Multi-stage Dockerfile: pin base image, add test/lint stages

Pin alpine:latest to the full patch-level tag alpine:3.22.1 so Renovate
can classify patch/minor/major bumps on it. Add a `test` stage (bats)
and a `lint` stage (shellcheck, severity=error) that build from `base`
before ENTRYPOINT is set, so CI can run them without an --entrypoint
override. A trailing `FROM base` keeps the lean prod image as the
default `docker build .` target despite the extra stages.
This commit is contained in:
Djeex
2026-08-22 23:50:40 +02:00
parent 59be656047
commit 56daf61290
+18 -2
View File
@@ -1,4 +1,4 @@
FROM alpine:latest FROM alpine:3.22.1 AS base
RUN apk add --no-cache socat netcat-openbsd \ RUN apk add --no-cache socat netcat-openbsd \
&& rm -rf /var/cache/apk/* /tmp/* && rm -rf /var/cache/apk/* /tmp/*
@@ -7,4 +7,20 @@ COPY entrypoint.sh VERSION /
RUN mkdir -p /socket \ RUN mkdir -p /socket \
&& chmod +x /entrypoint.sh && chmod +x /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"] FROM base AS test
RUN apk add --no-cache bats bash procps
WORKDIR /app
COPY entrypoint.sh VERSION /app/
COPY tests/ /app/tests/
FROM base AS lint
RUN apk add --no-cache shellcheck
RUN shellcheck --severity=error -s sh /entrypoint.sh
# Kept as the last stage so `docker build .` (no --target) still produces
# the lean prod image, not the `test`/`lint` stages above.
FROM base
ENTRYPOINT ["/entrypoint.sh"]