Sign inSign up

mbauer599/proxer

By mbauer599

•Updated 3 months ago

A security focused docker socket proxy, aimed at build functionality via an API interface

Image
Security
Integration & delivery
0

1.5K

mbauer599/proxer repository overview

⁠What is Proxer

Proxer is a project that I started in my off-time to address the near constant issue of running Docker builds in GitLab CI without enabling privileged mode for the runner jobs. It comes in two parts:

  • A small footprint, security focused server that runs in a container that mounts the local docker socket (/var/run/docker.sock) and exposes an API endpoint for Docker image builds. The Server will do the following (attempting to use the default GitLab CI runner variables):
    • Clone a remote repository;
    • Build the configured Dockerfile;
    • Cache the image layers for quick building in the future;
    • Tag and push the images to the configured container registry.
  • A small footprint python client that runs in a container 'mbauer599/proxer:client⁠' that can be used to push the request to the server.
    • The client, if running in a GitLab CI Job, will use the default CI Vars out of the box, so you don't have much to configure.

⁠The major issues with GitLab Runners:

  • When you configure a service (DinD) to build the docker image, there is no way to run the service as privileged without running the job as privileged;
  • and even if there was, allowing privileged mode for the DinD service and port access to that service, allows you to interface with the container that is running in privileged mode with few real constraints;
  • and I'm really tired of non-answers to this question. If you think that running a separate container with --privileged solves this issue, you're wrong.

If you would like to know more, then this is a pretty good article by trendmicro.com.⁠

⁠Example - Server

version: '3.7'

services:
  redis:
    image: redis
    ports:
      - "6379:6379"
  api:
    image: mbauer599/proxer:server
    depends_on:
      - redis
    links:
      - redis
    deploy:
      replicas: 1
      restart_policy:
        condition: any
    ports:
      - "8443:8443"
  worker:
    image: mbauer599/proxer:worker
    depends_on:
      - redis
    links:
      - redis
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock  # Mount Docker socket

⁠Client (.gitlab-ci.yml)

local-build:
  stage: build
  image: mbauer599/proxer:client
  script:
    - proxer --dockerfile "Dockerfile" --tags "testing" --server "https://your_proxer_server_instance:8443" 

⁠Projects without a source are sketchy, so where can I find the juicy bits?

I think so too, and this will probably end up on github at some point but for now it's on my personal GitLab⁠.

⁠This is a work in progress and has a ways to go.

Tag summary

Content type

Image

Digest

sha256:495c79089…

Size

405.5 MB

Last updated

3 months ago

docker pull mbauer599/proxer:worker