# dig a www.example.com @0 -p 1053
# Builder
-FROM debian:10-slim AS builder
+FROM debian:11-slim AS builder
+
+ENV NO_LUA_JIT="s390x arm64"
# Reusable layer for base update
RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
# devscripts gives us mk-build-deps (and a lot of other stuff)
-RUN apt-get install -y --no-install-recommends devscripts equivs git curl && apt-get clean
+RUN apt-get install -y --no-install-recommends devscripts equivs git curl jq && apt-get clean
COPY builder-support /source/builder-support
COPY .git /source/.git
COPY builder/helpers/set-configure-ac-version.sh /usr/local/bin
+COPY builder-support/helpers/install_rust.sh /source/install_rust.sh
+COPY builder-support/helpers/rust.json /source/rust.json
+RUN cd /source/ && ./install_rust.sh
+
# build and install (TODO: before we hit this line, rearrange /source structure if we are coming from a tarball)
WORKDIR /source/pdns/recursordist
BUILDER_MODULES=recursor autoreconf -vfi
RUN mkdir /build && \
+ LUAVER=$([ -z "${NO_LUA_JIT##*$(dpkg --print-architecture)*}" ] && echo 'lua5.3' || echo 'luajit') && \
./configure \
- --with-lua=luajit \
+ --with-lua=${LUAVER} \
LDFLAGS=-rdynamic \
--sysconfdir=/etc/powerdns \
--enable-option-checking=fatal && \
dpkg-deb -I equivs-dummy_1.0_all.deb && cp equivs-dummy_1.0_all.deb /build/tmp/
# Runtime
-FROM debian:10-slim
+FROM debian:11-slim
# Reusable layer for base update - Should be cached from builder
RUN apt-get update && apt-get -y dist-upgrade && apt-get clean
# Executables from builder
COPY --from=builder /build /
RUN chmod 1777 /tmp # FIXME: better not use /build/tmp for equivs at all
-RUN setcap 'cap_net_bind_service=+eip' /usr/local/sbin/pdns_recursor
# Ensure dependencies are present
-RUN apt install -y /tmp/equivs-dummy_1.0_all.deb && apt clean
+RUN apt-get install -y /tmp/equivs-dummy_1.0_all.deb && apt-get clean
# Start script
COPY dockerdata/startup.py /usr/local/sbin/pdns_recursor-startup
RUN chown pdns:pdns /var/run/pdns-recursor /etc/powerdns/recursor.d /etc/powerdns/templates.d
USER pdns
-# DNS ports
+# Default DNS ports
EXPOSE 53/udp
EXPOSE 53/tcp
-# webserver port
+# Default webserver port
EXPOSE 8082/tcp
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/sbin/pdns_recursor-startup"]