Note: This document serves dual purpose as the README for a GitHub repo and for the DockerHub repository built from it (as an automated build).
This provides a base Docker image with the Ubuntu OS. It is called "ubu-lts" after the Ubuntu long-term service release and is versioned based on the date of the patch to the release. Currently, this is the so-called "Focal Fossa" version.
The goal of providing this is to make it easier to take control of an entire Docker image chain for reproducibility, which requires locking down the base image. The trade off in doing so is also locking in any security flaws. The original open-source repository that builds the official Ubuntu base image is not easily reused by independent pipelines to build their own images or to control exactly which version is used when. This one is intended to be simpler.
Images are tagged using the following scheme:
All three tagged versions will be built automatically using the DockerHub automation. Local builds only build the fully versioned one, see the following.
To build a image locally based on a specific release by tag, clone the tagged commit, cd into the repo, and run the build.sh script.
git clone --branch <tag> --depth 1 https://github.com/JefferysDockers/ubu-lts
cd ubu-lts
./build.sh
To just clone the latest tagged release, you can try leaving off the "--branch <tag>" option. That will work as long as the latest commit on the master branch of GitHub has a tag. It probably does, but if you get an error saying something about "no tag available" you'll have to try again, cloning the repo using the tag explicitly.
This will build an image named "ubu-lts:<ubuntu.ver>-<build.ver>". If you want the other tags, you will have to create them yourself, e.g.
docker tag ubu-lts:<ubuntu.ver>-<build.ver> <ubuntu.ver>
docker tag ubu-lts:<ubuntu.ver>-<build.ver> latest
Licensing is complicated and not what I want to spend my time on, but here is my best attempt to license and comply with existing licenses:
This GitHub repo is based on Tianon's source github repo which is used to build the Ubuntu base DockerHub distributions. I am using the MIT licensed for my repo to maximize what can be done with it as far as I have the ability to. Different licensing applies to the Dockerfile and to the Ubuntu image contents based on the original licenses of what they were derived from.
The Dockerfile in this repo is licensed under the Apache 2 License, based on the license for the GitHub repository it is derived from. That repository uses a significant amount of automation to build all the various versions of Ubuntu images, including the update.sh script that generates Dockerfiles on demand. The Dockerfile in this repo is based on that script.
Ubuntu and Canonical have a reasonable interest in people not thinking my image has anything to do with them or their trademarks. So any use of Ubuntu or Canonical (or Focal, if that is also trademarked) is only to describe where the original sources can be obtained. This image is not otherwise associated with Ubuntu or Canonical and is in no way official or sanctioned. However, since its contents are as identical as I can make them, it is licensed under the same terms as their official image. The Ubuntu licence statement is here
The Ubuntu tarball and manifest in the root of this repository are the meat of the base image. It is from an open canonical web site described in the official repo README. This tarball is unpacked to form the starting contents of the image, which allows bootstrapping a base image. Again, although these tarballs come from a Canonical web site for the Ubuntu core and are used unmodified here there is nothing that makes my use of them official or sanctioned.
The core of the built-from-scratch distro is a pre-built tarball from the above Canonical/Ubuntu core link. It must be local (in the root build context alongside the Dockerfile) for the build to work. I have copied the local *.tar.gz and *.manifest files from that remote site.
I'm including the checksum file for the tarball so it can be verified locally. I don't think the tarball or the sha sums can be changed once committed so if you do a pull by commit hash instead of by tag, it should get both unchanged. To independently verify the tarball and/or checksums, just check the original sources (if still available, they update pretty often and only the most recent are available). You can trust a commit hash pull thereafter.
A "one-line" local test command in Bash for verifying sha256 against a local copy of the checksum file, assuming you have openssl and are in the root directory of the repo:
checkSha256() { diff <(openssl dgst -sha256 "$1" | cut -d " " -f 2) \
<(grep amd64 "$2" | cut -d " " -f 1) || echo "**FAIL**" ; }; \
checkSha256 "ubuntu-focal-core-cloudimg-amd64-root.tar.gz" "SHA256SUMS"
Just unpacking the tarball into the docker image creates a working Linux distro, but a few specific tweaks are useful for docker as listed at the Moby link above. I modified the comments on each in my Dockerfile based on my understanding of what is being done.
DockerHub automation provides for ENV variables in the build environment and a default build process whose steps can be over-ridden by appropriately named scripts in a "hooks" directory. To allow both manual (local) builds and automated DockerHub builds, the build.sh script mimics the DockerHub build environment by setting ENV variables and then calling the hooks/build script to build the image.
The only difficulty in doing this is providing the "TAG" environmental variable, which is based on the Git tag of the particular GitHub commit that DockerHub is building. Building from a local repo requires reading that with Git, which only works if the local repo contains a tag. If it contains more than one tag, the tag from the last commit in the repo with a tag is used. To build a specific tag, clone only that tagged commit (see [Local Build](#local-b uild), above).
Repeating the information above, when building locally, only the fully versioned "ubu-lts:<ubuntu.ver>-<build.ver>" image is built. You will have to add tags for "ubu-lts:<ubuntu.ver>" and "ubu-lts:latest" on your own if you need to.
Every commit on the master branch of the GitHub repo is a release and should be tagged with a different tag formatted as "<ubuntu.ver>-<build.ver>"
Pushing a new tag with a hyphen to GitHub master branch will trigger DockerHub to build a new image using the hooks/build script and add it to the image repo "ubu-lts:<ubuntu.ver>-<build.ver>". Then the hooks/post_push script is run. That will additionally add the tags "ubu-lts:latest" and "ubu-lts:<ubuntu.ver>". Doing the tagging this way rather than setting three separate automated builds is a much more efficient use of DockerHub resources.
Note that there may be brief periods where the leading commit on the master branch of the GitHub repo is not tagged, or when the "ubu-lts:latest" image does not match with the latest "ubu-lts:<ubuntu.ver>" and/or "ubu-lts:<ubuntu.ver>-<build.ver>" versions of the image on DockerHub due to time required to run different steps of the build process.
Content type
Image
Digest
Size
27.2 MB
Last updated
almost 6 years ago
docker pull jefferys/ubu-lts