A security focused docker socket proxy, aimed at build functionality via an API interface
1.5K
Proxer is a project that I started in my off-time to address the near constant issue of running Docker builds in GitLab CI without enabling privileged mode for the runner jobs. It comes in two parts:
/var/run/docker.sock) and exposes an API endpoint for Docker image builds. The Server will do the following (attempting to use the default GitLab CI runner variables):
--privileged solves this issue, you're wrong.If you would like to know more, then this is a pretty good article by trendmicro.com.
version: '3.7'
services:
redis:
image: redis
ports:
- "6379:6379"
api:
image: mbauer599/proxer:server
depends_on:
- redis
links:
- redis
deploy:
replicas: 1
restart_policy:
condition: any
ports:
- "8443:8443"
worker:
image: mbauer599/proxer:worker
depends_on:
- redis
links:
- redis
volumes:
- /var/run/docker.sock:/var/run/docker.sock # Mount Docker socket
.gitlab-ci.yml)local-build:
stage: build
image: mbauer599/proxer:client
script:
- proxer --dockerfile "Dockerfile" --tags "testing" --server "https://your_proxer_server_instance:8443"
I think so too, and this will probably end up on github at some point but for now it's on my personal GitLab.
Content type
Image
Digest
sha256:495c79089…
Size
405.5 MB
Last updated
3 months ago
docker pull mbauer599/proxer:worker