Skip to content
Snippets Groups Projects
Commit 3560bbbb authored by Will Medlar's avatar Will Medlar
Browse files

Allow kube-bench to be run inside its distribution container

parent 67786fd3
No related branches found
No related tags found
No related merge requests found
FROM golang:1.9 FROM golang:1.9 AS build
WORKDIR /kube-bench WORKDIR /go/src/github.com/aquasecurity/kube-bench/
RUN go get github.com/aquasecurity/kube-bench ADD glide.lock glide.yaml ./
RUN go get github.com/Masterminds/glide && glide install
ADD main.go .
ADD check/ check/
ADD cmd/ cmd/
RUN CGO_ENABLED=0 go install -a -ldflags '-w'
FROM alpine:latest FROM alpine:latest AS run
WORKDIR / WORKDIR /opt/kube-bench/
COPY --from=0 /go/bin/kube-bench /kube-bench # add GNU ps for -C, -o cmd, and --no-headers support
COPY --from=0 /go/src/github.com/aquasecurity/kube-bench/cfg /cfg # https://github.com/aquasecurity/kube-bench/issues/109
COPY --from=0 /go/src/github.com/aquasecurity/kube-bench/entrypoint.sh /entrypoint.sh RUN apk --no-cache add procps
ENTRYPOINT /entrypoint.sh COPY --from=build /go/bin/kube-bench /usr/local/bin/kube-bench
ADD entrypoint.sh .
ADD cfg/ cfg/
ENTRYPOINT ["./entrypoint.sh"]
# Build-time metadata as defined at http://label-schema.org # Build-time metadata as defined at http://label-schema.org
ARG BUILD_DATE ARG BUILD_DATE
......
hooks/build 100644 → 100755
File mode changed from 100644 to 100755
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment