coder / coder/envbuilder

feature: Allow appending an arbitrary validation command to the built image

Open
#383 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
300
Forks
64
Avg merge
20m
Merged PRs (30d)
1

Description

# Motivation

Some image building workflows involve a final `RUN` command that serves to in some way validate the built image before pushing it to a remote registry ([example](https://docs.docker.com/build/ci/github-actions/test-before-push/)).

For example, we may want to run a security scan of the image for CVEs using e.g. [trivy](https://github.com/aquasecurity/trivy), or perform a final confidence check on the image using e.g. [goss](https://github.com/goss-org/goss).

With Envbuilder, the built image is only available inside the running `envbuilder` container, so it can't be scanned easily by external processes.

# Solution

Allow appending an arbitrary RUN command to the Dockerfile produced by Envbuilder. An example of such a command could be:

```shell
RUN curl -fsSL -o /tmp/validate.sh https://host.internal/validate.sh && \
chmod +x /tmp/validate.sh && \
/tmp/validate.sh && \
rm -f /tmp/validate.sh
```

# Alternatives

The above behaviour can be approximated with no code changes with the below:

- Append a RUN command to the Dockerfile containing the specific check(s) they wish to run, or
- Add the required validation steps to `devcontainer.json` as e.g. `postCreateCommand`, or
- Create a specific devcontainer feature that runs the desired validation commands.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.