Skip to content

Commit

Permalink
add full container
Browse files Browse the repository at this point in the history
Signed-off-by: Sylvain Hellegouarch <[email protected]>
  • Loading branch information
Lawouach committed Nov 21, 2023
1 parent 944e75e commit d65028a
Show file tree
Hide file tree
Showing 7 changed files with 3,709 additions and 0 deletions.
37 changes: 37 additions & 0 deletions .github/workflows/cli-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -63,11 +63,48 @@ jobs:
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

build-full-container:
name: Build full containers with extensions
runs-on: ubuntu-22.04
needs:
- publish-wheels
steps:
- uses: actions/checkout@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- name: Login to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: meta for the container image
id: meta
uses: docker/metadata-action@v4
with:
flavor: |
prefix=
images: |
ghcr.io/reliablyhq/cli/full
tags: |
type=sha,prefix=,format=long
type=raw,value=latest
- name: Build and push Container
uses: docker/build-push-action@v4
with:
context: ./container
push: ${{ github.event_name != 'pull_request' }}
platforms: linux/amd64
file: ./Dockerfile
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

release:
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
needs:
- build-container
- build-full-container
steps:
- name: Build Changelog
id: github_release
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,12 @@

* Import into starter library your own extensions for easily building new
experiments
* Also build a container image with most major Chaos Toolkit extensions, ready
to be used by Reliably plans

### Changed

* Bump dependencies

## [0.24.0][]

Expand Down
162 changes: 162 additions & 0 deletions container/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,162 @@
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class

# C extensions
*.so

# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST

# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec

# Installer logs
pip-log.txt
pip-delete-this-directory.txt

# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
cover/

# Translations
*.mo
*.pot

# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal

# Flask stuff:
instance/
.webassets-cache

# Scrapy stuff:
.scrapy

# Sphinx documentation
docs/_build/

# PyBuilder
.pybuilder/
target/

# Jupyter Notebook
.ipynb_checkpoints

# IPython
profile_default/
ipython_config.py

# pyenv
# For a library or package, you might want to ignore these files since the code is
# intended to run in multiple environments; otherwise, check them in:
# .python-version

# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock

# poetry
# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control.
# This is especially recommended for binary packages to ensure reproducibility, and is more
# commonly ignored for libraries.
# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control
#poetry.lock

# pdm
# Similar to Pipfile.lock, it is generally recommended to include pdm.lock in version control.
#pdm.lock
# pdm stores project-wide configurations in .pdm.toml, but it is recommended to not include it
# in version control.
# https://pdm-project.org/#use-with-ide
.pdm.toml
.pdm-python
.pdm-build/

# PEP 582; used by e.g. github.com/David-OConnor/pyflow and github.com/pdm-project/pdm
__pypackages__/

# Celery stuff
celerybeat-schedule
celerybeat.pid

# SageMath parsed files
*.sage.py

# Environments
.env
.venv
env/
venv/
ENV/
env.bak/
venv.bak/

# Spyder project settings
.spyderproject
.spyproject

# Rope project settings
.ropeproject

# mkdocs documentation
/site

# mypy
.mypy_cache/
.dmypy.json
dmypy.json

# Pyre type checker
.pyre/

# pytype static type analyzer
.pytype/

# Cython debug symbols
cython_debug/

# PyCharm
# JetBrains specific template is maintained in a separate JetBrains.gitignore that can
# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore
# and can be added to the global gitignore or merged into this file. For a more nuclear
# option (not recommended) you can uncomment the following to ignore the entire idea folder.
#.idea/
51 changes: 51 additions & 0 deletions container/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
FROM ubuntu:23.10 AS build-venv

ARG DEBIAN_FRONTEND=noninteractive

RUN groupadd -g 1001 svc && useradd -r -u 1001 -g svc svc

COPY pyproject.toml pdm.lock /home/svc/
RUN apt-get update && \
apt-get install -y python3.11 python3-pip python3.11-venv curl && \
apt-get install -y --no-install-recommends build-essential gcc && \
curl -sSL https://raw.githubusercontent.com/pdm-project/pdm/main/install-pdm.py | python3.11 - && \
export PATH="$PATH:/root/.local/bin" && \
pdm self update && \
cd /home/svc/ && \
pdm venv create && \
pdm use .venv && \
pdm install -v --no-editable --no-self && \
chown --recursive svc:svc /home/svc/.venv && \
apt-get remove -y build-essential gcc && \
apt-get clean && rm -rf /var/lib/apt/lists/*

FROM ubuntu:23.10

LABEL org.opencontainers.image.authors="Reliably <[email protected]>"
LABEL org.opencontainers.image.vendor="Reliably"
LABEL org.opencontainers.image.url="https://reliably.com"
LABEL org.opencontainers.image.licenses="Apache-2.0"

RUN apt-get update && apt-get install -y curl python3.11 python3-distutils && \
groupadd -g 1001 svc && useradd -m -u 1001 -g svc svc && \
curl -Lo aws-iam-authenticator https://github.com/kubernetes-sigs/aws-iam-authenticator/releases/download/v0.6.11/aws-iam-authenticator_0.6.11_linux_amd64 && \
chmod +x ./aws-iam-authenticator && \
chown svc:svc ./aws-iam-authenticator && \
mv ./aws-iam-authenticator /home/svc/aws-iam-authenticator && \
apt-get remove -y curl && \
apt-get remove --auto-remove -y golang-go && \
apt-get clean && \
rm -rf /var/lib/apt/lists/*

COPY --from=build-venv --chown=svc:svc /home/svc/.venv /home/svc/.venv
WORKDIR /home/svc
COPY --chown=svc:svc settings.yaml /home/svc/.chaostoolkit/settings.yaml
USER 1001

RUN mkdir -p /home/svc/bin && \
mv ./aws-iam-authenticator /home/svc/bin/aws-iam-authenticator

ENV PATH="$PATH:/home/svc/bin:/home/svc/.venv/bin"

ENTRYPOINT ["/home/svc/.venv/bin/reliably"]
CMD ["--help"]
1 change: 1 addition & 0 deletions container/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
# reliably-cli-container
Loading

0 comments on commit d65028a

Please sign in to comment.