coder / coder/envbuilder

feature: Allow appending an arbitrary validation command to the built image

オープン
#383 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Go
スター
300
フォーク
64
平均マージ
20分
マージ済み PR(30日)
1

説明

# Motivation

Some image building workflows involve a final `RUN` command that serves to in some way validate the built image before pushing it to a remote registry ([example](https://docs.docker.com/build/ci/github-actions/test-before-push/)).

For example, we may want to run a security scan of the image for CVEs using e.g. [trivy](https://github.com/aquasecurity/trivy), or perform a final confidence check on the image using e.g. [goss](https://github.com/goss-org/goss).

With Envbuilder, the built image is only available inside the running `envbuilder` container, so it can't be scanned easily by external processes.

# Solution

Allow appending an arbitrary RUN command to the Dockerfile produced by Envbuilder. An example of such a command could be:

```shell
RUN curl -fsSL -o /tmp/validate.sh https://host.internal/validate.sh && \
chmod +x /tmp/validate.sh && \
/tmp/validate.sh && \
rm -f /tmp/validate.sh
```

# Alternatives

The above behaviour can be approximated with no code changes with the below:

- Append a RUN command to the Dockerfile containing the specific check(s) they wish to run, or
- Add the required validation steps to `devcontainer.json` as e.g. `postCreateCommand`, or
- Create a specific devcontainer feature that runs the desired validation commands.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

issue にはファイルやテストが記載されていないため、まず Envbuilder の Dockerfile 生成エントリポイントと、既存の設定または CLI オプションを見つけます。生成されたイメージがどのようにビルドされるかを追跡し、その後、指定された検証コマンドがイメージの push 前に最後の RUN ステップになることを、生成された Dockerfile のリグレッションカバレッジで検証します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
docker, go
領域
build-system, devops
issue の種類
機能追加
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。