This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git

commit f209a1dce63b9a7d9face6c08912153fb6b8f06a
Author: Sandor Molnar <[email protected]>
AuthorDate: Mon May 25 21:11:44 2026 +0200

    KNOX-3256: Refactor Docker build to use local Maven artifacts and unify 
CI/Dev workflows (#1239)
---
 .dockerignore                                | 32 ++++++++++++++++++++++++++++
 .github/workflows/build/Dockerfile           |  2 +-
 .github/workflows/compose/docker-compose.yml |  6 +++---
 .github/workflows/tests.yml                  |  6 +++---
 4 files changed, 39 insertions(+), 7 deletions(-)

diff --git a/.dockerignore b/.dockerignore
new file mode 100644
index 000000000..45964f0d9
--- /dev/null
+++ b/.dockerignore
@@ -0,0 +1,32 @@
+##########################################################################
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+##########################################################################
+
+# Ignore all files by default to reduce build context size and protect secrets.
+*
+
+# Allow the target directory and its subdirectories for the required artifacts.
+!target/
+!target/*/
+!target/*/knox-*.tar.gz
+!target/*/knoxshell-*.tar.gz
+
+# Allow the build workflow configurations and scripts.
+!.github/
+!.github/workflows/
+!.github/workflows/build/
+!.github/workflows/build/**
diff --git a/.github/workflows/build/Dockerfile 
b/.github/workflows/build/Dockerfile
index b3f04ea25..c06db8cf4 100644
--- a/.github/workflows/build/Dockerfile
+++ b/.github/workflows/build/Dockerfile
@@ -36,7 +36,7 @@ RUN tar -xvzf /tmp/knox-artifacts/knox-*.tar.gz -C 
/tmp/knox-artifacts/ && \
     mv /tmp/knoxshell-artifacts/knoxshell-*/* /knox-runtime/knoxshell/ && \
     rm -rf /tmp/knox-artifacts /tmp/knoxshell-artifacts
 
-# Configuration and scripts
+# Master secret, configuration and topologies
 ADD .github/workflows/build/master /knox-runtime/data/security/master
 ADD .github/workflows/build/gateway-site.xml 
/knox-runtime/conf/gateway-site.xml
 ADD .github/workflows/build/conf/topologies/knoxtoken.xml 
/knox-runtime/conf/topologies/knoxtoken.xml
diff --git a/.github/workflows/compose/docker-compose.yml 
b/.github/workflows/compose/docker-compose.yml
index fc5e075d3..e03e90e5a 100644
--- a/.github/workflows/compose/docker-compose.yml
+++ b/.github/workflows/compose/docker-compose.yml
@@ -18,16 +18,16 @@ services:
     build:
       context: ../../../
       dockerfile: .github/workflows/build/Dockerfile
-    image: 
apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local}
+    image: apache/knox-dev:${IMAGE_TAG:-master}
 
   ldap:
-    image: 
apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local}
+    image: apache/knox-dev:${IMAGE_TAG:-master}
     command: /ldap.sh
     depends_on:
       - knox-dev
 
   knox:
-    image: 
apache/knox-dev:local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local}
+    image: apache/knox-dev:${IMAGE_TAG:-master}
     command: /gateway.sh
     volumes:
 #      - ./topologies:/knox-runtime/conf/topologies
diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml
index e26268627..ff353a246 100644
--- a/.github/workflows/tests.yml
+++ b/.github/workflows/tests.yml
@@ -116,7 +116,7 @@ jobs:
         if: always()
         run: |
           docker compose -f ./.github/workflows/compose/docker-compose.yml 
down --volumes
-          IMAGE_TAG="local-${GITHUB_RUN_ID:-local}-${GITHUB_RUN_ID:-local}"
-          if docker image inspect "apache/knox-dev:$IMAGE_TAG" >/dev/null 
2>&1; then
-            docker rmi "apache/knox-dev:$IMAGE_TAG"
+          TAG=${IMAGE_TAG:-master}
+          if docker image inspect "apache/knox-dev:$TAG" >/dev/null 2>&1; then
+            docker rmi "apache/knox-dev:$TAG"
           fi

Reply via email to