-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathDockerfile.native
More file actions
120 lines (84 loc) · 3.29 KB
/
Dockerfile.native
File metadata and controls
120 lines (84 loc) · 3.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
ARG OS=
ARG AWS_LC_VERSION=
ARG AWS_LC_SHA256=
ARG PCRE2_VERSION=
ARG PCRE2_SHA256=
ARG HAPROXY_MAJOR=
ARG HAPROXY_VERSION=
ARG HAPROXY_SHA256=
ARG LUA_VERSION=
ARG LUA_MD5=
### Builder -- adds common utils needed for all build images
FROM $OS as builder
RUN apt-get update && \
apt-get install --no-install-recommends -y gcc g++ make file libc6-dev perl libtext-template-perl libreadline-dev curl ca-certificates libcrypt-dev \
cmake ninja-build golang
### AWS-LC
FROM builder as awslc
ARG AWS_LC_VERSION
ARG AWS_LC_SHA256
RUN curl -OJL https://github.com/aws/aws-lc/archive/refs/tags/${AWS_LC_VERSION}.tar.gz && \
echo ${AWS_LC_SHA256} aws-lc-${AWS_LC_VERSION#v}.tar.gz | sha256sum -c && \
tar zxvf aws-lc-${AWS_LC_VERSION#v}.tar.gz && \
cd aws-lc-${AWS_LC_VERSION#v} && \
cmake -GNinja -DCMAKE_BUILD_TYPE=Release -DBUILD_TESTING=ON -DBUILD_SHARED_LIBS=OFF \
-DCMAKE_INSTALL_PREFIX=/tmp/awslc \
. && \
ninja && \
ninja run_tests && \
ninja install
### PCRE2
FROM builder as pcre2
ARG PCRE2_VERSION
ARG PCRE2_SHA256
RUN curl -OJL "https://github.com/PhilipHazel/pcre2/releases/download/pcre2-${PCRE2_VERSION}/pcre2-${PCRE2_VERSION}.tar.gz" && \
echo ${PCRE2_SHA256} pcre2-${PCRE2_VERSION}.tar.gz | sha256sum -c && \
tar zxvf pcre2-${PCRE2_VERSION}.tar.gz && \
cd pcre2-${PCRE2_VERSION} && \
LDFLAGS="-fPIE -pie -Wl,-z,relro -Wl,-z,now" \
CFLAGS="-pthread -g -O2 -fPIE -fstack-protector-strong -Wformat -Werror=format-security -Wall -fvisibility=hidden" \
./configure --prefix=/tmp/pcre2 --disable-shared --enable-utf8 --enable-jit --enable-unicode-properties --disable-cpp && \
make check && \
make install
# Lua
FROM builder as lua
ARG LUA_VERSION
ARG LUA_MD5
RUN curl -OJL "http://www.lua.org/ftp/lua-${LUA_VERSION}.tar.gz" && \
echo "${LUA_MD5} lua-${LUA_VERSION}.tar.gz" | md5sum -c && \
tar zxf lua-${LUA_VERSION}.tar.gz && \
cd lua-${LUA_VERSION} && \
make linux && \
make install INSTALL_TOP=/tmp/lua
### HAProxy
FROM builder as haproxy
COPY --from=awslc /tmp/awslc /tmp/awslc
COPY --from=pcre2 /tmp/pcre2 /tmp/pcre2
COPY --from=lua /tmp/lua/bin /usr/local/bin
COPY --from=lua /tmp/lua/include /usr/local/include
COPY --from=lua /tmp/lua/lib /usr/local/lib
ARG HAPROXY_MAJOR
ARG HAPROXY_VERSION
ARG HAPROXY_SHA256
RUN curl -OJL "http://www.haproxy.org/download/${HAPROXY_MAJOR}/src/haproxy-${HAPROXY_VERSION}.tar.gz" && \
echo "${HAPROXY_SHA256} haproxy-${HAPROXY_VERSION}.tar.gz" | sha256sum -c && \
tar zxvf haproxy-${HAPROXY_VERSION}.tar.gz && \
make -C haproxy-${HAPROXY_VERSION} \
TARGET=linux-glibc \
USE_SLZ=1 \
USE_STATIC_PCRE2=1 USE_PCRE2_JIT=1 PCRE2DIR=/tmp/pcre2 \
USE_OPENSSL=1 SSL_INC=/tmp/awslc/include SSL_LIB=/tmp/awslc/lib \
USE_LUA=1 \
USE_PROMEX=1 \
DESTDIR=/tmp/haproxy PREFIX= \
all \
install-bin && \
mkdir -p /tmp/haproxy/etc/haproxy && \
cp -R haproxy-${HAPROXY_VERSION}/examples/errorfiles /tmp/haproxy/etc/haproxy/errors
### HAProxy runtime image
FROM $OS as runtime
RUN apt-get update && \
apt-get install --no-install-recommends -y curl ca-certificates
COPY --from=haproxy /tmp/haproxy /usr/local/
RUN rm -rf /var/lib/apt/lists/*
CMD ["haproxy", "-f", "/usr/local/etc/haproxy/haproxy.cfg"]