Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions Dockerfile.gateway
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,15 @@ COPY api api
COPY api/LICENSE /licenses/
WORKDIR /opt/app-root/src/api

RUN CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -mod=mod -tags strictfipsruntime -o tempostack-gateway -trimpath -ldflags "-s -w"
RUN CGO_ENABLED=0 GOFIPS140=certified go build -mod=mod -tags no_openssl -o tempostack-gateway -trimpath -ldflags "-s -w"

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base

FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as install-additional-packages
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -36,6 +36,7 @@ RUN mkdir /licenses
COPY api/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/api/tempostack-gateway /usr/bin/tempostack-gateway

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/tempostack-gateway"]
Expand Down
5 changes: 3 additions & 2 deletions Dockerfile.jaegerquery
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ RUN go version && \
exportOrFail VERSION_DATE=`date -u +'%Y-%m-%dT%H:%M:%SZ'` && \
exportOrFail GIT_LATEST_TAG="1.68.0" && \
exportOrFail GIT_COMMIT_SHA=`git rev-parse HEAD` && \
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -C ./cmd/query -mod=mod -tags strictfipsruntime,ui \
CGO_ENABLED=0 GOFIPS140=certified go build -C ./cmd/query -mod=mod -tags no_openssl,ui \
-o ./jaeger -trimpath -ldflags "-s -w \
-X ${VERSION_PKG}.commitSHA=${GIT_COMMIT_SHA} \
-X ${VERSION_PKG}.latestVersion=${GIT_LATEST_TAG} \
Expand All @@ -53,7 +53,7 @@ FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f2660
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -69,6 +69,7 @@ RUN mkdir /licenses
COPY jaeger/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/jaeger/cmd/query/jaeger /usr/bin/jaeger

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/jaeger"]
Expand Down
5 changes: 3 additions & 2 deletions Dockerfile.opa
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,15 @@ COPY opa-openshift opa-openshift
COPY api/LICENSE /licenses/
WORKDIR /opt/app-root/src/opa-openshift

RUN CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -mod=mod -tags strictfipsruntime -o opa-openshift -trimpath -ldflags "-s -w"
RUN CGO_ENABLED=0 GOFIPS140=certified go build -mod=mod -tags no_openssl -o opa-openshift -trimpath -ldflags "-s -w"

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base

FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as install-additional-packages
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -36,6 +36,7 @@ RUN mkdir /licenses
COPY opa-openshift/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/opa-openshift/opa-openshift /usr/bin/opa-openshift

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/opa-openshift"]
Expand Down
5 changes: 3 additions & 2 deletions Dockerfile.operator
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ RUN exportOrFail() { echo $1; if [[ $1 == *= ]]; then echo "Error: empty variabl
exportOrFail TEMPO_VERSION=`cat config/manager/manager.yaml | grep -oP "docker.io/grafana/tempo:\K.*"` && \
exportOrFail TEMPO_QUERY_VERSION=`cat config/manager/manager.yaml | grep -oP "docker.io/grafana/tempo-query:\K.*"` && \
ls -al && \
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -mod=mod -tags strictfipsruntime \
CGO_ENABLED=0 GOFIPS140=certified go build -mod=mod -tags no_openssl \
-o "tempo-operator" -trimpath -ldflags "-s -w \
-X ${VERSION_PKG}.buildDate=${BUILD_DATE} \
-X ${VERSION_PKG}.revision=${COMMIT_SHA} \
Expand All @@ -39,7 +39,7 @@ FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f2660
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -54,6 +54,7 @@ RUN mkdir /licenses
COPY tempo-operator/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/tempo-operator/tempo-operator /usr/bin/tempo-operator

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/tempo-operator"]
Expand Down
5 changes: 3 additions & 2 deletions Dockerfile.tempo
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ RUN exportOrFail() { echo $1; if [[ $1 == *= ]]; then echo "Error: empty variabl
exportOrFail GIT_BRANCH=`git rev-parse --abbrev-ref HEAD` && \
exportOrFail GIT_REVISION=`git rev-parse --short HEAD` && \
exportOrFail VERSION="2.10.8" && \
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -C ./cmd/tempo -tags strictfipsruntime -mod vendor \
CGO_ENABLED=0 GOFIPS140=certified go build -C ./cmd/tempo -tags no_openssl -mod vendor \
-o "tempo" -trimpath -ldflags "-s -w -X main.Branch=${GIT_BRANCH} -X main.Revision=${GIT_REVISION} -X main.Version=${VERSION}"

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base
Expand All @@ -26,7 +26,7 @@ FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f2660
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -41,6 +41,7 @@ RUN mkdir /licenses
COPY tempo/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/tempo/cmd/tempo/tempo /usr/bin/tempo

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/tempo"]
Expand Down
5 changes: 3 additions & 2 deletions Dockerfile.tempoquery
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ RUN exportOrFail() { echo $1; if [[ $1 == *= ]]; then echo "Error: empty variabl
exportOrFail GIT_BRANCH=`git rev-parse --abbrev-ref HEAD` && \
exportOrFail GIT_REVISION=`git rev-parse --short HEAD` && \
exportOrFail VERSION="2.10.8" && \
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -C ./cmd/tempo-query -tags strictfipsruntime -mod vendor \
CGO_ENABLED=0 GOFIPS140=certified go build -C ./cmd/tempo-query -tags no_openssl -mod vendor \
-o "tempo-query" -trimpath -ldflags "-s -w -X main.Branch=${GIT_BRANCH} -X main.Revision=${GIT_REVISION} -X main.Version=${VERSION}"

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base
Expand All @@ -26,7 +26,7 @@ FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f2660
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*
Expand All @@ -41,6 +41,7 @@ RUN mkdir /licenses
COPY tempo/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/tempo/cmd/tempo-query/tempo-query /usr/bin/tempo-query

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/tempo-query"]
Expand Down
1 change: 0 additions & 1 deletion rpms.in.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ contentOrigin:
packages:
- git
- golang
- openssl
- systemd
- patch
arches:
Expand Down
Loading