Sign inSign up

jfxs/ansible

By jfxs

•Updated 4 days ago

A lightweight automatically updated and tested multiarch docker image to run Ansible playbooks

Image
Integration & delivery
0

50K+

jfxs/ansible repository overview

⁠Docker alpine Ansible

Software License Pipeline Status

A Docker image to run Ansible⁠ playbooks. Ansible-lint⁠ to test playbooks is also included.

  • lightweight image based on Alpine Linux,
  • multiarch with support of amd64 and arm64,
  • non-root container user,
  • automatically kept up to date by Renovate⁠ (base image, Ansible and dependency versions),
  • image signed with Cosign⁠,
  • a software bill of materials (SBOM) attestation added using Syft⁠,
  • available on Docker Hub and Quay.io.

GitLab The main repository.

Docker Hub The Docker Hub registry.

Quay.io The Quay.io registry.

Since Ansible version 2.10, the Docker image has only ansible-core without any collection. It could be necessary to install them. This image includes:

⁠Running Ansible

Example to run Ansible playbooks in your current directory:

docker run -it --rm -v $(pwd):/ansible jfxs/ansible ansible-playbook playbook.yml

To install collections:

docker run -it --rm -v $(pwd):/ansible jfxs/ansible /bin/sh -c "ansible-galaxy collection install ansible.utils && ansible-playbook playbook.yml"

To test playbooks in your current directory with ansible-lint:

docker run -it --rm -v $(pwd):/ansible jfxs/ansible ansible-lint playbook.yml

The container user is 10010. With a bind mount on a Linux host, run the container with your own user to be able to write in the current directory (the image supports arbitrary user IDs):

docker run -it --rm -u "$(id -u):$(id -g)" -v $(pwd):/ansible jfxs/ansible ansible-playbook playbook.yml

The system SSH client configuration of the image (/etc/ssh/ssh_config) disables the host key checking (StrictHostKeyChecking no). Override it with your own ssh_config or SSH options if you need it.

⁠Built with

Docker latest tag is 2.21.4-003, 2.21, 2⁠.

The complete software bill of materials (SBOM) of each published image, with its known vulnerabilities, is collected in the sbom-docker⁠ repository, under the component docker-ansible.

Dockerhub Overview page⁠ has the details of the last published image.

⁠Versioning

Docker tag definition:

  • the ansible-core version used,
  • a dash
  • an increment to differentiate build with the same version starting at 001
<ansible_version>-<increment>

Example: 2.21.4-001

⁠Signature and attestation

Cosign⁠ public key:

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEa3yV6+yd/l4zh/tfT6Tx+zn0dhy3
BhFqSad1norLeKSCN2MILv4fZ9GA6ODOlJOw+7vzUvzZVr9IXnxEdjoWJw==
-----END PUBLIC KEY-----

The public key is also available online: https://gitlab.com/op_so/docker/cosign-public-key/-/raw/main/cosign.pub⁠.

To verify an image:

cosign verify --key cosign.pub $IMAGE_URI

To verify and get the SBOM attestation:

cosign verify-attestation --key cosign.pub --type spdxjson $IMAGE_URI | jq '.payload | @base64d | fromjson | .predicate'

⁠Authors

⁠License

This program is free software: you can redistribute it and/or modify it under the terms of the MIT License (MIT). See the LICENSE⁠ for details.

Tag summary

Content type

Image

Digest

sha256:bbaf27027…

Size

84.3 MB

Last updated

4 days ago

docker pull jfxs/ansible