Skip to content

Commit 785fbb4

Browse files
committed
build: use official Musl builds for x64 and fallback otherwise
1 parent 8db05b4 commit 785fbb4

2 files changed

Lines changed: 44 additions & 54 deletions

File tree

‎Dockerfile-alpine.template‎

Lines changed: 22 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -5,43 +5,48 @@ ENV NODE_VERSION=0.0.0
55
RUN addgroup -g 1000 node \
66
&& adduser -u 1000 -G node -s /bin/sh -D node \
77
&& apk add --no-cache \
8+
libatomic \
89
libstdc++ \
910
&& apk add --no-cache --virtual .build-deps \
11+
gnupg \
1012
curl \
1113
&& ARCH= OPENSSL_ARCH='linux*' && alpineArch="$(apk --print-arch)" \
1214
&& case "${alpineArch##*-}" in \
1315
"${ALPINE_ARCH[@]}"
1416
esac \
15-
&& if [ -n "${CHECKSUM}" ]; then \
16-
set -eu; \
17-
curl -fsSLO --compressed "https://unofficial-builds.nodejs.org/download/release/v$NODE_VERSION/node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz"; \
18-
echo "$CHECKSUM node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" | sha256sum -c - \
19-
&& tar -xJf "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" -C /usr/local --strip-components=1 --no-same-owner \
20-
&& ln -s /usr/local/bin/node /usr/local/bin/nodejs; \
17+
# use pre-existing gpg directory, see https://github.com/nodejs/docker-node/pull/1895#issuecomment-1550389150
18+
&& export GNUPGHOME="$(mktemp -d)" \
19+
# gpg keys listed at https://github.com/nodejs/node#release-keys
20+
&& set -ex \
21+
&& for key in \
22+
"${NODE_KEYS[@]}"
23+
; do \
24+
{ gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || \
25+
{ gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; \
26+
done \
27+
&& if [ "$ARCH" = "x64" ]; then \
28+
curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" \
29+
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/SHASUMS256.txt.asc" \
30+
&& gpg --batch --decrypt --output SHASUMS256.txt SHASUMS256.txt.asc \
31+
&& gpgconf --kill all \
32+
&& rm -rf "$GNUPGHOME" \
33+
&& grep " node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz\$" SHASUMS256.txt | sha256sum -c - \
34+
&& tar -xJf "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" -C /usr/local --strip-components=1 --no-same-owner \
35+
&& rm "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" SHASUMS256.txt.asc SHASUMS256.txt \
36+
&& ln -s /usr/local/bin/node /usr/local/bin/nodejs; \
2137
else \
2238
echo "Building from source" \
23-
# backup build
2439
&& apk add --no-cache --virtual .build-deps-full \
2540
binutils-gold \
2641
g++ \
2742
gcc \
28-
gnupg \
2943
libgcc \
3044
linux-headers \
3145
make \
3246
python3 \
3347
py-setuptools \
3448
rust \
3549
cargo \
36-
# use pre-existing gpg directory, see https://github.com/nodejs/docker-node/pull/1895#issuecomment-1550389150
37-
&& export GNUPGHOME="$(mktemp -d)" \
38-
# gpg keys listed at https://github.com/nodejs/node#release-keys
39-
&& for key in \
40-
"${NODE_KEYS[@]}"
41-
; do \
42-
{ gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || \
43-
{ gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; \
44-
done \
4550
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION.tar.xz" \
4651
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/SHASUMS256.txt.asc" \
4752
&& gpg --batch --decrypt --output SHASUMS256.txt SHASUMS256.txt.asc \
@@ -58,7 +63,6 @@ RUN addgroup -g 1000 node \
5863
&& rm -Rf "node-v$NODE_VERSION" \
5964
&& rm "node-v$NODE_VERSION.tar.xz" SHASUMS256.txt.asc SHASUMS256.txt; \
6065
fi \
61-
&& rm -f "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" \
6266
# Remove unused OpenSSL headers to save ~34MB. See this NodeJS issue: https://github.com/nodejs/node/issues/46451
6367
&& find /usr/local/include/node/openssl/archs -mindepth 1 -maxdepth 1 ! -name "$OPENSSL_ARCH" -exec rm -rf {} \; \
6468
&& apk del .build-deps \

‎update.sh‎

Lines changed: 22 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,9 @@ function usage() {
2525
EOF
2626
}
2727

