diff --git a/compose.local.yaml b/compose.local.yaml index f4e342e..04719b1 100644 --- a/compose.local.yaml +++ b/compose.local.yaml @@ -99,7 +99,11 @@ services: restart: on-failure storage-init: - image: ${MINIO_IMAGE:-quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z} + build: + context: . + dockerfile: local/Dockerfile.storage-init + args: + MINIO_IMAGE: ${MINIO_IMAGE:-quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z} entrypoint: [/bin/sh, /init.sh] environment: MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local} @@ -107,19 +111,19 @@ services: S3_APP_USER: ${S3_APP_USER:-dtf_app} S3_APP_PASSWORD: ${S3_APP_PASSWORD:-local-app-storage-only} S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork} - volumes: - - ./local/storage-init.sh:/init.sh:ro - - ./local/storage-policy.json:/policy.json:ro - - ./local/storage-lifecycle.json:/lifecycle.json:ro networks: [local] depends_on: storage: {condition: service_healthy} restart: on-failure scanner: - image: clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 + # Built, not bind-mounted: see local/Dockerfile.scanner. + build: + context: . + dockerfile: local/Dockerfile.scanner + args: + CLAMAV_IMAGE: ${CLAMAV_IMAGE:-clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4} entrypoint: [clamd, --foreground=true, --config-file=/etc/clamav/clamd.conf] - volumes: [./local/clamd.conf:/etc/clamav/clamd.conf:ro] networks: [local] security_opt: [no-new-privileges:true] healthcheck: diff --git a/local/Dockerfile.scanner b/local/Dockerfile.scanner new file mode 100644 index 0000000..cddcf42 --- /dev/null +++ b/local/Dockerfile.scanner @@ -0,0 +1,7 @@ +# The scanner configuration is baked in rather than bind-mounted. +# A containerised CI runner shares the host's Docker daemon, so a host path from +# the runner's workspace does not exist where the daemon creates the mount: it +# makes an empty directory instead and the container fails to start. +ARG CLAMAV_IMAGE=clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 +FROM ${CLAMAV_IMAGE} +COPY local/clamd.conf /etc/clamav/clamd.conf diff --git a/local/Dockerfile.storage-init b/local/Dockerfile.storage-init new file mode 100644 index 0000000..d6e492e --- /dev/null +++ b/local/Dockerfile.storage-init @@ -0,0 +1,6 @@ +# Provisioning script and policies baked in, for the same reason as the scanner. +ARG MINIO_IMAGE=quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z +FROM ${MINIO_IMAGE} +COPY local/storage-init.sh /init.sh +COPY local/storage-policy.json /policy.json +COPY local/storage-lifecycle.json /lifecycle.json