Repository navigation
Expand file tree
/
Copy pathDockerfile.php
More file actions
163 lines (153 loc) · 8.06 KB
/
Copy pathDockerfile.php
File metadata and controls
163 lines (153 loc) · 8.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
# Stage 1: Pull wiremock image as tar (no daemon needed)
FROM alpine:3.23 AS wiremock-pull
RUN apk add --no-cache curl && \
ARCH=$(uname -m) && if [ "$ARCH" = "aarch64" ]; then ARCH="arm64"; fi && \
curl -sL "https://github.com/google/go-containerregistry/releases/download/v0.21.2/go-containerregistry_Linux_${ARCH}.tar.gz" | tar xz -C /usr/local/bin crane && \
crane pull wiremock/wiremock:3.9.1 /wiremock.tar
# Stage 2: Rebuild containerd v2.3.0 + runc v1.3.5 + moby (dockerd, docker-proxy)
# + docker CLI from source with go1.26.3 and golang.org/x/net v0.53.0.
# Upstream `docker:29.4.3-dind-alpine3.23` ships dockerd / docker / docker-proxy
# built with go1.26.2, which grype flags for the unpatched go/stdlib 1.26.2
# CVEs (CVE-2026-33811, CVE-2026-33814, CVE-2026-39820, CVE-2026-39836,
# CVE-2026-42499). Rebuilding under GOTOOLCHAIN=go1.26.3 swaps the embedded
# stdlib without changing functionality. The containerd/runc rebuild also
# picks up the grpc / otel / go-jose bumps from the v2.3.0 release line.
FROM golang:1.26.3-alpine3.23 AS overlay-binaries
ARG CONTAINERD_VERSION=2.3.0
ARG RUNC_VERSION=1.3.5
# moby v29.5.1 fixes CVE-2026-41567, CVE-2026-41568, CVE-2026-42306
# (GHSA-x86f-5xw2-fm2r, GHSA-vp62-88p7-qqf5, GHSA-rg2x-37c3-w2rh)
# and includes the earlier CVE-2026-33997 / CVE-2026-34040 fixes.
ARG MOBY_VERSION=29.5.1
ARG DOCKER_CLI_VERSION=29.5.1
ARG COMPOSE_VERSION=5.1.3
ARG XNET_VERSION=0.53.0
ARG OTEL_SDK_VERSION=1.43.0
ARG IN_TOTO_VERSION=0.11.0
# Latest 28.x backport of CVE-2026-33997/34040 (compose v5.1.3's legacy
# github.com/docker/docker indirect dep is frozen at v28.5.2).
ARG DOCKER_LEGACY_VERSION=v28.5.3-0.20260325154711-31a1689cb0a1+incompatible
ENV GOTOOLCHAIN=go1.26.3
RUN apk add --no-cache git make gcc musl-dev linux-headers libseccomp-dev libseccomp-static bash ca-certificates && \
mkdir -p /overlay/usr/local/bin
# Bump in-toto-golang to v0.11.0 (GHSA-pmwq-pjrm-6p5r) and pin the OTLP
# HTTP exporters to v${OTEL_SDK_VERSION} (CVE-2026-39882).
RUN git clone --depth 1 --branch v${CONTAINERD_VERSION} https://github.com/containerd/containerd.git /src/containerd && \
cd /src/containerd && \
go get golang.org/x/net@v${XNET_VERSION} \
github.com/in-toto/in-toto-golang@v${IN_TOTO_VERSION} \
go.opentelemetry.io/otel/sdk@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/trace@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/metric@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp@v${OTEL_SDK_VERSION} && \
go mod tidy && \
go mod vendor && \
for cmd in containerd ctr containerd-shim-runc-v2; do \
CGO_ENABLED=0 go build -tags "osusergo netgo static_build" -trimpath -ldflags "-s -w" \
-o /overlay/usr/local/bin/$cmd ./cmd/$cmd ; \
done
RUN git clone --depth 1 --branch v${RUNC_VERSION} https://github.com/opencontainers/runc.git /src/runc && \
cd /src/runc && \
go get golang.org/x/net@v${XNET_VERSION} && \
go mod tidy && \
go mod vendor && \
make static EXTRA_LDFLAGS="-s -w" && \
cp runc /overlay/usr/local/bin/runc
RUN git clone --depth 1 --branch docker-v${MOBY_VERSION} https://github.com/moby/moby.git /src/moby && \
