From c8a3b422f9cda3efaad0d7b18878f87667851065 Mon Sep 17 00:00:00 2001 From: David Haukeness Date: Mon, 23 Mar 2020 21:38:34 +0000 Subject: [PATCH] add support for docker swarm secrets paperkey --- Dockerfile | 6 ++++-- provision.sh | 6 ++++++ 2 files changed, 10 insertions(+), 2 deletions(-) create mode 100644 provision.sh diff --git a/Dockerfile b/Dockerfile index e48cd00..c2ba882 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,9 +5,11 @@ COPY . . RUN go get -d -v RUN go build -o app . -FROM keybaseio/client:latest +FROM keybaseio/client:stable-slim WORKDIR /home/keybase COPY --from=builder /go/src/app/app . +COPY --from=builder /go/src/app/provision.sh . ENV KEYBASE_SERVICE=1 -CMD ["./app"] +RUN chmod +x provision.sh +CMD ["./provision.sh"] diff --git a/provision.sh b/provision.sh new file mode 100644 index 0000000..d408c16 --- /dev/null +++ b/provision.sh @@ -0,0 +1,6 @@ +#!/usr/bin/env bash +keybase --no-auto-fork \ + oneshot \ + -u $KEYBASE_USERNAME \ + --paperkey "$(cat /run/secrets/$KEYBASE_USERNAME-paperkey)" +./app \ No newline at end of file