feat: container-based Bitwarden CLI using native Rust binary (no Node.js)
Replace the Node.js @bitwarden/cli dependency with the pre-compiled native Rust binary (v2026.7.0) for CMMC/ITAR/STIG audit readiness. The Node.js dependency tree was a significant attack surface that would fail security audits. Infrastructure: - docker/bw-native/Dockerfile: minimal debian-slim + native bw binary - scripts/bw-cli.sh: host wrapper handling full auth lifecycle (config, API-key login, unlock, sync) inside the container - scripts/bw-entrypoint.sh: container entrypoint for auth lifecycle - scripts/bw-install.sh: one-command installer (download, build, deploy) Root causes fixed: - ~/.config/bw/env values now single-quoted (master password has $ chars that shell expansion corrupted, truncating 32→16 chars) - Added BW_SERVER for self-hosted instance (pwvault.turnsys.com) - Entrypoint bw config server tolerates re-run (|| true) All scripts pass shellcheck with zero warnings including info-level. Verified: bw status (unlocked, coo@turnsys.com), generate, list items. 💘 Generated with Crush Assisted-by: Crush:glm-5.2
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Dockerfile — Native Bitwarden CLI (Rust binary, no Node.js)
|
||||
#
|
||||
# Builds a minimal container image around the pre-compiled native bw CLI
|
||||
# binary from the official Bitwarden GitHub releases. The binary is a
|
||||
# Rust executable with glibc dependencies. No Node.js runtime is
|
||||
# included or required.
|
||||
#
|
||||
# Build prerequisites:
|
||||
# 1. Download the native binary:
|
||||
# https://github.com/bitwarden/clients/releases/download/cli-v2026.7.0/bw-linux-2026.7.0.zip
|
||||
# 2. Unzip and place the `bw` executable next to this Dockerfile.
|
||||
# 3. Build: docker build -t reachableceo-bw-native:2026.7.0 .
|
||||
#
|
||||
# Or use the installer: scripts/bw-install.sh
|
||||
|
||||
FROM debian:bookworm-slim
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates && rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY bw /usr/local/bin/bw
|
||||
RUN chmod +x /usr/local/bin/bw
|
||||
|
||||
ENTRYPOINT ["bw"]
|
||||
Reference in New Issue
Block a user