Consistent linting, building and pushing Docker images (and their README files) across projects.
10K+
This image, onestic/docker-ci, is designed to facilitate consistent linting, building, and pushing Docker images (and their README files) across projects.
It's been optimized for seamless integration into Bitbucket Pipelines, ensuring reliable and standardized Docker image management process.
This image is built for linux/amd64 and linux/arm64 platforms.
The only supported tag for this image is based and limited to the major Docker version they are based on: 25-cli.
This tag will be updated daily. New features may be added, always in a retro compatible way, using feature flags if needed for their activation.
Note: There may be other development-related tags, use at your own discretion.
When started with arguments, containers based on this image will behave as a regular docker:25-cli container. It is possible to run this image this way, but it does not offer any advantage compared to its base image.
The intended way to use this image is without arguments, configured using environment variables. When used this way (pipe mode), it will attempt to execute the following actions:
Sample usage (with short variables description) in Bitbucket pipelines as a pipe (remove commented lines that you don't need):
pipelines:
default:
- step:
name: 'Lint, build & push'
script:
- pipe: 'docker://onestic/docker-ci:25-cli'
variables:
# Uncomment lines below to skip pipe actions.
# DOCKER_CI_LINT_SKIP: '1'
# DOCKER_CI_LOGIN_SKIP: '1'
# DOCKER_CI_BUILD_SKIP: '1'
# DOCKER_CI_PUSHRM_SKIP: '1'
# Uncomment and adapt line below to specify a workdir different from default. You usually won't need this.
# DOCKER_CI_WORKDIR: ${BITBUCKET_CLONE_DIR}
# Uncomment and adapt line below to specify custom path to Dockerfile. You won't need it unless Dockerfile is not at the repository root.
# DOCKER_CI_DOCKERFILE: ${BITBUCKET_CLONE_DIR}/Dockerfile
# Uncomment line below to increment shell verbosity (-x).
# DOCKER_CI_DEBUG: '1'
# Uncomment and adapt line below to log in to a different registry (other than Docker Hub).
# DOCKER_CI_LOGIN_REGISTRY: docker.io
# Declare and set login values as secure variables within Bitbucket system.
DOCKER_CI_LOGIN_REGISTRY_USER: ${DOCKER_CI_LOGIN_REGISTRY_USER}
DOCKER_CI_LOGIN_REGISTRY_PASSWORD: ${DOCKER_CI_LOGIN_REGISTRY_PASSWORD}
# Uncomment and adapt line below to tag / push image to a different registry (other than Docker Hub).
# DOCKER_CI_BUILD_IMAGE_REGISTRY: docker.io
# Uncomment and adapt line below to tag / push image for a different registry user (other than onestic).
# DOCKER_CI_BUILD_IMAGE_USER: 'onestic'
# Uncomment and adapt line below to tag / push image for a different registry repository (other than repository slug).
# DOCKER_CI_BUILD_IMAGE_REPOSITORY: ${BITBUCKET_REPO_SLUG}
# Uncomment and adapt line below to specify platforms to build against, when they differ from defaults.
# DOCKER_CI_BUILD_PLATFORM_EMULATORS: 'linux/amd64,linux/arm64'
# If build context is the repository root itself, and not the context folder, uncomment line below.
# DOCKER_CI_BUILD_CONTEXT: ${BITBUCKET_CLONE_DIR}
# Uncomment and use line below to specify Dockerfile build args if needed.
# DOCKER_CI_BUILD_ARGS: ''
# Uncomment and adapt line below if you need to fine tune `docker buildx build` command arguments.
# DOCKER_CI_BUILD_COMMAND_ARGS: '--push'
# Use line below to specify additional image tags (within target registry, user and repository).
# DOCKER_CI_BUILD_TAGS: ''
# The rest of lines are used for automatic tagging.
# You can override then or set them empty on purpose if you want to skip some type of automatic tags.
# DOCKER_CI_BUILD_NUMBER: ''
# DOCKER_CI_BUILD_TAG: ''
# DOCKER_CI_BUILD_PR_ID: ''
# DOCKER_CI_BUILD_BRANCH: ''
It is possible to run this image in one-shot mode, for example for linting, as long as you define action variables, mount volumes and define working directory properly.
For example, if you cd into a project where there is a Dockerfile, you could lint the Dockerfile this way:
docker run --rm -it \
-e DOCKER_CI_LOGIN_SKIP=1 \
-e DOCKER_CI_BUILD_SKIP=1 \
-e DOCKER_CI_PUSHRM_SKIP=1 \
-w /opt/project \
-v "$(pwd):/opt/project" \
-- \
onestic/docker-ci:25-cli
The previous will:
Following the previous example, it is possible to execute any combination of pipe actions manually / locally in one-shot mode.
Each pipe action can be skipped by setting its own skip environment variables to 1:
| Variable | Short description | Mandatory | Default |
|---|---|---|---|
| DOCKER_CI_LINT_SKIP | Skip Docker lint action. Set to 1 to skip this action. | No | 0 |
| DOCKER_CI_LOGIN_SKIP | Skip Docker registry login action. Set to 1 to skip this action. | No | 0 |
| DOCKER_CI_BUILD_SKIP | Skip Docker build / push action. Set to 1 to skip this action. | No | 0 |
| DOCKER_CI_PUSHRM_SKIP | Skip pushing README-containers.md / README.md file to Docker / container registry. Set to 1 to skip this action. | No | 0 |
| Variable | Short description | Mandatory | Default |
|---|---|---|---|
| DOCKER_CI_WORKDIR | Working directory. | No | ${BITBUCKET_CLONE_DIR:-$(pwd)} |
| DOCKER_CI_DOCKERFILE | Path to Dockerfile (absolute or relative to workdir). | No | ${DOCKER_CI_WORKDIR}/Dockerfile |
| DOCKER_CI_DEBUG | Whether to activate shell verbose mode (-x) or not. Set to 1 to activate. | No | 0 |
Please note that mandatory variables are only mandatory when action is not skipped.
