|
| 1 | +ARG debian_version=13 |
| 2 | +FROM debian:$debian_version |
| 3 | +# needed to do again after FROM due to docker limitation |
| 4 | +ARG debian_version |
| 5 | +ARG go_version=1.22.3 |
| 6 | +ARG cmake_version=3.29.3 |
| 7 | +ENV GO_VERSION $go_version |
| 8 | +ENV CMAKE_VERSION $cmake_version |
| 9 | +ENV DEBIAN_FRONTEND noninteractive |
| 10 | + |
| 11 | +# A modern glibc builder for boringssl-static, and the only in-tree image that can build the |
| 12 | +# fips-boringssl-static profile. That profile pins the BoringCrypto module that holds |
| 13 | +# certificate #5244, and this image carries the build environment its security policy names: |
| 14 | +# clang 17.0.6, go 1.22.3, ninja 1.12.1, cmake 3.29.3 |
| 15 | +# Debian 13 packages clang-17 at exactly 17.0.6 and ninja at exactly 1.12.1. Its cmake (3.31) |
| 16 | +# and Go (1.24) are newer than the policy's, so those two come from cmake.org and go.dev at the |
| 17 | +# policy's versions instead. patchelf 0.18 has --remove-needed; APR's buildconf wants the |
| 18 | +# `libtool` script, which is in libtool-bin. |
| 19 | +# |
| 20 | +# No JDK 8 in trixie: the build runs on JDK 21. The pom compiles with --release 8, so the |
| 21 | +# class files are still Java 8. |
| 22 | +# |
| 23 | +# Not pinned to linux/amd64 like the older images, so it can also be built natively on an |
| 24 | +# arm64 host for a quick local run. CI builds it on amd64 runners. |
| 25 | +# |
| 26 | +# Unlike the CentOS 6 image this is NOT a release builder: its artifact has a glibc 2.41 floor. |
| 27 | +# It exists to give the boringssl-static and FIPS builds CI coverage on a current toolchain. |
| 28 | +RUN apt-get update && apt-get install -y --no-install-recommends \ |
| 29 | + autoconf \ |
| 30 | + automake \ |
| 31 | + bzip2 \ |
| 32 | + ca-certificates \ |
| 33 | + clang-17 \ |
| 34 | + curl \ |
| 35 | + g++ \ |
| 36 | + gcc \ |
| 37 | + git \ |
| 38 | + gnupg \ |
| 39 | + libapr1-dev \ |
| 40 | + libtool \ |
| 41 | + libtool-bin \ |
| 42 | + make \ |
| 43 | + ninja-build \ |
| 44 | + openjdk-21-jdk-headless \ |
| 45 | + patch \ |
| 46 | + patchelf \ |
| 47 | + perl \ |
| 48 | + pkg-config \ |
| 49 | + tar \ |
| 50 | + unzip \ |
| 51 | + wget \ |
| 52 | + xz-utils \ |
| 53 | + zip \ |
| 54 | + && rm -rf /var/lib/apt/lists/* |
| 55 | + |
| 56 | +# dpkg's amd64/arm64 spelling matches go.dev's; cmake.org spells the arch x86_64/aarch64. |
| 57 | +RUN ARCH=$(dpkg --print-architecture) && case $ARCH in amd64) CM=x86_64;; arm64) CM=aarch64;; esac \ |
| 58 | + && wget -q https://go.dev/dl/go$GO_VERSION.linux-$ARCH.tar.gz \ |
| 59 | + && tar -C /opt -xzf go$GO_VERSION.linux-$ARCH.tar.gz && rm go$GO_VERSION.linux-$ARCH.tar.gz \ |
| 60 | + && wget -q https://github.com/Kitware/CMake/releases/download/v$CMAKE_VERSION/cmake-$CMAKE_VERSION-linux-$CM.tar.gz \ |
| 61 | + && tar -C /opt -xzf cmake-$CMAKE_VERSION-linux-$CM.tar.gz && rm cmake-$CMAKE_VERSION-linux-$CM.tar.gz \ |
| 62 | + && ln -s /opt/cmake-$CMAKE_VERSION-linux-$CM /opt/cmake \ |
| 63 | + && ln -s /usr/lib/jvm/java-21-openjdk-$ARCH /usr/lib/jvm/java-21 |
| 64 | +# The compose services run `bash -cl`, and Debian's /etc/profile resets PATH for login shells, |
| 65 | +# so ENV PATH alone is not enough: root's ~/.profile sources ~/.bashrc, which restores it. |
| 66 | +ENV PATH /opt/go/bin:/opt/cmake/bin:$PATH |
| 67 | +RUN echo 'export PATH=/opt/go/bin:/opt/cmake/bin:$PATH' >> ~/.bashrc |
| 68 | +ENV JAVA_HOME /usr/lib/jvm/java-21 |
| 69 | +RUN go version && clang-17 --version | head -1 && ninja --version && cmake --version | head -1 |
| 70 | + |
| 71 | +# /code is a bind mount owned by the host user; newer git refuses to touch it otherwise. |
| 72 | +RUN git config --global --add safe.directory '*' |
0 commit comments