Compare commits

..
1 Commits
Author SHA1 Message Date
freudenreichan 1a0fcbbd12 .drone.yml aktualisiert 2026-04-11 11:45:33 +00:00
2 changed files with 14 additions and 30 deletions
+1 -1
View File
@@ -26,7 +26,7 @@ steps:
fi fi
- name: security-scan - name: security-scan
image: aquasec/trivy:latest image: ghcr.io/aquasecurity/trivy:0.69.3
commands: commands:
- trivy image --input image.tar --severity HIGH,CRITICAL --exit-code 1 - trivy image --input image.tar --severity HIGH,CRITICAL --exit-code 1
+13 -29
View File
@@ -1,38 +1,22 @@
# Base-Image - Alpine statt Ubuntu # Base-Image
FROM alpine:latest AS build FROM ubuntu:latest
# Build-Tools installieren # Pakete installieren
RUN apk add --no-cache gcc musl-dev RUN apt-get update
RUN apt-get install -y build-essential gcc curl vim net-tools
# Arbeitsverzeichnis setzen # Arbeitsverzeichnis setzen
WORKDIR /app WORKDIR /app
# Code kopieren und kompilieren # alles kopieren
COPY deployment.c . COPY . .
# Code kompilieren
RUN gcc -o deployment deployment.c RUN gcc -o deployment deployment.c
# Finales schlankes Image # Verzeichnis für Ausgabe anlegen
FROM alpine:latest RUN mkdir /output
# Nicht als root laufen # Ausgabe wird ins Container-Dateisystem geschrieben
RUN adduser -D appuser ENTRYPOINT ["/bin/bash", "-c"]
WORKDIR /app
# Nur das Binary kopieren
COPY --from=build /app/deployment .
# Ausgabeverzeichnis anlegen und Rechte setzen
RUN mkdir /output && chown appuser /output
# Volume für Ausgabe
VOLUME /output
# User wechseln
USER appuser
# Healthcheck
HEALTHCHECK --interval=30s --timeout=5s CMD pgrep deployment || exit 1
ENTRYPOINT ["/bin/sh", "-c"]
CMD ["./deployment 10 > /output/output.txt && tail -f /output/output.txt"] CMD ["./deployment 10 > /output/output.txt && tail -f /output/output.txt"]