Moving bitcoin to build role

This commit is contained in:
2024-02-09 19:11:46 -06:00
parent aa68070871
commit 6831ae2cbd
13 changed files with 111 additions and 0 deletions
-68
View File
@@ -1,68 +0,0 @@
#Based on Dockerflie from Kyle Manna - https://github.com/kylemanna/docker-bitcoind
FROM almalinux/9-minimal AS build
RUN microdnf update -y \
&& microdnf install -y \
ca-certificates \
gnupg2 \
libatomic \
wget \
tar \
gzip \
&& microdnf clean all && rm -fr /tmp/* /var/tmp/*
ARG VERSION=26.0
ARG BITCOIN_CORE_SIGNATURE=71A3B16735405025D447E8F274810B012346C9A6
ENV GOSU_VERSION 1.17
RUN cd /tmp \
&& gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys ${BITCOIN_CORE_SIGNATURE} \
&& wget https://bitcoincore.org/bin/bitcoin-core-${VERSION}/SHA256SUMS.asc \
https://bitcoincore.org/bin/bitcoin-core-${VERSION}/SHA256SUMS \
https://bitcoincore.org/bin/bitcoin-core-${VERSION}/bitcoin-${VERSION}-x86_64-linux-gnu.tar.gz \
&& gpg --verify --status-fd 1 --verify SHA256SUMS.asc SHA256SUMS 2>/dev/null | grep "^\[GNUPG:\] VALIDSIG.*${BITCOIN_CORE_SIGNATURE}\$" \
&& sha256sum --ignore-missing --check SHA256SUMS \
&& tar -xzvf bitcoin-${VERSION}-x86_64-linux-gnu.tar.gz -C /opt \
&& ln -sv bitcoin-${VERSION} /opt/bitcoin \
&& /opt/bitcoin/bin/test_bitcoin --show_progress \
&& rm -v /opt/bitcoin/bin/test_bitcoin /opt/bitcoin/bin/bitcoin-qt
RUN wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-amd64"; \
wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-amd64.asc"; \
\
# verify the signature
export GNUPGHOME="$(mktemp -d)"; \
gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4; \
gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu; \
gpgconf --kill all; \
rm -rf "$GNUPGHOME" /usr/local/bin/gosu.asc;
FROM almalinux/9-minimal
LABEL maintainer="b0xxer@b0xxy.net"
ENTRYPOINT ["entrypoint.sh"]
ENV HOME /bitcoin
EXPOSE 8332 8333
VOLUME ["/bitcoin/.bitcoin"]
WORKDIR /bitcoin
COPY --from=build /opt/ /opt/
COPY --from=build /usr/local/bin/gosu /usr/local/bin/
RUN microdnf update -y \
&& microdnf install -y libatomic shadow-utils \
&& microdnf clean all && rm -rf /tmp/* /var/tmp/* \
&& ln -sv /opt/bitcoin/bin/* /usr/local/bin
ARG GROUP_ID=1000
ARG USER_ID=1000
RUN groupadd -g ${GROUP_ID} bitcoin \
&& useradd -u ${USER_ID} -g bitcoin -d /bitcoin bitcoin
COPY ./bin ./entrypoint.sh /usr/local/bin/
RUN chmod +x /usr/local/bin/entrypoint.sh && chmod +x /usr/local/bin/gosu \
&& chmod +x /usr/local/bin/btc_oneshot && chmod +x /usr/local/bin/btc_init
CMD ["btc_oneshot"]
-25
View File
@@ -1,25 +0,0 @@
#!/bin/bash
set -ex
# This shouldn't be in the Dockerfile or containers built from the same image
# will have the same credentials.
if [ ! -e "$HOME/.bitcoin/bitcoin.conf" ]; then
mkdir -p $HOME/.bitcoin
echo "Creating bitcoin.conf"
# Seed a random password for JSON RPC server
cat <<EOF > $HOME/.bitcoin/bitcoin.conf
regtest=${REGTEST:-0}
disablewallet=${DISABLEWALLET:-1}
printtoconsole=${PRINTTOCONSOLE:-1}
rpcuser=${RPCUSER:-bitcoinrpc}
rpcpassword=${RPCPASSWORD:-`dd if=/dev/urandom bs=33 count=1 2>/dev/null | base64`}
EOF
fi
cat $HOME/.bitcoin/bitcoin.conf
echo "Initialization completed successfully"
-16
View File
@@ -1,16 +0,0 @@
#!/bin/sh
set -ex
# Generate bitcoin.conf
btc_init
# Default / no argument invocation listens for RPC commands and has to accept non-localhost because of
# Docker port proxying or Docker private networking.
if [ $# -eq 0 ]; then
# If IPv6 is in the container do both:
#set -- '-rpcbind=[::]:8332' '-rpcallowip=::/0' '-rpcallowip=0.0.0.0/0'
set -- '-rpcbind=:8332' '-rpcallowip=0.0.0.0/0'
fi
exec bitcoind "$@"
-18
View File
@@ -1,18 +0,0 @@
#!/bin/sh
set -e
# first arg is `-f` or `--some-option`
# or first arg is `something.conf`
if [ "${1#-}" != "$1" ] || [ "${1%.conf}" != "$1" ]; then
set -- btc_oneshot "$@"
fi
# Allow the container to be started with `--user`, if running as root drop privileges
if [ "$1" = 'btc_oneshot' -a "$(id -u)" = '0' ]; then
chown -R bitcoin .
exec gosu bitcoin "$0" "$@"
fi
# If not root (i.e. docker run --user $USER ...), then run as invoked
exec "$@"