From fa1469d6c3366e723541891add563611568f4c54 Mon Sep 17 00:00:00 2001 From: Travis Dockter Date: Wed, 5 Aug 2026 15:41:34 -0600 Subject: [PATCH] Docker audit --- .dockerignore | 51 +++++++++++++++++++++++++++++++++++++++++++ Dockerfile | 20 ----------------- Dockerfile.prod | 13 +++++------ bin/docker-entrypoint | 16 ++++++++------ entrypoint.sh | 12 ---------- 5 files changed, 66 insertions(+), 46 deletions(-) create mode 100644 .dockerignore delete mode 100755 entrypoint.sh diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..7746d69 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,51 @@ +# See https://docs.docker.com/engine/reference/builder/#dockerignore-file for more about ignoring files. + +# Ignore git directory. +/.git/ +/.gitignore + +# Ignore bundler config. +/.bundle + +# Ignore all environment files. +/.env* + +# Ignore all default key files. +/config/master.key + +# Ignore all logfiles and tempfiles. +/log/* +/tmp/* +!/log/.keep +!/tmp/.keep + +# Ignore pidfiles, but keep the directory. +/tmp/pids/* +!/tmp/pids/ +!/tmp/pids/.keep + +# Ignore storage (uploaded files in development and any SQLite databases). +/storage/* +!/storage/.keep +/tmp/storage/* +!/tmp/storage/ +!/tmp/storage/.keep + +# Ignore assets. +/node_modules/ +/public/assets + +# Ignore CI/CD service files. +/.github + +# Ignore Kamal secrets/config. +/.kamal + +# Ignore locally-installed gems; the build stage runs its own bundle install. +/vendor/bundle + +# Ignore test-only artifacts and tooling not needed in the production image. +/coverage +/spec +/cypress +/cypress.config.js diff --git a/Dockerfile b/Dockerfile index db6c9e1..86a878e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,26 +9,6 @@ WORKDIR $APP_HOME ARG UID=1000 ARG GID=1000 -#RUN apt-get update \ -# && apt-get install -y --no-install-recommends build-essential git curl \ -# && rm -rf /var/lib/apt/lists/* /usr/share/doc /usr/share/man \ -# && apt-get clean \ -# && groupadd -g "${GID}" ruby \ -# && useradd --create-home --no-log-init -u "${UID}" -g "${GID}" ruby \ -# && chown -R ruby:ruby $APP_HOME - -RUN bash -c "set -o pipefail && apt-get update \ - && apt-get install -y --no-install-recommends build-essential curl git libpq-dev libyaml-dev \ - && curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key -o /etc/apt/keyrings/nodesource.asc \ - && echo 'deb [signed-by=/etc/apt/keyrings/nodesource.asc] https://deb.nodesource.com/node_22.x nodistro main' | tee /etc/apt/sources.list.d/nodesource.list \ - && apt-get update && apt-get install -y --no-install-recommends nodejs \ - && corepack enable \ - && rm -rf /var/lib/apt/lists/* /usr/share/doc /usr/share/man \ - && apt-get clean \ - && groupadd -g \"${GID}\" ruby \ - && useradd --create-home --no-log-init -u \"${UID}\" -g \"${GID}\" ruby \ - && mkdir /node_modules && chown ruby:ruby -R /node_modules /app_home" - EXPOSE 3000 ENTRYPOINT ["./bin/docker-entrypoint"] diff --git a/Dockerfile.prod b/Dockerfile.prod index 4d3c40e..188b78a 100644 --- a/Dockerfile.prod +++ b/Dockerfile.prod @@ -3,11 +3,11 @@ # This Dockerfile is designed for production, not development. Use with Kamal or build'n'run by hand: # docker build -t today . -# docker run -d -p 80:80 -e RAILS_MASTER_KEY= --name today today +# docker run -d -p 3000:3000 -e RAILS_MASTER_KEY= --name today today # For a containerized dev environment, see Dev Containers: https://guides.rubyonrails.org/getting_started_with_devcontainer.html -# Make sure RUBY_VERSION matches the Ruby version in .ruby-version +# Make sure RUBY_VERSION matches the Ruby version in the Gemfile ARG RUBY_VERSION=4.0 FROM docker.io/library/ruby:$RUBY_VERSION-slim AS base @@ -24,7 +24,7 @@ RUN apt-get update -qq && \ ENV RAILS_ENV="production" \ BUNDLE_DEPLOYMENT="1" \ BUNDLE_PATH="/usr/local/bundle" \ - BUNDLE_WITHOUT="development" \ + BUNDLE_WITHOUT="development test" \ LD_PRELOAD="/usr/local/lib/libjemalloc.so" # Throw-away build stage to reduce size of final image @@ -32,7 +32,7 @@ FROM base AS build # Install packages needed to build gems RUN apt-get update -qq && \ - apt-get install --no-install-recommends -y build-essential git libyaml-dev pkg-config && \ + apt-get install --no-install-recommends -y build-essential libyaml-dev pkg-config && \ rm -rf /var/lib/apt/lists /var/cache/apt/archives # Install application gems @@ -69,8 +69,7 @@ COPY --chown=rails:rails --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}" COPY --chown=rails:rails --from=build /rails /rails # Entrypoint prepares the database. -#ENTRYPOINT ["/rails/bin/docker-entrypoint"] +ENTRYPOINT ["/rails/bin/docker-entrypoint"] -# Start server via Thruster by default, this can be overwritten at runtime -EXPOSE 80 +EXPOSE 3000 CMD ["./bin/rails", "server"] diff --git a/bin/docker-entrypoint b/bin/docker-entrypoint index 0cbd8b4..c4b6069 100755 --- a/bin/docker-entrypoint +++ b/bin/docker-entrypoint @@ -1,11 +1,13 @@ #!/bin/bash -if bundle check -then - echo "Bundle installing..." - bundle install > ${BUNDLE_PATH}/bundle_install - tail -n 2 ${BUNDLE_PATH}/bundle_install -else - bundle install +if [ "${RAILS_ENV}" != "production" ]; then + if bundle check + then + echo "Bundle installing..." + bundle install > ${BUNDLE_PATH}/bundle_install + tail -n 2 ${BUNDLE_PATH}/bundle_install + else + bundle install + fi fi # If running the rails server then create or migrate existing database diff --git a/entrypoint.sh b/entrypoint.sh deleted file mode 100755 index 88a8f07..0000000 --- a/entrypoint.sh +++ /dev/null @@ -1,12 +0,0 @@ -#!/bin/bash - -if bundle check -then - echo "Bundle installing..." - bundle install --jobs=`getconf _NPROCESSORS_ONLN` > ${BUNDLE_PATH}/bundle_install - tail -n 2 ${BUNDLE_PATH}/bundle_install -else - bundle install --jobs=`getconf _NPROCESSORS_ONLN` -fi - -exec "$@"