Building images from RPM non-root with fake(ch)root on openshift from GitLab with odagrun.
4.3K
Image for building images from a CentOS RPM repository as non-root with fake(ch)root from GitLab-CI on openshift with odagrun.
The imagebuilder is build in 2 stages, starting from an official CentOS7 from the dockerhub to create an image to build the fake_xxx rpms in pass two and push it to the registry.
The imagebuilder is kept small and contains besides the linux coreutils, yum, rpm :
libfakearch.so, an LD_PRELOAD lib to fake a different architecture by setting the envirnoment variable FAKE_ARCH.trap_print, a script helper to catch errors and a set +x alternative for printing variable expanded command.In order to be able to create a rootfs with yum --installroot=xxx as non-root a few wrappers and stubs are provided in /usr/sbin/glibc-fake :
FAKE_SKIP_LDCONFIG is set ldconfig wrapper will return trueSKIP_BUILD_LOCALE_ARCHIVE is set /sbin/build-locale-archive will be skippedmake_os is a script that set's the environment for fakeroot,fakechroot and a few wrappers/stubs to build a rootfs system with yum --installroot=xxx for a given make_os.config.
OS_CONFIG variable pointing to a make_os.conf and create that make_os.conf.Sample make_os.conf to create a minimal rootfs with CentOS 7 coreutils:
install_packages="coreutils"
#
# uncomment to use a group install:
#install_groups="@Development Tools"
#
#
# uncomment to add a post script, use absolute path,
# BASE points to the root of the project_dir
#postscript=$BASE/postscript
#
#
# uncomment if one would like to preserve some by default cleaned sections:
#OS_KEEP_CRACKLIB=True
#OS_KEEP_LOCALE=True
#OS_KEEP_MAN_and_DOCS=True
#OS_KEEP_i18n=True
#
# uncomment to change the base arch, for future extensions
#basearch=x86_64
#
#
# To define a diferent yum_conf, uncomment and edit
#yum_config=yum.conf
#
#
# uncomment and set desired DISTRO_RELEASE
#DISTRO_RELEASE=7
#
Create directory yum.repo.d and add the repo's for yum to use
Create Directory GPG-KEYS, all keys in this deirectory will be imported.
if the default yum.conf does not exists if will be create as:
[main]
cachedir=/var/cache/yum/$basearch/$releasever
keepcache=1
debuglevel=1
logfile=/yum.log
exactarch=1
obsoletes=1
gpgcheck=1
plugins=1
installonly_limit=5
distroverpkg=centos-release
reposdir=./yum.repos.d/
metadata_expire=90m
http_caching=all
color=off
export target=rootfs
make_os
and the directory as pointed to with target, default ./rootfs will contain the new docker os image layer.
root:rootmake_os will link the directory $BASE/cache/yum into the new rootfs and remove the cache form the newly create rootfs, with base pointing to the CI_PROJECT_DIR.
To create a cache image layer with odagrun gitlab-runner define a variable in gitlab-ci.yml f.i.:
variables:
WORK_SPACES: |
- name: "repocache C${DISTRO_RELEASE}"
key: x86_64
scope: global
path:
- cache/yum/x86_64/${DISTRO_RELEASE}/base
- cache/yum/x86_64/${DISTRO_RELEASE}/updates
strategy: push-pull
mandatory: false
This to reduce the bandwithd usage to the public centos(vault).
are listed in $target/etc/system_packages, obtained with rpm -qa > $target/etc/system_packages
chmod 775 $target/etc/passwd
imagebuilder-imageor checkout gioxa/buildimages
Cmd:
- /bin/bash
Env:
- 'PATH=/usr/local/bin:/usr/local/sbin:/usr/bin:/usr/sbin:/bin:/sbin'
Hostname: $CI_PROJECT_NAME
WorkingDir: /
User: ""
For use with gitlab-ci and odagrun
.gitlab-ci.yml file:build:
image: gioxa/imagebuilder-c7:latest
script:
- export OS_CONFIG=make_os.conf
- make_os
- registry_push --rootfs --ISR --reference=${CI_PIPELINE_ID}
tags: odagrun
make_os.conf file and content:# make_os.conf
install_packages="coreutils"
yum.repos.d with a e.g. : base.repo file.# base.repo
[base]
name=CentOS- - Base
mirrorlist=http://mirrorlist.centos.org/?release=&arch=&repo=os&infra=
[updates]
name=CentOS- - Updates
mirrorlist=http://mirrorlist.centos.org/?release=&arch=&repo=updates&infra=
create GPG-KEYS directory with a file : RPM-GPG-KEY-CentOS-7
commit:
Result: a CentOS 7 nano docker image with coreutils pushed to ImageStream:${CI_PIPELINE_ID}
Build with odagrun on openshift-online-starter
Content type
Image
Digest
Size
40.7 MB
Last updated
almost 8 years ago
docker pull gioxa/imagebuilder-c7