| Uses inherited variable | Short description |
|---|---|
| DOCKER_CI_DOCKERFILE | Used for finding Dockerfile to be linted. See common variables. |
Please note that mandatory variables are only mandatory when action is not skipped.
| Variable | Short description | Mandatory | Default |
|---|---|---|---|
| DOCKER_CI_LOGIN_REGISTRY | Registry to login to. | No | docker.io |
| DOCKER_CI_LOGIN_REGISTRY_USER | Username to use for login. | Yes | |
| DOCKER_CI_LOGIN_REGISTRY_PASSWORD | Password to use for login. | Yes |
Please note that mandatory variables are only mandatory when action is not skipped.
| Uses inherited variable | Short description |
|---|---|
| DOCKER_CI_DOCKERFILE | Used for finding Dockerfile to be used for building. See common variables. |
The following table shows action specific variables:
| Variable | Short description | Mandatory | Default |
|---|---|---|---|
| DOCKER_CI_BUILD_IMAGE_REGISTRY | Registry to push image to. For example, in docker.io/nginx/hello-world:1.19 would correspond to the docker.io part. | No | docker.io |
| DOCKER_CI_BUILD_IMAGE_USER | User that owns the repository that we'll be pushing to. For example, in docker.io/nginx/hello-world:1.19 would correspond to the nginx part. | No | onestic |
| DOCKER_CI_BUILD_IMAGE_REPOSITORY | Repository to push image against. For example, in docker.io/nginx/hello-world:1.19 would correspond to the hello-world part. | Only if pushing to registry and not in Bitbucket CI | In Bitbucket CI, defaults to ${BITBUCKET_REPO_SLUG} |
| DOCKER_CI_BUILD_PLATFORM_EMULATORS | Indicates the platforms the image will be built for. | No | linux/amd64,linux/arm64 |
| DOCKER_CI_BUILD_CONTEXT | The build context used for building the image. | No | ${DOCKER_CI_WORKDIR}/context |
| DOCKER_CI_BUILD_ARGS | The build arguments needed, as declared in Dockerfile. For example, setting this variable to PHP_VERSION=8.1 COMPOSER_VERSION=2 will translate as --build-arg 'PHP_VERSION=8.1' --build-arg 'COMPOSER_VERSION=2' | Only if Dockerfile requires build args. | |
| DOCKER_CI_BUILD_COMMAND_ARGS | Allows to modify the list of options passed to docker buildx buildNOTE: As it defaults to --push, when you define this variable to define custom arguments for building, do not forget adding --push if you want to preserve pushing to registry behaviour. | No | --push |
| DOCKER_CI_BUILD_TAGS | Aside the automatic tags, use this variable to add space-separated additional tags the image needs to be tagged with. | No | |
| DOCKER_CI_BUILD_NUMBER | Optional. If available, will be used for computing automatic tags. If defined and not empty, image will have an additional tag named build-${DOCKER_CI_BUILD_NUMBER}. | No | In Bitbucket CI, defaults to ${BITBUCKET_BUILD_NUMBER}, available in every pipeline. |
| DOCKER_CI_BUILD_TAG | Optional. If available, will be used for computing automatic tags. If defined and not empty, image will have an additional tag named ${DOCKER_CI_BUILD_TAG}. | No | In Bitbucket CI, defaults to ${BITBUCKET_TAG}, available only in builds against repository tag. |
| DOCKER_CI_BUILD_PR_ID | Optional. If available, will be used for computing automatic tags. If defined and not empty, image will have an additional tag named pr-${DOCKER_CI_BUILD_TAG}. | No | In Bitbucket CI, defaults to ${BITBUCKET_PR_ID}, available only in builds against PRs. |
| DOCKER_CI_BUILD_BRANCH | Optional. If available, will be used for computing automatic tags. If defined and not empty: - If branch name is main or master, image will have an additional tag named latest.- Similar to Composer, if branch name resembles a version number, image will have an additional tag named ${DOCKER_CI_BUILD_BRANCH}.x-dev.- Also similar to Composer, in any other cases, image will have an additional tag named dev-${DOCKER_CI_BUILD_BRANCH}. | No | In Bitbucket CI, defaults to ${BITBUCKET_BRANCH}, available only in builds against branches. |
Please note that mandatory variables are only mandatory when action is not skipped.
Also note that pushing README files over 25k characters to Docker Hub may fail.
| Uses inherited variable | Short description |
|---|---|
| DOCKER_CI_DOCKERFILE | Used for finding Dockerfile to be used for building. See common variables. |
The following table shows action specific variables:
| Variable | Short description | Mandatory | Default |
|---|---|---|---|
| DOCKER_CI_BUILD_IMAGE_REGISTRY | Registry to push README-containers.md / README.md contents to. | No | docker.io |
| DOCKER_CI_BUILD_IMAGE_USER | User that owns the repository that we'll be pushing README-containers.md / README.md. | No | onestic |
| DOCKER_CI_BUILD_IMAGE_REPOSITORY | Repository to push README-containers.md / README.md contents to. | Only if not in Bitbucket CI | In Bitbucket CI, defaults to ${BITBUCKET_REPO_SLUG} |
Content type
Image
Digest
sha256:4dc2e93d1…
Size
70.6 MB
Last updated
7 months ago
docker pull onestic/docker-ci