mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-25 08:00:59 +00:00
aeee148723
Add podman + crun + uidmap + fuse-overlayfs + slirp4netns and a windmill user (uid 1000) with a subuid/subgid range to DockerfileFull and DockerfileFullEe, so the `container_runtime: podman` worker-group option works out of the box on the *-full images. Run the docker worker group as `user: "1000:1000"` for a rootless (unprivileged) daemon; root still works but is rootful. Base/slim images are untouched (kept lean). Verified on debian:bookworm-slim: packages resolve (podman 4.3.1), user + subuid set up, ~103MB layer delta (rounding error on the multi-GB full image). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
58 lines
2.6 KiB
Plaintext
58 lines
2.6 KiB
Plaintext
FROM ghcr.io/windmill-labs/windmill:dev
|
|
|
|
# Rust
|
|
COPY --from=rust:1.93.0 /usr/local/cargo /usr/local/cargo
|
|
COPY --from=rust:1.93.0 /usr/local/rustup /usr/local/rustup
|
|
RUN RUSTUP_HOME=/usr/local/rustup CARGO_HOME=/usr/local/cargo /usr/local/cargo/bin/cargo install cargo-sweep --version ^0.7
|
|
|
|
# Ansible
|
|
RUN uv tool install ansible && [ -d "$(uv tool dir)/ansible/bin/" ] && find "$(uv tool dir)/ansible/bin/" -mindepth 1 -maxdepth 1 -type f -executable -regextype posix-extended -regex '^((.+/)?)[^.]+' -print0 | xargs -0 ln -s -t "$UV_TOOL_BIN_DIR/" || true
|
|
|
|
# C#
|
|
RUN wget https://dot.net/v1/dotnet-install.sh -O dotnet-install.sh \
|
|
&& chmod +x dotnet-install.sh \
|
|
&& ./dotnet-install.sh --channel 9.0 --install-dir /usr/share/dotnet \
|
|
&& ln -s /usr/share/dotnet/dotnet /usr/bin/dotnet \
|
|
&& rm dotnet-install.sh
|
|
# Nushell
|
|
COPY --from=ghcr.io/nushell/nushell:0.101.0-bookworm /usr/bin/nu /usr/bin/nu
|
|
|
|
# Java
|
|
RUN apt-get -y update && apt-get install -y default-jdk
|
|
RUN curl -fLo coursier https://github.com/coursier/coursier/releases/download/v2.1.24/coursier \
|
|
&& mv ./coursier /usr/bin/coursier \
|
|
&& chmod +x /usr/bin/coursier
|
|
RUN /usr/bin/java -jar /usr/bin/coursier about
|
|
|
|
# Ruby
|
|
RUN apt-get install -y ruby ruby-bundler
|
|
|
|
# R
|
|
RUN apt-get install -y r-base-dev \
|
|
&& Rscript -e 'install.packages("renv", lib="/usr/lib/R/library", repos="https://cloud.r-project.org")'
|
|
|
|
# Rootless container runtime (podman) for docker-mode jobs. Set the
|
|
# `container_runtime: podman` worker-group option to run `# docker` scripts
|
|
# without a privileged dind sidecar or the host Docker socket. Run the docker
|
|
# worker group as `user: "1000:1000"` for a rootless (unprivileged) daemon;
|
|
# running as root still works but is rootful (less isolated).
|
|
RUN apt-get -y update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
podman \
|
|
uidmap \
|
|
fuse-overlayfs \
|
|
slirp4netns \
|
|
crun \
|
|
&& apt-get clean \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
RUN useradd -u 1000 -m -s /bin/bash windmill 2>/dev/null || true
|
|
# Ensure a subuid/subgid range exists for rootless podman (useradd usually adds
|
|
# one already; only append if it didn't, to avoid a duplicate range).
|
|
RUN grep -q '^windmill:' /etc/subuid || echo "windmill:100000:65536" >> /etc/subuid; \
|
|
grep -q '^windmill:' /etc/subgid || echo "windmill:100000:65536" >> /etc/subgid
|
|
|
|
# Fix UV cache permissions for non-root user support (uid 1000, etc.)
|
|
# The uv tool install ansible command populates the UV cache with root-owned files
|
|
RUN chmod -R a+rw /tmp/windmill/cache/uv && \
|
|
find /tmp/windmill/cache/uv -type d -exec chmod 777 {} +
|