A container running g10k and webhook.
The purpose is to catch webhook posts from a git server and run g10k to build puppet environments.
This is roughly derrived from camptocamp/docker-g10k-webhook, but runs a container based on s6.
This image is layered on jchonig/webhook.
docker create \
--name=g10k \
-e TZ=Europe/London \
--expose 9000 \
--restart unless-stopped \
jchonig/g10k
Compatible with docker-compose v2 schemas.
---
version: "3"
services:
monit:
image: jchonig/g10k
container_name: g10k
environment:
TZ: Europe/London
HOOK_SECRET: MYSHAREDSECRET
volumes:
- </path/to/appdata/config>:/config
- /etc/puppetlabs/code:/etc/puppetlabs/code
expose:
- 9000
restart: unless-stopped
| Volume | Function |
|---|---|
| 9000 | Webook port |
| Env | Function |
|---|---|
| PUID=1000 | for UserID - see below for explanation |
| PGID=1000 | for GroupID - see below for explanation |
| TZ=UTC | Specify a timezone to use EG UTC |
| PUPPET_SERVER= | FQDN of the Puppet server (e.g. puppet8.home.honig.net); enables environment cache flushing after each successful deploy |
| Volume | Function |
|---|---|
| /config | All the config files reside here |
| /etc/puppetlabs/code | Where generated puppet environments live |
| /etc/puppetlabs/puppet/ssl | Puppet SSL directory; required for environment cache flushing (see below) |
env in
the config directory. This file is sourced by the shell.SSH configuration should be stored in the /config/.ssh,
including a /config/.ssh/config file which specifies which keys
to use for each git server.
Host git.server.adddress.com
Compression no
IdentityFile %d/.ssh/id_rsa
IdentitiesOnly yes
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
A pre-push git hook is provided that builds the image and runs smoke tests before allowing a push. To enable it:
git config core.hooksPath hooks
The hook will build the image, start a container, run all tests, and clean up automatically. A failed test aborts the push.
A GitHub Actions workflow (.github/workflows/test.yml) runs the same tests on
every push and pull request. The Docker Hub image is only built and pushed after
all tests pass, and only on pushes to master.
To enable the Docker Hub push, two secrets must be added to the GitHub repository and a Docker Hub access token must be created.
github-docker-g10k), set permissions to Read & WriteGo to the GitHub repository → Settings → Secrets and variables → Actions → New repository secret and add each of the following:
| Secret | Value |
|---|---|
DOCKERHUB_USERNAME | Your Docker Hub username |
DOCKERHUB_TOKEN | The access token created above |
If you have multiple Docker Hub repositories under the same account, these secrets can be set at the organization level instead (Settings → Secrets and variables → Actions, on the organization page) and shared across all repositories.
Docker Hub automated builds must be disabled for this repository so that the image is only published via the GitHub Action after tests pass.
After a successful g10k deploy, the container can notify the Puppet server to flush its compiled catalog cache for the deployed environment. This ensures agents pick up the new code immediately rather than serving stale catalogs.
To enable this, set PUPPET_SERVER to the FQDN of the Puppet server and mount
its SSL directory read-only:
environment:
PUPPET_SERVER: puppet8.home.honig.net
volumes:
- /etc/puppetlabs/puppet/ssl:/etc/puppetlabs/puppet/ssl:ro
The container uses the Puppet server's own certificate (named after
PUPPET_SERVER) to authenticate to the admin API:
| File | Purpose |
|---|---|
/etc/puppetlabs/puppet/ssl/certs/ca.pem | CA certificate |
/etc/puppetlabs/puppet/ssl/certs/<PUPPET_SERVER>.pem | Client certificate |
/etc/puppetlabs/puppet/ssl/private_keys/<PUPPET_SERVER>.pem | Private key |
If any of these files are absent, the flush is skipped with a warning and the
deploy still succeeds. The notification title prefix is derived from the
hostname portion of PUPPET_SERVER (e.g. puppet8).
This container contains apprise which can send notifications via almost all notification services.
To send notifications on completions of g10k runs, create a
/config/.apprise.yml that lists the urls to notify.
Content type
Image
Digest
sha256:2b7ae36e0…
Size
45.8 MB
Last updated
4 days ago
docker pull jchonig/g10k