Files
KNEL-TSYSDevStack-SupportSt…/Package-Workspace/API-Gateway/apisix/Dockerfile
T
vpengops 17a3e8e9c0 fix(api-gateway): rewrite APISIX package and deploy to production
The 09-01 package referenced a nonexistent Cloudron etcd addon and an
unpinned base image. Rewritten: digest-pinned apisix 3.18.0 with an
embedded single-node etcd, loopback-only Admin API, and read-only
rootfs support. Deployed live at apigw.knownelement.com (healthz 200).

Umbrella: https://projects.knownelement.com/issues/632
2026-09-07 10:02:09 -05:00

44 lines
2.2 KiB
Docker

# APISIX Cloudron Package
#
# Apache APISIX API gateway, traditional deployment mode with an embedded
# single-node etcd. Cloudron has no etcd addon, so the etcd server ships
# inside this image (copied from the upstream release image) and stores its
# state under /app/data/etcd - that keeps the Admin API + dynamic routes
# available without any platform dependency.
#
# Upstream: https://github.com/apache/apisix
# - Official image apache/apisix:3.18.0-debian, runs as non-root apisix
# (uid 636), ENTRYPOINT /docker-entrypoint.sh CMD docker-start which
# does `apisix init` + `apisix init_etcd` then execs openresty with
# `daemon off`.
#
# Authentication: APISIX is a gateway (no user concept). The Admin API
# listens on 127.0.0.1:9180 ONLY (never exposed) and is protected by a
# persisted random admin key in /app/data/.admin_key. Operators reach it
# via `cloudron exec` into the app. Data-plane auth (key-auth, OIDC
# relay, etc.) is route-level and configured per API by the operator.
#
# Pattern: official-image wrapper. Image pinned by tag AND digest.
FROM apache/apisix:3.18.0-debian@sha256:84e6b5e787e9f889ebff88161cb9a16599bafcffa236c6b54c7f779a0655940d
# etcd + etcdctl from the upstream release image (multi-arch manifest
# digest; build resolves the amd64 binary). etcdctl is kept as an ops tool
# for `cloudron exec` debugging of the config store.
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcd /usr/local/bin/etcd
COPY --from=quay.io/coreos/etcd@sha256:d367cba7801b29d2f7481bb56802894658ec8a647834509118c81f77f721381b /usr/local/bin/etcdctl /usr/local/bin/etcdctl
# start.sh waits for etcd, regenerates config.yaml from the Cloudron env
# contract and execs openresty in the foreground. Made executable on the
# host, not at build time (Cloudron builds hit permission errors on RUN chmod).
COPY start.sh /app/start.sh
# Cloudron proxies HTTPS -> this port (manifest httpPort / healthCheckPath "/").
EXPOSE 9080
# Cloudron does not chown /app/data to arbitrary non-root image users, so the
# container runs as root (the Cloudron app convention) and start.sh keeps the
# Admin API loopback-only + key-protected.
USER root
ENTRYPOINT ["/bin/bash", "/app/start.sh"]