# syntax=docker/dockerfile:1 # # Multi-stage build: xcaddy compiles Caddy with the Coraza WAF plugin and the # OWASP Core Rule Set embedded at build time, then the final image is a minimal # debian:bookworm-slim layer that ships only the compiled binary. # # Rebuild whenever the ARG versions below change; Ansible will detect the # Dockerfile checksum change and re-run `podman build`. FROM golang:1.26-trixie AS builder ARG XCADDY_VERSION=v0.3.5 ARG CADDY_VERSION=v2.11.2 ARG CORAZA_CADDY_VERSION=v2.5.0 ARG CORAZA_CRS_VERSION=v4.7.0 RUN go install "github.com/caddyserver/xcaddy/cmd/xcaddy@${XCADDY_VERSION}" RUN xcaddy build "${CADDY_VERSION}" \ --with "github.com/corazawaf/coraza-caddy/v2@${CORAZA_CADDY_VERSION}" \ --with "github.com/corazawaf/coraza-coreruleset@${CORAZA_CRS_VERSION}" # ── Runtime image ────────────────────────────────────────────────────────────── FROM debian:trixie-slim RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates \ && rm -rf /var/lib/apt/lists/* COPY --from=builder /go/caddy /usr/bin/caddy RUN groupadd --system --gid 1000 caddy \ && useradd --system --uid 1000 --gid caddy --no-create-home caddy EXPOSE 80 3100 3200 4317 4318 8080 ENTRYPOINT ["/usr/bin/caddy"] CMD ["run", "--config", "/etc/caddy/Caddyfile", "--adapter", "caddyfile"]