This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit f209a1dce63b9a7d9face6c08912153fb6b8f06a Author: Sandor Molnar <[email protected]> AuthorDate: Mon May 25 21:11:44 2026 +0200 KNOX-3256: Refactor Docker build to use local Maven artifacts and unify CI/Dev workflows (#1239) --- .dockerignore | 32 ++++++++++++++++++++++++++++ .github/workflows/build/Dockerfile | 2 +- .github/workflows/compose/docker-compose.yml | 6 +++--- .github/workflows/tests.yml | 6 +++--- 4 files changed, 39 insertions(+), 7 deletions(-) diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 000000000..45964f0d9 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,32 @@ +########################################################################## +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +########################################################################## + +# Ignore all files by default to reduce build context size and protect secrets. +* + +# Allow the target directory and its subdirectories for the required artifacts. +!target/ +!target/*/ +!target/*/knox-*.tar.gz +!target/*/knoxshell-*.tar.gz + +# Allow the build workflow configurations and scripts. +!.github/ +!.github/workflows/ +!.github/workflows/build/ +!.github/workflows/build/** diff --git a/.github/workflows/build/Dockerfile b/.github/workflows/build/Dockerfile index b3f04ea25..c06db8cf4 100644 --- a/.github/workflows/build/Dockerfile +++ b/.github/workflows/build/Dockerfile @@ -36,7 +36,7 @@ RUN tar -xvzf /tmp/knox-artifacts/knox-*.tar.gz -C /tmp/knox-artifacts/ && \ mv /tmp/knoxshell-artifacts/knoxshell-*/* /knox-runtime/knoxshell/ && \ rm -rf /tmp/knox-artifacts /tmp/knoxshell-artifacts -# Configuration and scripts +# Master secret, configuration and topologies ADD .github/workflows/build/master /knox-runtime/data/security/master ADD .github/workflows/build/gateway-site.xml /knox-runtime/conf/gateway-site.xml ADD .github/workflows/build/conf/topologies/knoxtoken.xml /knox-runtime/conf/topologies/knoxtoken.xml diff --git a/.github/workflows/compose/docker-compose.yml b/.github/workflows/compose/docker-compose.yml index fc5e075d3..e03e90e5a 100644 --- a/.github/workflows/compose/docker-compose.yml +++ b/.github/workflows/compose/docker-compose.yml @@ -18,16 +18,16 @@ services: build: context: ../../../ dockerfile: .github/workflows/build/Dockerfile - image: apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local} + image: apache/knox-dev:${IMAGE_TAG:-master} ldap: - image: apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local} + image: apache/knox-dev:${IMAGE_TAG:-master} command: /ldap.sh depends_on: - knox-dev knox: - image: apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local} + image: apache/knox-dev:${IMAGE_TAG:-master} command: /gateway.sh volumes: # - ./topologies:/knox-runtime/conf/topologies diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index e26268627..ff353a246 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -116,7 +116,7 @@ jobs: if: always() run: | docker compose -f ./.github/workflows/compose/docker-compose.yml down --volumes - IMAGE_TAG="local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local}" - if docker image inspect "apache/knox-dev:$IMAGE_TAG" >/dev/null 2>&1; then - docker rmi "apache/knox-dev:$IMAGE_TAG" + TAG=${IMAGE_TAG:-master} + if docker image inspect "apache/knox-dev:$TAG" >/dev/null 2>&1; then + docker rmi "apache/knox-dev:$TAG" fi