cd /src/moby && \
# Force patched x/net (CVE-2026-33814), otel SDK + OTLP HTTP exporters
# (CVE-2026-39882, CVE-2026-39883) before vendoring dockerd/docker-proxy.
go get golang.org/x/net@v${XNET_VERSION} \
go.opentelemetry.io/otel/sdk@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/trace@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/metric@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp@v${OTEL_SDK_VERSION} && \
go mod tidy && \
go mod vendor && \
CGO_ENABLED=0 go build -mod=vendor \
-tags "osusergo netgo static_build exclude_graphdriver_btrfs exclude_graphdriver_devicemapper" \
-trimpath -ldflags "-s -w" \
-o /overlay/usr/local/bin/dockerd ./cmd/dockerd && \
CGO_ENABLED=0 go build -mod=vendor \
-tags "osusergo netgo static_build" \
-trimpath -ldflags "-s -w" \
-o /overlay/usr/local/bin/docker-proxy ./cmd/docker-proxy
RUN git clone --depth 1 --branch v${DOCKER_CLI_VERSION} https://github.com/docker/cli.git /src/docker-cli && \
cd /src/docker-cli && \
cp vendor.mod go.mod && cp vendor.sum go.sum && \
# docker CLI's vendor.mod pins x/net <0.53; bump it (and re-vendor)
# so the built /usr/local/bin/docker also clears CVE-2026-33814.
go get golang.org/x/net@v${XNET_VERSION} && \
go mod tidy && \
go mod vendor && \
CGO_ENABLED=0 go build -mod=vendor \
-tags "osusergo netgo static_build pkcs11" \
-trimpath -ldflags "-s -w" \
-o /overlay/usr/local/bin/docker ./cmd/docker
# Rebuild docker-compose to clear x/net <0.53, OTLP HTTP exporter <1.43.0
# (CVE-2026-39882), in-toto-golang <0.11.0 (GHSA-pmwq-pjrm-6p5r), and the
# legacy github.com/docker/docker v28.5.2 (CVE-2026-33997/34040) that the
# v5.1.3 upstream prebuilt vendors.
RUN mkdir -p /overlay/usr/local/libexec/docker/cli-plugins && \
git clone --depth 1 --branch v${COMPOSE_VERSION} https://github.com/docker/compose.git /src/compose && \
cd /src/compose && \
go get golang.org/x/net@v${XNET_VERSION} \
github.com/in-toto/in-toto-golang@v${IN_TOTO_VERSION} \
github.com/docker/docker@${DOCKER_LEGACY_VERSION} \
go.opentelemetry.io/otel/sdk@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/trace@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/metric@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v${OTEL_SDK_VERSION} \
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp@v${OTEL_SDK_VERSION} && \
go mod tidy && \
CGO_ENABLED=0 go build \
-trimpath -ldflags "-s -w -X github.com/docker/compose/v5/internal.Version=v${COMPOSE_VERSION}" \
-o /overlay/usr/local/libexec/docker/cli-plugins/docker-compose ./cmd
# Stage 3: Build the seed image
FROM docker:29.4.3-dind-alpine3.23
# Apply latest APK security patches
RUN apk update && apk upgrade --no-cache --available
# Overlay rebuilt containerd + runc + moby (dockerd, docker-proxy) + docker CLI
# binaries (see stage 2). These replace the upstream go1.26.2 builds.
COPY --from=overlay-binaries /overlay/ /
# Drop unused buildx CLI plugin that ships vulnerable embedded Go modules.
# Keep docker-compose: wire-test bootstraps in generators/php/sdk run
# `docker compose -f …` to start WireMock alongside generated SDK tests.
RUN rm -f /usr/local/libexec/docker/cli-plugins/docker-buildx
# Copy pre-pulled wiremock image
COPY --from=wiremock-pull /wiremock.tar /wiremock.tar
# Install PHP, Composer, and required extensions. alpine 3.23's composer pulls
# in php84 (forward-compatible with generated SDK templates requiring php: ^8.1).
RUN apk add --no-cache \
php84 \
php84-phar \
php84-mbstring \
php84-openssl \
php84-curl \
php84-dom \
php84-xml \
php84-xmlwriter \
php84-tokenizer \
php84-ctype \
php84-iconv \
php84-simplexml \
php84-fileinfo \
composer \
bash \
git
# Create symlink for php command
RUN ln -sf /usr/bin/php84 /usr/bin/php
# Create entrypoint script to start dockerd and wait until it is ready
RUN echo '#!/bin/sh' > /entrypoint.sh && \
echo 'dockerd &' >> /entrypoint.sh && \
echo 'for i in $(seq 1 30); do docker info >/dev/null 2>&1 && break; sleep 0.1; done' >> /entrypoint.sh && \
echo 'if [ -f /wiremock.tar ]; then docker load < /wiremock.tar && rm -f /wiremock.tar; fi' >> /entrypoint.sh && \
echo 'exec "$@"' >> /entrypoint.sh && \
chmod +x /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"]
CMD ["tail", "-f", "/dev/null"]