]> git.ipfire.org Git - thirdparty/pdns.git/blob - Dockerfile-dnsdist
Merge pull request #13580 from Habbie/ubuntu-noble
[thirdparty/pdns.git] / Dockerfile-dnsdist
1 # our chosen base image
2 FROM debian:11-slim AS builder
3
4 ENV NO_LUA_JIT="s390x arm64"
5
6 # TODO: make sure /source looks roughly the same from git or tar
7
8 # Reusable layer for base update
9 RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
10
11 # devscripts gives us mk-build-deps (and a lot of other stuff)
12 RUN apt-get update && apt-get -y dist-upgrade && apt-get install -y --no-install-recommends devscripts equivs git && apt-get clean
13
14 COPY builder-support /source/builder-support
15
16 # TODO: control file is not in tarballs at all right now
17 RUN mk-build-deps -i -t 'apt-get -y -o Debug::pkgProblemResolver=yes --no-install-recommends' /source/builder-support/debian/dnsdist/debian-buster/control && \
18 apt-get clean
19
20 COPY pdns /source/pdns
21 COPY build-aux /source/build-aux
22 COPY m4 /source/m4
23 COPY ext /source/ext
24 COPY builder/helpers/set-configure-ac-version.sh /usr/local/bin
25 COPY .git /source/.git
26
27 # build and install (TODO: before we hit this line, rearrange /source structure if we are coming from a tarball)
28 WORKDIR /source/pdns/dnsdistdist
29
30 ARG MAKEFLAGS=
31 ENV MAKEFLAGS ${MAKEFLAGS:--j2}
32
33 ARG DOCKER_FAKE_RELEASE=NO
34 ENV DOCKER_FAKE_RELEASE ${DOCKER_FAKE_RELEASE}
35
36 RUN touch dnsdist.1 # avoid having to install pandoc and venv
37
38 RUN if [ "${DOCKER_FAKE_RELEASE}" = "YES" ]; then \
39 BUILDER_VERSION="$(IS_RELEASE=YES BUILDER_MODULES=dnsdist ./builder-support/gen-version | sed 's/\([0-9]\+\.[0-9]\+\.[0-9]\+\(\(alpha|beta|rc\)\d\+\)\)?.*/\1/')" set-configure-ac-version.sh;\
40 fi && \
41 BUILDER_MODULES=dnsdist autoreconf -vfi
42
43
44 RUN mkdir /libh2o && cd /libh2o && \
45 apt-get update && apt-get install -y cmake curl libssl-dev zlib1g-dev && \
46 curl -f -L https://github.com/PowerDNS/h2o/archive/refs/tags/v2.2.6+pdns2.tar.gz | tar xz && \
47 CFLAGS='-fPIC' cmake -DWITH_PICOTLS=off -DWITH_BUNDLED_SSL=off -DWITH_MRUBY=off -DCMAKE_INSTALL_PREFIX=/opt ./h2o-2.2.6-pdns2 && \
48 make install
49
50 RUN mkdir /quiche && cd /quiche && \
51 apt-get install -y libclang-dev && \
52 apt-get clean && \
53 /source/builder-support/helpers/install_rust.sh && \
54 /source/builder-support/helpers/install_quiche.sh
55
56 RUN mkdir /build && \
57 LUAVER=$([ -z "${NO_LUA_JIT##*$(dpkg --print-architecture)*}" ] && echo 'lua5.3' || echo 'luajit') && \
58 ./configure \
59 --with-lua=${LUAVER} \
60 LDFLAGS=-rdynamic \
61 --sysconfdir=/etc/dnsdist \
62 --enable-option-checking=fatal \
63 --enable-dnscrypt \
64 --enable-dns-over-tls \
65 --enable-dns-over-https \
66 --with-re2 \
67 --with-h2o \
68 --enable-dns-over-quic \
69 --enable-dns-over-http3 \
70 --with-quiche \
71 PKG_CONFIG_PATH=/opt/lib/pkgconfig && \
72 make clean && \
73 make $MAKEFLAGS install DESTDIR=/build && make clean && \
74 strip /build/usr/local/bin/* &&\
75 mkdir -p /build/usr/lib/ && \
76 cp -rf /usr/lib/libdnsdist-quiche.so /build/usr/lib/
77
78 RUN cd /tmp && mkdir /build/tmp/ && mkdir debian && \
79 echo 'Source: docker-deps-for-pdns' > debian/control && \
80 dpkg-shlibdeps /build/usr/local/bin/dnsdist && \
81 sed 's/^shlibs:Depends=/Depends: /' debian/substvars >> debian/control && \
82 equivs-build debian/control && \
83 dpkg-deb -I equivs-dummy_1.0_all.deb && cp equivs-dummy_1.0_all.deb /build/tmp/
84
85 # Runtime
86
87 FROM debian:11-slim
88
89 # Reusable layer for base update - Should be cached from builder
90 RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
91
92 # - python3 and jinja2 (for startup script)
93 # - python3-atomicwrites (for backend management)
94 # - tini (for signal management)
95 # - ca-certificates (for verifying downstream DoH/DoT certificates)
96 RUN apt-get install -y python3 python3-jinja2 python3-atomicwrites tini libcap2-bin ca-certificates && apt-get clean
97
98 # Output from builder
99 COPY --from=builder /build /
100 RUN chmod 1777 /tmp # FIXME: better not use /build/tmp for equivs at all
101
102 # Ensure dependencies are present
103 RUN apt-get install -y /tmp/equivs-dummy_1.0_all.deb && apt-get clean
104
105 # Config
106 RUN mkdir -p /etc/dnsdist/conf.d /etc/dnsdist/templates.d
107 COPY dockerdata/dnsdist.conf /etc/dnsdist/
108
109 # Start script
110 COPY dockerdata/startup.py /usr/local/bin/dnsdist-startup
111
112 # Work with pdns user - not root
113 RUN adduser --system --disabled-password --disabled-login --no-create-home --group pdns --uid 953
114 RUN chown pdns:pdns /etc/dnsdist/conf.d /etc/dnsdist/templates.d
115 USER pdns
116
117 # Default DNS ports
118 EXPOSE 53/udp
119 EXPOSE 53/tcp
120 # Default console port
121 EXPOSE 5199/tcp
122 # Default webserver port
123 EXPOSE 8083/tcp
124
125 WORKDIR /etc/dnsdist
126
127 COPY dockerdata/dnsdist-resolver.lua /etc/dnsdist/
128 COPY dockerdata/dnsdist-resolver.py /usr/local/bin/dnsdist-resolver
129
130 ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/dnsdist-startup"]