Files
2026-05-10 22:05:12 -05:00

39 lines
1.4 KiB
Docker

# syntax=docker/dockerfile:1
#
# Multi-stage build: xcaddy compiles Caddy with the Coraza WAF plugin and the
# OWASP Core Rule Set embedded at build time, then the final image is a minimal
# debian:bookworm-slim layer that ships only the compiled binary.
#
# Rebuild whenever the ARG versions below change; Ansible will detect the
# Dockerfile checksum change and re-run `podman build`.
FROM golang:1.26-trixie AS builder
ARG XCADDY_VERSION=v0.3.5
ARG CADDY_VERSION=v2.11.2
ARG CORAZA_CADDY_VERSION=v2.5.0
ARG CORAZA_CRS_VERSION=v4.7.0
RUN go install "github.com/caddyserver/xcaddy/cmd/xcaddy@${XCADDY_VERSION}"
RUN xcaddy build "${CADDY_VERSION}" \
--with "github.com/corazawaf/coraza-caddy/v2@${CORAZA_CADDY_VERSION}" \
--with "github.com/corazawaf/coraza-coreruleset@${CORAZA_CRS_VERSION}"
# ── Runtime image ──────────────────────────────────────────────────────────────
FROM debian:trixie-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates \
&& rm -rf /var/lib/apt/lists/*
COPY --from=builder /go/caddy /usr/bin/caddy
RUN groupadd --system --gid 1000 caddy \
&& useradd --system --uid 1000 --gid caddy --no-create-home caddy
EXPOSE 80 3100 3200 4317 4318 8080
ENTRYPOINT ["/usr/bin/caddy"]
CMD ["run", "--config", "/etc/caddy/Caddyfile", "--adapter", "caddyfile"]