diff --git a/Dockerfile b/Dockerfile index f3a1837238e..e84d4d956bb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,15 +1,15 @@ # use a builder image for building cloudflare ARG TARGET_GOOS ARG TARGET_GOARCH -FROM golang:1.26.8 AS builder +FROM golang:1.27.1 AS builder ENV GO111MODULE=on \ - CGO_ENABLED=0 \ - GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ - TARGET_GOOS=${TARGET_GOOS} \ - TARGET_GOARCH=${TARGET_GOARCH} \ - # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual - # which changes how cloudflared binds the metrics server - CONTAINER_BUILD=1 + CGO_ENABLED=0 \ + GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ + TARGET_GOOS=${TARGET_GOOS} \ + TARGET_GOARCH=${TARGET_GOARCH} \ + # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual + # which changes how cloudflared binds the metrics server + CONTAINER_BUILD=1 WORKDIR /go/src/github.com/cloudflare/cloudflared/ @@ -23,13 +23,22 @@ COPY . . # compile cloudflared RUN make cloudflared -# use a distroless base image with glibc -FROM gcr.io/distroless/base-debian13:nonroot@sha256:0896741ba5bafd3ac87ea025a5f578952f2d238ddc3614cb368acc983a687aa2 +FROM alpine:3.24 LABEL org.opencontainers.image.source="https://github.com/cloudflare/cloudflared" +RUN apk add --no-cache ca-certificates && \ + addgroup -g 65532 nonroot && \ + adduser -D -H -u 65532 -G nonroot nonroot + # copy our compiled binary -COPY --from=builder --chown=nonroot /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ +COPY --from=builder --chown=65532:65532 /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ + +# Healthcheck +ENV TUNNEL_METRICS=0.0.0.0:2000 + +HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \ + CMD ["cloudflared", "tunnel", "--metrics", "127.0.0.1:2000", "ready"] # run as nonroot user # We need to use numeric user id's because Kubernetes doesn't support strings: diff --git a/Dockerfile.amd64 b/Dockerfile.amd64 index 812e7b6778e..3d01cebd62e 100644 --- a/Dockerfile.amd64 +++ b/Dockerfile.amd64 @@ -1,11 +1,11 @@ # use a builder image for building cloudflare -FROM golang:1.26.8 AS builder +FROM golang:1.27.1 AS builder ENV GO111MODULE=on \ - CGO_ENABLED=0 \ - GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ - # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual - # which changes how cloudflared binds the metrics server - CONTAINER_BUILD=1 + CGO_ENABLED=0 \ + GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ + # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual + # which changes how cloudflared binds the metrics server + CONTAINER_BUILD=1 WORKDIR /go/src/github.com/cloudflare/cloudflared/ @@ -18,13 +18,22 @@ COPY . . # compile cloudflared RUN GOOS=linux GOARCH=amd64 make cloudflared -# use a distroless base image with glibc -FROM gcr.io/distroless/base-debian13:nonroot-amd64@sha256:65795e700eda57743efe12537e031042bd7832a19cc23f772acf2057dc7566f1 +FROM alpine:3.24 LABEL org.opencontainers.image.source="https://github.com/cloudflare/cloudflared" +RUN apk add --no-cache ca-certificates && \ + addgroup -g 65532 nonroot && \ + adduser -D -H -u 65532 -G nonroot nonroot + # copy our compiled binary -COPY --from=builder --chown=nonroot /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ +COPY --from=builder --chown=65532:65532 /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ + +# Healthcheck +ENV TUNNEL_METRICS=0.0.0.0:2000 + +HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \ + CMD ["cloudflared", "tunnel", "--metrics", "127.0.0.1:2000", "ready"] # run as nonroot user # We need to use numeric user id's because Kubernetes doesn't support strings: diff --git a/Dockerfile.arm64 b/Dockerfile.arm64 index 9db8a45bcb6..c0fa57cb957 100644 --- a/Dockerfile.arm64 +++ b/Dockerfile.arm64 @@ -1,11 +1,11 @@ # use a builder image for building cloudflare -FROM golang:1.26.8 AS builder +FROM golang:1.27.1 AS builder ENV GO111MODULE=on \ - CGO_ENABLED=0 \ - GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ - # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual - # which changes how cloudflared binds the metrics server - CONTAINER_BUILD=1 + CGO_ENABLED=0 \ + GOPROXY=https://athens.cfdata.org|https://proxy.golang.org|direct \ + # the CONTAINER_BUILD envvar is used set github.com/cloudflare/cloudflared/metrics.Runtime=virtual + # which changes how cloudflared binds the metrics server + CONTAINER_BUILD=1 WORKDIR /go/src/github.com/cloudflare/cloudflared/ @@ -18,13 +18,22 @@ COPY . . # compile cloudflared RUN GOOS=linux GOARCH=arm64 make cloudflared -# use a distroless base image with glibc -FROM gcr.io/distroless/base-debian13:nonroot-arm64@sha256:7a4876f88e7fe3190972c274b679b3473f61e8d990a4dce3627961b3e22a0eaf +FROM alpine:3.24 LABEL org.opencontainers.image.source="https://github.com/cloudflare/cloudflared" +RUN apk add --no-cache ca-certificates && \ + addgroup -g 65532 nonroot && \ + adduser -D -H -u 65532 -G nonroot nonroot + # copy our compiled binary -COPY --from=builder --chown=nonroot /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ +COPY --from=builder --chown=65532:65532 /go/src/github.com/cloudflare/cloudflared/cloudflared /usr/local/bin/ + +# Healthcheck +ENV TUNNEL_METRICS=0.0.0.0:2000 + +HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \ + CMD ["cloudflared", "tunnel", "--metrics", "127.0.0.1:2000", "ready"] # run as nonroot user # We need to use numeric user id's because Kubernetes doesn't support strings: diff --git a/go.mod b/go.mod index 8c737df1cfb..1eeac7ae5ac 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/cloudflare/cloudflared -go 1.26 +go 1.26.0 require ( github.com/cloudflare/backoff v0.0.0-20240920015135-e46b80a3a7d0 @@ -36,7 +36,7 @@ require ( go.opentelemetry.io/proto/otlp v1.11.0 go.uber.org/automaxprocs v1.6.0 go.uber.org/mock v0.5.2 - golang.org/x/crypto v0.55.0 + golang.org/x/crypto v0.56.0 golang.org/x/net v0.58.0 golang.org/x/sync v0.22.0 golang.org/x/sys v0.47.0 diff --git a/go.sum b/go.sum index 32ae4c92aa7..8101c74ec18 100644 --- a/go.sum +++ b/go.sum @@ -237,8 +237,8 @@ golang.org/x/arch v0.4.0 h1:A8WCeEWhLwPBKNbFi5Wv5UTCBx5zzubnXDlMOFAzFMc= golang.org/x/arch v0.4.0/go.mod h1:5om86z9Hs0C8fWVUuoMHwpExlXzs5Tkyp9hOrfG7pp8= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/lint v0.0.0-20200302205851-738671d3881b/go.mod h1:3xt1FjdF8hUf6vQPIChWIBhFzV8gjjsPE/fR3IyQdNY= golang.org/x/mod v0.1.1-0.20191105210325-c90efee705ee/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=