]> git.ipfire.org Git - thirdparty/pdns.git/blame - Dockerfile-recursor
Avoid label and goto in loop
[thirdparty/pdns.git] / Dockerfile-recursor
CommitLineData
c0e0545b
PD
1# USAGE
2
3# docker build --build-arg MAKEFLAGS=-j8 -t recursor -f docker/Dockerfile-recursor .
4# docker run -p 1053:53 -p 1053:53/udp -ti --rm recursor
5# dig a www.example.com @0 -p 1053
6
7# Builder
a0d3acff 8FROM debian:11-slim AS builder
c0e0545b 9
1e9b17d7 10ENV NO_LUA_JIT="s390x arm64"
c1a8e298 11
c0e0545b
PD
12# Reusable layer for base update
13RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
14
15# devscripts gives us mk-build-deps (and a lot of other stuff)
16RUN apt-get install -y --no-install-recommends devscripts equivs git curl && apt-get clean
17
d2a1e0c6 18COPY builder-support /source/builder-support
c0e0545b
PD
19
20# TODO: control file is not in tarballs at all right now
21RUN mk-build-deps -i -t 'apt-get -y -o Debug::pkgProblemResolver=yes --no-install-recommends' /source/builder-support/debian/recursor/debian-buster/control && \
22 apt-get clean
c0e0545b 23
d2a1e0c6
PL
24COPY pdns /source/pdns
25COPY build-aux /source/build-aux
26COPY m4 /source/m4
27COPY ext /source/ext
28COPY .git /source/.git
ff6b244a 29COPY builder/helpers/set-configure-ac-version.sh /usr/local/bin
d2a1e0c6 30
30ef2a39
OM
31COPY builder-support/helpers/install_rust.sh /source/install_rust.sh
32RUN /source/install_rust.sh
33
c0e0545b
PD
34# build and install (TODO: before we hit this line, rearrange /source structure if we are coming from a tarball)
35WORKDIR /source/pdns/recursordist
36
37ARG MAKEFLAGS=
38ENV MAKEFLAGS ${MAKEFLAGS:--j2}
39
ff6b244a
PL
40ARG DOCKER_FAKE_RELEASE=NO
41ENV DOCKER_FAKE_RELEASE ${DOCKER_FAKE_RELEASE}
42
c0e0545b 43# Manpage deps
98508251 44# RUN apt-get install -y python3-venv && apt-get clean
c0e0545b
PD
45
46# Manpage prevent
47RUN touch pdns_recursor.1 rec_control.1 # avoid installing pandoc
48
ff6b244a 49RUN if [ "${DOCKER_FAKE_RELEASE}" = "YES" ]; then \
a508963d 50 BUILDER_VERSION="$(IS_RELEASE=YES BUILDER_MODULES=recursor ./builder-support/gen-version | sed 's/\([0-9]\+\.[0-9]\+\.[0-9]\+\(\(alpha|beta|rc\)\d\+\)\)?.*/\1/')" set-configure-ac-version.sh;\
ff6b244a
PL
51 fi && \
52 BUILDER_MODULES=recursor autoreconf -vfi
c0e0545b
PD
53
54RUN mkdir /build && \
1e9b17d7 55 LUAVER=$([ -z "${NO_LUA_JIT##*$(dpkg --print-architecture)*}" ] && echo 'lua5.3' || echo 'luajit') && \
64d4a9d9
JC
56 ./configure \
57 --with-lua=${LUAVER} \
c0e0545b
PD
58 LDFLAGS=-rdynamic \
59 --sysconfdir=/etc/powerdns \
60 --enable-option-checking=fatal && \
61 make clean && \
62 make $MAKEFLAGS install DESTDIR=/build && make clean && \
63 strip /build/usr/local/bin/* /build/usr/local/sbin/*
64RUN cd /tmp && mkdir /build/tmp/ && mkdir debian && \
7b968335 65 echo 'Source: docker-deps-for-pdns' > debian/control && \
c0e0545b
PD
66 dpkg-shlibdeps /build/usr/local/bin/rec_control /build/usr/local/sbin/pdns_recursor && \
67 sed 's/^shlibs:Depends=/Depends: /' debian/substvars >> debian/control && \
68 equivs-build debian/control && \
69 dpkg-deb -I equivs-dummy_1.0_all.deb && cp equivs-dummy_1.0_all.deb /build/tmp/
70
71# Runtime
a0d3acff 72FROM debian:11-slim
c0e0545b
PD
73
74# Reusable layer for base update - Should be cached from builder
75RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
76
6c1e69e0
PL
77# Ensure python3 and jinja2 is present (for startup script), and tini for signal management
78RUN apt-get install -y python3 python3-jinja2 tini libcap2-bin && apt-get clean
c0e0545b
PD
79
80# Executables from builder
81COPY --from=builder /build /
82RUN chmod 1777 /tmp # FIXME: better not use /build/tmp for equivs at all
c0e0545b
PD
83
84# Ensure dependencies are present
2e209af7 85RUN apt-get install -y /tmp/equivs-dummy_1.0_all.deb && apt-get clean
c0e0545b
PD
86
87# Start script
88COPY dockerdata/startup.py /usr/local/sbin/pdns_recursor-startup
89
90# Config file(s) from builder
d2a1e0c6 91COPY dockerdata/recursor.conf /etc/powerdns/
c0e0545b
PD
92
93# Is recursor.d necessary if we copy the config into recursor.conf? (see above)
6c1e69e0 94RUN mkdir -p /etc/powerdns/recursor.d /var/run/pdns-recursor /etc/powerdns/templates.d
c0e0545b
PD
95
96# Work with pdns user - not root
97RUN adduser --system --disabled-password --disabled-login --no-create-home --group pdns --uid 953
6c1e69e0 98RUN chown pdns:pdns /var/run/pdns-recursor /etc/powerdns/recursor.d /etc/powerdns/templates.d
c0e0545b
PD
99USER pdns
100
f28c81ed 101# Default DNS ports
c0e0545b
PD
102EXPOSE 53/udp
103EXPOSE 53/tcp
104
f28c81ed 105# Default webserver port
c0e0545b
PD
106EXPOSE 8082/tcp
107
108ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/sbin/pdns_recursor-startup"]