|
| 1 | +# Everything in this image is pinned: the base by digest, the Debian archive by a |
| 2 | +# snapshot.debian.org timestamp, clang by version, Go by version and checksum. To refresh it, |
| 3 | +# bump the four values below together and rebuild. |
| 4 | +ARG debian_image=debian:13.7@sha256:9cc080028c43b27d2074d63a5f9caf7166d731494965616c1a6d2827a004585c |
| 5 | +FROM $debian_image |
| 6 | +ARG debian_snapshot=20260915T000000Z |
| 7 | +ARG clang_version=19 |
| 8 | +ARG go_version=1.27.1 |
| 9 | +ARG go_sha256_amd64=63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 |
| 10 | +ARG go_sha256_arm64=3450b45a3f9ee8568792736a5c5e70a1f2e9b36c35a8f74958c03e51d7d92bec |
| 11 | +ENV DEBIAN_FRONTEND noninteractive |
| 12 | + |
| 13 | +# A modern glibc builder for boringssl-static, and the only in-tree image that can build the |
| 14 | +# fips-boringssl-static profile, which compiles BoringSSL with clang. Google's FIPS.md asks for |
| 15 | +# recent stable Clang, Go, Ninja and CMake: clang, ninja and cmake are Debian 13's own. Go is |
| 16 | +# not: BoringSSL's go.mod floor (1.25.8 on the pinned fips-20260721) is ahead of trixie's 1.24, |
| 17 | +# so it comes from go.dev, checksum-verified. patchelf 0.18 has --remove-needed; APR's |
| 18 | +# buildconf wants the `libtool` script, which is in libtool-bin. |
| 19 | +# |
| 20 | +# No JDK 8 in trixie: the build runs on JDK 21. The pom compiles with --release 8, so the |
| 21 | +# class files are still Java 8. |
| 22 | +# |
| 23 | +# Not pinned to linux/amd64 like the older images, so it can also be built natively on an |
| 24 | +# arm64 host for a quick local run. CI builds it on amd64 runners. |
| 25 | +# |
| 26 | +# Unlike the CentOS 6 image this is NOT a release builder: its artifact has a glibc 2.34 floor. |
| 27 | +# It exists to give the boringssl-static and FIPS builds CI coverage on a current toolchain. |
| 28 | + |
| 29 | +# Freeze the archive. snapshot.debian.org serves the archive as it was at that instant, so the |
| 30 | +# same package versions install no matter when the image is built; Valid-Until has long passed |
| 31 | +# by then, hence check-valid-until=no. |
| 32 | +RUN rm -f /etc/apt/sources.list.d/debian.sources \ |
| 33 | + && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian/$debian_snapshot trixie main" > /etc/apt/sources.list \ |
| 34 | + && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian/$debian_snapshot trixie-updates main" >> /etc/apt/sources.list \ |
| 35 | + && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/$debian_snapshot trixie-security main" >> /etc/apt/sources.list |
| 36 | + |
| 37 | +RUN apt-get update && apt-get install -y --no-install-recommends \ |
| 38 | + autoconf \ |
| 39 | + automake \ |
| 40 | + bzip2 \ |
| 41 | + ca-certificates \ |
| 42 | + clang-$clang_version \ |
| 43 | + cmake \ |
| 44 | + curl \ |
| 45 | + g++ \ |
| 46 | + gcc \ |
| 47 | + git \ |
| 48 | + gnupg \ |
| 49 | + libapr1-dev \ |
| 50 | + libtool \ |
| 51 | + libtool-bin \ |
| 52 | + make \ |
| 53 | + ninja-build \ |
| 54 | + openjdk-21-jdk-headless \ |
| 55 | + patch \ |
| 56 | + patchelf \ |
| 57 | + perl \ |
| 58 | + pkg-config \ |
| 59 | + tar \ |
| 60 | + unzip \ |
| 61 | + wget \ |
| 62 | + xz-utils \ |
| 63 | + zip \ |
| 64 | + && rm -rf /var/lib/apt/lists/* \ |
| 65 | + && ln -s clang-$clang_version /usr/bin/clang && ln -s clang++-$clang_version /usr/bin/clang++ |
| 66 | + |
| 67 | +# dpkg's amd64/arm64 spelling matches go.dev's and the JVM directory name. |
| 68 | +RUN ARCH=$(dpkg --print-architecture) \ |
| 69 | + && case $ARCH in amd64) GO_SHA256=$go_sha256_amd64;; arm64) GO_SHA256=$go_sha256_arm64;; esac \ |
| 70 | + && wget -q https://go.dev/dl/go$go_version.linux-$ARCH.tar.gz \ |
| 71 | + && echo "$GO_SHA256 go$go_version.linux-$ARCH.tar.gz" | sha256sum -c - \ |
| 72 | + && tar -C /opt -xzf go$go_version.linux-$ARCH.tar.gz && rm go$go_version.linux-$ARCH.tar.gz \ |
| 73 | + && ln -s /opt/go/bin/go /usr/local/bin/go && ln -s /opt/go/bin/gofmt /usr/local/bin/gofmt \ |
| 74 | + && ln -s /usr/lib/jvm/java-21-openjdk-$ARCH /usr/lib/jvm/java-21 \ |
| 75 | + && go version && clang --version | head -1 && ninja --version && cmake --version | head -1 |
| 76 | +ENV JAVA_HOME /usr/lib/jvm/java-21 |
| 77 | +# Use exactly the pinned Go; never let it fetch another toolchain. |
| 78 | +ENV GOTOOLCHAIN local |
| 79 | + |
| 80 | +# /code is a bind mount owned by the host user; newer git refuses to touch it otherwise. |
| 81 | +RUN git config --global --add safe.directory '*' |
0 commit comments