28-
SKIP_ALPINE=false
2928
while getopts "sh" opt; do
3029
case "${opt}" in
3130
s)
32-
SKIP_ALPINE=true
3331
shift
3432
;;
3533
h)
@@ -145,41 +143,29 @@ function update_node_version() {
145143

146144
if is_alpine "${variant}"; then
147145
alpine_version="${variant#*alpine}"
148-
checksum=$(
149-
curl -sSL --compressed "https://unofficial-builds.nodejs.org/download/release/v${nodeVersion}/SHASUMS256.txt" | grep "node-v${nodeVersion}-linux-x64-musl.tar.xz" | cut -d' ' -f1
150-
)
151-
if [ -z "$checksum" ]; then
152-
rm -f "${dockerfile}-tmp"
153-
if [ "${SKIP_ALPINE}" = true ]; then
154-
echo "${nodeVersion} is missing the musl build for ${variant}, but skipping for security release!"
155-
else
156-
fatal "Failed to fetch checksum for musl build version ${nodeVersion}"
157-
fi
158-
else
159-
sed -Ei -e "s/(alpine:)0.0/\\1${alpine_version}/" "${dockerfile}-tmp"
160-
161-
alpine_arch=''
162-
local -a arches
163-
arches=$(jq -r ".\"${version}\".variants.\"alpine${alpine_version}\" | @sh" "versions.json")
164-
if [[ "${arches[0]}" == *"amd64"* ]]; then
165-
alpine_arch+='x86_64) ARCH='"'"'x64'"'"' CHECKSUM="'${checksum}'" OPENSSL_ARCH=linux-x86_64;; \\\n '
166-
fi
167-
if [[ "${arches[0]}" == *"arm64v8"* ]]; then
168-
alpine_arch+='aarch64) OPENSSL_ARCH=linux-aarch64;; \\\n '
169-
fi
170-
if [[ "${arches[0]}" == *"arm32"* ]]; then
171-
alpine_arch+='arm*) OPENSSL_ARCH=linux-armv4;; \\\n '
172-
fi
173-
if [[ "${arches[0]}" == *"ppc64le"* ]]; then
174-
alpine_arch+='ppc64le) OPENSSL_ARCH=linux-ppc64le;; \\\n '
175-
fi
176-
if [[ "${arches[0]}" == *"s390x"* ]]; then
177-
alpine_arch+='s390x) OPENSSL_ARCH=linux-s390x;; \\\n '
178-
fi
179-
# shellcheck disable=SC1003
180-
alpine_arch+='*) echo "unsupported architecture"; exit 1 ;; \\'
181-
sed -Ei -e "s/\"\\$\{ALPINE_ARCH\[@\]\}\"/${alpine_arch}/" "${dockerfile}-tmp"
146+
sed -Ei -e "s/(alpine:)0.0/\\1${alpine_version}/" "${dockerfile}-tmp"
147+
148+
alpine_arch=''
149+
local -a arches
150+
arches=$(jq -r ".\"${version}\".variants.\"alpine${alpine_version}\" | @sh" "versions.json")
151+
if [[ "${arches[0]}" == *"amd64"* ]]; then
152+
alpine_arch+='x86_64) ARCH='"'"'x64'"'"' OPENSSL_ARCH=linux-x86_64;; \\\n '
153+
fi
154+
if [[ "${arches[0]}" == *"arm64v8"* ]]; then
155+
alpine_arch+='aarch64) OPENSSL_ARCH=linux-aarch64;; \\\n '
156+
fi
157+
if [[ "${arches[0]}" == *"arm32"* ]]; then
158+
alpine_arch+='arm*) OPENSSL_ARCH=linux-armv4;; \\\n '
182159
fi
160+
if [[ "${arches[0]}" == *"ppc64le"* ]]; then
161+
alpine_arch+='ppc64le) OPENSSL_ARCH=linux-ppc64le;; \\\n '
162+
fi
163+
if [[ "${arches[0]}" == *"s390x"* ]]; then
164+
alpine_arch+='s390x) OPENSSL_ARCH=linux-s390x;; \\\n '
165+
fi
166+
# shellcheck disable=SC1003
167+
alpine_arch+='*) echo "unsupported architecture"; exit 1 ;; \\'
168+
sed -Ei -e "s/\"\\$\{ALPINE_ARCH\[@\]\}\"/${alpine_arch}/" "${dockerfile}-tmp"
183169
elif is_debian "${variant}"; then
184170
sed -Ei -e "s/(buildpack-deps:)name/\\1${variant}/" "${dockerfile}-tmp"
185171
deb_arch=''

0 commit comments

Comments
 (0)