From 6a50e6db4dabce341a21c8218cb673adc37046a0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Mon, 21 Sep 2026 12:51:08 -0300 Subject: [PATCH] fix: bake scanner and storage config into images instead of bind-mounting The integration job failed starting the scanner: error mounting ".../local/clamd.conf" to rootfs at "/etc/clamav/clamd.conf": not a directory The files are in the repository, so this was not a missing checkout. A containerised CI runner shares the host's Docker daemon, so "./local/clamd.conf" resolves to a workspace path that exists inside the runner but not on the host where the daemon creates the mount. The daemon makes an empty directory there and the container cannot start. Only the bind-mounting services were affected, which is why PostgreSQL and MinIO came up first. Build the scanner and storage-init images with their configuration copied in, so compose.local.yaml no longer bind-mounts anything from the host and works regardless of how the runner reaches the daemon. Both bases stay overridable through CLAMAV_IMAGE and MINIO_IMAGE. The production stack is unaffected: it ships clamd.conf as a Swarm config, which the manager reads at deploy time. Verified from a clean slate: the stack starts, the scanner runs the baked configuration, storage provisioning runs from the baked script, and the full suite passes. Co-Authored-By: Claude Opus 5 --- compose.local.yaml | 18 +++++++++++------- local/Dockerfile.scanner | 7 +++++++ local/Dockerfile.storage-init | 6 ++++++ 3 files changed, 24 insertions(+), 7 deletions(-) create mode 100644 local/Dockerfile.scanner create mode 100644 local/Dockerfile.storage-init diff --git a/compose.local.yaml b/compose.local.yaml index f4e342e..04719b1 100644 --- a/compose.local.yaml +++ b/compose.local.yaml @@ -99,7 +99,11 @@ services: restart: on-failure storage-init: - image: ${MINIO_IMAGE:-quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z} + build: + context: . + dockerfile: local/Dockerfile.storage-init + args: + MINIO_IMAGE: ${MINIO_IMAGE:-quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z} entrypoint: [/bin/sh, /init.sh] environment: MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local} @@ -107,19 +111,19 @@ services: S3_APP_USER: ${S3_APP_USER:-dtf_app} S3_APP_PASSWORD: ${S3_APP_PASSWORD:-local-app-storage-only} S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork} - volumes: - - ./local/storage-init.sh:/init.sh:ro - - ./local/storage-policy.json:/policy.json:ro - - ./local/storage-lifecycle.json:/lifecycle.json:ro networks: [local] depends_on: storage: {condition: service_healthy} restart: on-failure scanner: - image: clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 + # Built, not bind-mounted: see local/Dockerfile.scanner. + build: + context: . + dockerfile: local/Dockerfile.scanner + args: + CLAMAV_IMAGE: ${CLAMAV_IMAGE:-clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4} entrypoint: [clamd, --foreground=true, --config-file=/etc/clamav/clamd.conf] - volumes: [./local/clamd.conf:/etc/clamav/clamd.conf:ro] networks: [local] security_opt: [no-new-privileges:true] healthcheck: diff --git a/local/Dockerfile.scanner b/local/Dockerfile.scanner new file mode 100644 index 0000000..cddcf42 --- /dev/null +++ b/local/Dockerfile.scanner @@ -0,0 +1,7 @@ +# The scanner configuration is baked in rather than bind-mounted. +# A containerised CI runner shares the host's Docker daemon, so a host path from +# the runner's workspace does not exist where the daemon creates the mount: it +# makes an empty directory instead and the container fails to start. +ARG CLAMAV_IMAGE=clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 +FROM ${CLAMAV_IMAGE} +COPY local/clamd.conf /etc/clamav/clamd.conf diff --git a/local/Dockerfile.storage-init b/local/Dockerfile.storage-init new file mode 100644 index 0000000..d6e492e --- /dev/null +++ b/local/Dockerfile.storage-init @@ -0,0 +1,6 @@ +# Provisioning script and policies baked in, for the same reason as the scanner. +ARG MINIO_IMAGE=quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z +FROM ${MINIO_IMAGE} +COPY local/storage-init.sh /init.sh +COPY local/storage-policy.json /policy.json +COPY local/storage-lifecycle.json /lifecycle.json