-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
66 lines (52 loc) · 2.88 KB
/
Copy pathDockerfile
File metadata and controls
66 lines (52 loc) · 2.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
# syntax=docker/dockerfile:1
# ── Build ────────────────────────────────────────────────────────────────────
FROM golang:1.24-alpine AS build
WORKDIR /src
# Dependencies first, so a source-only change does not re-download the module
# cache on every build.
COPY go.mod go.sum ./
RUN go mod download
COPY . .
ARG VERSION=docker
ARG COMMIT=unknown
ARG DATE=unknown
# CGO off keeps the binary static, so it runs on a base image with no libc of
# the builder's vintage. -trimpath keeps build paths out of the binary.
RUN CGO_ENABLED=0 go build \
-trimpath \
-ldflags "-s -w -X main.version=${VERSION} -X main.commit=${COMMIT} -X main.date=${DATE}" \
-o /out/netdiag .
# ── Capabilities ─────────────────────────────────────────────────────────────
# setcap has to run somewhere with libcap, and the final image should not carry
# a package manager just to install it. Do it in its own stage and copy the
# binary with its file capabilities intact.
FROM alpine:3.21 AS setcap
RUN apk add --no-cache libcap
COPY --from=build /out/netdiag /out/netdiag
# cap_net_raw is what ping, trace, discover and `scan --fast` need. Granting it
# to the binary means the container does not have to run as root, and the
# capability cannot leak to anything else in the image.
RUN setcap cap_net_raw+ep /out/netdiag
# ── Runtime ──────────────────────────────────────────────────────────────────
# Alpine rather than distroless: file capabilities need a filesystem that
# preserves extended attributes through COPY, and having a shell in the image
# is worth more than the few MB for a tool people will want to exec into.
FROM alpine:3.21
# ca-certificates for the HTTPS commands (http, speedtest); the rest of netdiag
# speaks raw TCP, UDP and ICMP and needs nothing else.
RUN apk add --no-cache ca-certificates \
&& adduser -D -H -u 10001 netdiag
COPY --from=setcap /out/netdiag /usr/local/bin/netdiag
# Unprivileged. The binary carries exactly the one capability it needs, so
# there is no reason for the process to be root.
#
# Note for hardened deployments: `--cap-drop=ALL` alone will not start this
# image. Linux refuses to exec a file with permitted capabilities the process
# could never be granted, so dropping cap_net_raw produces an exec error rather
# than a netdiag that falls back to unprivileged scanning. Drop everything and
# add back the one capability instead:
#
# docker run --rm --cap-drop=ALL --cap-add=NET_RAW netdiag scan host --fast
USER netdiag
ENTRYPOINT ["/usr/local/bin/netdiag"]
CMD ["--help"]