action-hsm-sign/Dockerfile

24 lines
799 B
Docker

FROM docker:28.3.1-dind-alpine3.22
# Cannot use a rootless container due to permissions errors writing to the
# workspace
# This is an alpine-based image
# The HSM's power is switched through the kernel's sysfs port interface (see
# entrypoint.sh), so uhubctl is not needed
RUN true && \
apk add --no-cache curl && \
apkArch="$(arch)" && \
if [ $apkArch = "x86_64" ]; then apkArch=amd64; fi && \
curl -sLO https://github.com/sigstore/rekor/releases/download/v1.0.1/rekor-cli-linux-${apkArch} && \
mv rekor-cli-linux-${apkArch} /usr/bin/rekor && \
chmod 755 /usr/bin/rekor && \
true
COPY entrypoint.sh /
# The signer's build context, built on the host daemon at run time so its
# layers are cached there between runs
COPY signer /signer
ENTRYPOINT ["/entrypoint.sh"]