Files
OpenShell/deploy/docker/Dockerfile.supervisor
John T. Myers 0fd3385726 fix(container): use distroless Debian 13 for supervisor (#3393)
* fix(container): use distroless Debian 13 for supervisor

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(docker): preserve supervisor bootstrap ownership

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-17 05:29:47 +00:00

18 lines
753 B
Docker

# syntax=docker/dockerfile:1.4
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# The dynamically linked GNU supervisor binary is staged under
# deploy/docker/.build/prebuilt-binaries/<arch>/.
# Keep the GNU runtime and CA roots without a shell or unused native TLS libraries.
# The default variant preserves UID 0 and /; compute drivers set the runtime UID.
FROM gcr.io/distroless/base-nossl-debian13@sha256:af5cb8dd589b8520b8c06bebb9efb73d7e16406cab58e85c51761fff49d370a0 AS supervisor
ARG TARGETARCH
COPY --chmod=0555 deploy/docker/.build/prebuilt-binaries/${TARGETARCH}/openshell-supervisor /openshell-supervisor
ENTRYPOINT ["/openshell-supervisor"]