
|
||||
podman image prune -f
|
|
@ -1,34 +0,0 @@
|
|||
#ifndef SOURCE
|
||||
#define SOURCE gitea.sebastian-tobie.de/docker/keycloak:latest-orig
|
||||
#endif
|
||||
FROM SOURCE as builder
|
||||
ENV PATH="/opt/keycloak/bin:/usr/bin:/usr/local/bin"
|
||||
|
||||
ENV KC_HEALTH_ENABLED=false
|
||||
ENV KC_DB=postgres
|
||||
ENV KC_CACHE_STACK=tcp
|
||||
ENV KC_HTTPS_CLIENT_AUTH=request
|
||||
ENV KC_FEATURES=dynamic-scopes,recovery-codes,preview
|
||||
ENV KC_DB_URL=postgresql://postgres.services.tobie:5432/keycloak
|
||||
RUN kc.sh build
|
||||
|
||||
FROM SOURCE
|
||||
ENV PATH="/opt/keycloak/bin:/usr/bin:/usr/local/bin"
|
||||
|
||||
COPY --from=builder /opt/keycloak/ /opt/keycloak/
|
||||
|
||||
WORKDIR /opt/keycloak
|
||||
ENV KC_HOSTNAME_ADMIN_URL="https://admin.sso.sebastian-tobie.de"
|
||||
ENV KC_HOSTNAME_URL="https://sso.sebastian-tobie.de"
|
||||
ENV KC_DB_USERNAME=keycloak
|
||||
ENV KC_DB_PASSWORD=changeme
|
||||
ENV KC_DB_URL=postgresql://postgres.services.tobie:5432/keycloak
|
||||
|
||||
ENV KEYCLOAK_ADMIN="admin"
|
||||
ENV KEYCLOAK_ADMIN_PASSWORD="admin"
|
||||
EXPOSE 8080
|
||||
COPY --chown=root:root tobie-ca.crt /etc/pki/ca-trust/source/anchors/tobie-ca.crt
|
||||
USER root
|
||||
RUN keytool -importcert -alias tobieca -cacerts -storepass changeit -noprompt -trustcacerts -file /etc/pki/ca-trust/source/anchors/tobie-ca.crt
|
||||
USER keycloak
|
||||
ENTRYPOINT ["kc.sh", "start", "--optimized", "--http-enabled", "true", "--proxy", "edge", "--log-console-format", "'%-5p [%c] (%t) %s%e%n'", "--hostname-strict-backchannel=true"]
|
35
build_container.sh
Ausführbare Datei
35
build_container.sh
Ausführbare Datei
|
@ -0,0 +1,35 @@
|
|||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
both() {
|
||||
"$@" builder
|
||||
"$@" final
|
||||
}
|
||||
|
||||
source=quay.io/keycloak/keycloak:latest
|
||||
buildah from -q --name builder --pull=newer $source >/dev/null
|
||||
buildah from -q --name final $source >/dev/null
|
||||
|
||||
buildah config -l - -e - -a - -p - final
|
||||
buildah config \
|
||||
-e PATH="/opt/keycloak/bin:/usr/bin:/usr/local/bin" \
|
||||
-e KC_HTTPS_CLIENT_AUTH=request \
|
||||
builder
|
||||
buildah config \
|
||||
-e KC_HOSTNAME_ADMIN_URL="https://admin.sso.sebastian-tobie.de" \
|
||||
-e KC_HOSTNAME_URL="https://sso.sebastian-tobie.de" \
|
||||
-e KC_DB_USERNAME=keycloak \
|
||||
-e KC_DB_PASSWORD=changeme \
|
||||
-e KC_DB_URL=postgresql://postgres.services.tobie:5432/keycloak \
|
||||
-e KEYCLOAK_ADMIN="admin" \
|
||||
-e KEYCLOAK_ADMIN_PASSWORD="admin" \
|
||||
-p 8080/tcp \
|
||||
-u keycloak:keycloak \
|
||||
--entrypoint "[\"kc.sh\", \"start\", \"--optimized\", \"--http-enabled\", \"true\", \"--proxy\", \"edge\", \"--log-console-format\", \"'%-5p [%c] (%t) %s%e%n'\", \"--hostname-strict-backchannel=true\"]" \
|
||||
final
|
||||
|
||||
buildah run -- builder kc.sh build --db=postgres --metrics-enabled=true --https-client-auth request --features web-authn,passkeys,persistent-user-sessions,recovery-codes --features-disabled kerberos,docker,ciba,fips
|
||||
|
||||
buildah copy --from builder --chown root:root final /opt/keycloak/ /opt/keycloak/
|
||||
buildah rm builder
|
||||
buildah commit --squash -q -f oci --rm final dir:image
|
Laden …
Tabelle hinzufügen
In neuem Issue referenzieren