fix(api-gateway): rewrite APISIX package and deploy to production
The 09-01 package referenced a nonexistent Cloudron etcd addon and an unpinned base image. Rewritten: digest-pinned apisix 3.18.0 with an embedded single-node etcd, loopback-only Admin API, and read-only rootfs support. Deployed live at apigw.knownelement.com (healthz 200). Umbrella: https://projects.knownelement.com/issues/632
This commit is contained in:
@@ -1,7 +1,43 @@
|
||||
FROM apache/apisix:latest
|
||||
# APISIX Cloudron Package
|
||||
#
|
||||
# Apache APISIX API gateway, traditional deployment mode with an embedded
|
||||
# single-node etcd. Cloudron has no etcd addon, so the etcd server ships
|
||||
# inside this image (copied from the upstream release image) and stores its
|
||||
# state under /app/data/etcd - that keeps the Admin API + dynamic routes
|
||||
# available without any platform dependency.
|
||||
#
|
||||
# Upstream: https://github.com/apache/apisix
|
||||
# - Official image apache/apisix:3.18.0-debian, runs as non-root apisix
|
||||
# (uid 636), ENTRYPOINT /docker-entrypoint.sh CMD docker-start which
|
||||
# does `apisix init` + `apisix init_etcd` then execs openresty with
|
||||
# `daemon off`.
|
||||
#
|
||||
# Authentication: APISIX is a gateway (no user concept). The Admin API
|
||||
# listens on 127.0.0.1:9180 ONLY (never exposed) and is protected by a
|
||||
# persisted random admin key in /app/data/.admin_key. Operators reach it
|
||||
# via `cloudron exec` into the app. Data-plane auth (key-auth, OIDC
|
||||
# relay, etc.) is route-level and configured per API by the operator.
|
||||
#
|
||||
# Pattern: official-image wrapper. Image pinned by tag AND digest.
|
||||
FROM apache/apisix:3.18.0-debian@sha256:84e6b5e787e9f889ebff88161cb9a16599bafcffa236c6b54c7f779a0655940d
|
||||
|
||||
# Copy start script (already executable from host)
|
||||
COPY start.sh /start.sh
|
||||
# etcd + etcdctl from the upstream release image (multi-arch manifest
|
||||
# digest; build resolves the amd64 binary). etcdctl is kept as an ops tool
|
||||
# for `cloudron exec` debugging of the config store.
|
||||
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcd /usr/local/bin/etcd
|
||||
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcdctl /usr/local/bin/etcdctl
|
||||
|
||||
# Start APISIX
|
||||
CMD ["/start.sh"]
|
||||
# start.sh waits for etcd, regenerates config.yaml from the Cloudron env
|
||||
# contract and execs openresty in the foreground. Made executable on the
|
||||
# host, not at build time (Cloudron builds hit permission errors on RUN chmod).
|
||||
COPY start.sh /app/start.sh
|
||||
|
||||
# Cloudron proxies HTTPS -> this port (manifest httpPort / healthCheckPath "/").
|
||||
EXPOSE 9080
|
||||
|
||||
# Cloudron does not chown /app/data to arbitrary non-root image users, so the
|
||||
# container runs as root (the Cloudron app convention) and start.sh keeps the
|
||||
# Admin API loopback-only + key-protected.
|
||||
USER root
|
||||
|
||||
ENTRYPOINT ["/bin/bash", "/app/start.sh"]
|
||||
|
||||
Reference in New Issue
Block a user