Files
notifier/Dockerfile
T
igodwin 298c960808 Fix 8 high-severity audit findings across security, Go, API, and container domains
- Use typed context key for auth context to prevent collisions (auth.go)
- Eliminate nested locking in CheckRateLimit to prevent potential deadlock (auth.go)
- Add 1MB request body size limit middleware to prevent DoS (router.go)
- Return proper gRPC status codes instead of nil errors on failures (handler.go)
- Use key name instead of raw API key in admin URL paths to prevent secret leakage (keys.go, router.go, keystore_db.go, keystore_hybrid.go)
- Enforce RBAC authorization in service Send/SendBatch for both REST and gRPC (service.go)
- Pin runtime Docker image to alpine:3.21 for reproducible builds (Dockerfile)
- Enable readOnlyRootFilesystem with /tmp emptyDir in k8s deployment (deployment.yaml)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-26 20:17:51 -07:00

69 lines
1.6 KiB
Docker

# Build stage
FROM golang:1.24-alpine AS builder
# Build arguments
ARG VERSION=dev
ARG GIT_COMMIT=unknown
ARG BUILD_TIME=unknown
ARG BUILD_FLAGS="-s -w"
# Install build dependencies including protoc
RUN apk add --no-cache git make protobuf protobuf-dev
# Set working directory
WORKDIR /build
# Copy go mod files
COPY go.mod go.sum ./
# Download dependencies
RUN go mod download
# Install protoc plugins
RUN go install google.golang.org/protobuf/cmd/protoc-gen-go@latest && \
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
# Copy source code
COPY . .
# Generate protobuf code
RUN make proto-gen
# Build binary with version information
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo \
-ldflags "-X main.Version=${VERSION} -X main.GitCommit=${GIT_COMMIT} -X main.BuildTime=${BUILD_TIME} ${BUILD_FLAGS}" \
-o server ./cmd/server
# Runtime stage
FROM alpine:3.21
# Install runtime dependencies
RUN apk --no-cache add ca-certificates tzdata
# Create non-root user
RUN addgroup -g 1000 notifier && \
adduser -D -u 1000 -G notifier notifier
# Set working directory
WORKDIR /app
# Copy binary from builder
COPY --from=builder /build/server /app/
# Copy default config (can be overridden with volume mount)
COPY config.yaml /app/config.yaml
# Create directory for queue persistence
RUN mkdir -p /var/lib/notifier && \
chown -R notifier:notifier /var/lib/notifier
# Change to non-root user
USER notifier
# Expose ports
EXPOSE 8080 50051 9090 8081
# Run server (defaults to both REST and gRPC)
# Override mode with environment variable: -e SERVER_MODE=rest or -e SERVER_MODE=grpc
CMD ["/app/server"]