forked from external-secrets/external-secrets
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.standalone
More file actions
21 lines (18 loc) · 969 Bytes
/
Copy pathDockerfile.standalone
File metadata and controls
21 lines (18 loc) · 969 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
# This version of Dockerfile is for building without external dependencies.
# Build a multi-platform image e.g. `docker buildx build --push --platform linux/arm64,linux/amd64 --tag external-secrets:dev --file Dockerfile.standalone .`
FROM golang:1.26.3-alpine@sha256:91eda9776261207ea25fd06b5b7fed8d397dd2c0a283e77f2ab6e91bfa71079d AS builder
# Add metadata
LABEL maintainer="cncf-externalsecretsop-maintainers@lists.cncf.io" \
description="External Secrets Operator is a Kubernetes operator that integrates external secret management systems"
ARG TARGETOS
ARG TARGETARCH
ENV CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH}
WORKDIR /app
COPY . /app/
RUN go mod download
RUN go build -o external-secrets main.go
FROM gcr.io/distroless/static@sha256:3592aa8171c77482f62bbc4164e6a2d141c6122554ace66e5cc910cadb961ff0 AS app
COPY --from=builder /app/external-secrets /bin/external-secrets
# Run as UID for nobody
USER 65534
ENTRYPOINT ["/bin/external-secrets"]