The 09-01 package referenced a nonexistent Cloudron etcd addon and an unpinned base image. Rewritten: digest-pinned apisix 3.18.0 with an embedded single-node etcd, loopback-only Admin API, and read-only rootfs support. Deployed live at apigw.knownelement.com (healthz 200). Umbrella: https://projects.knownelement.com/issues/632
44 lines
2.2 KiB
Docker
44 lines
2.2 KiB
Docker
# APISIX Cloudron Package
|
|
#
|
|
# Apache APISIX API gateway, traditional deployment mode with an embedded
|
|
# single-node etcd. Cloudron has no etcd addon, so the etcd server ships
|
|
# inside this image (copied from the upstream release image) and stores its
|
|
# state under /app/data/etcd - that keeps the Admin API + dynamic routes
|
|
# available without any platform dependency.
|
|
#
|
|
# Upstream: https://github.com/apache/apisix
|
|
# - Official image apache/apisix:3.18.0-debian, runs as non-root apisix
|
|
# (uid 636), ENTRYPOINT /docker-entrypoint.sh CMD docker-start which
|
|
# does `apisix init` + `apisix init_etcd` then execs openresty with
|
|
# `daemon off`.
|
|
#
|
|
# Authentication: APISIX is a gateway (no user concept). The Admin API
|
|
# listens on 127.0.0.1:9180 ONLY (never exposed) and is protected by a
|
|
# persisted random admin key in /app/data/.admin_key. Operators reach it
|
|
# via `cloudron exec` into the app. Data-plane auth (key-auth, OIDC
|
|
# relay, etc.) is route-level and configured per API by the operator.
|
|
#
|
|
# Pattern: official-image wrapper. Image pinned by tag AND digest.
|
|
FROM apache/apisix:3.18.0-debian@sha256:84e6b5e787e9f889ebff88161cb9a16599bafcffa236c6b54c7f779a0655940d
|
|
|
|
# etcd + etcdctl from the upstream release image (multi-arch manifest
|
|
# digest; build resolves the amd64 binary). etcdctl is kept as an ops tool
|
|
# for `cloudron exec` debugging of the config store.
|
|
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcd /usr/local/bin/etcd
|
|
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcdctl /usr/local/bin/etcdctl
|
|
|
|
# start.sh waits for etcd, regenerates config.yaml from the Cloudron env
|
|
# contract and execs openresty in the foreground. Made executable on the
|
|
# host, not at build time (Cloudron builds hit permission errors on RUN chmod).
|
|
COPY start.sh /app/start.sh
|
|
|
|
# Cloudron proxies HTTPS -> this port (manifest httpPort / healthCheckPath "/").
|
|
EXPOSE 9080
|
|
|
|
# Cloudron does not chown /app/data to arbitrary non-root image users, so the
|
|
# container runs as root (the Cloudron app convention) and start.sh keeps the
|
|
# Admin API loopback-only + key-protected.
|
|
USER root
|
|
|
|
ENTRYPOINT ["/bin/bash", "/app/start.sh"]
|