1
0
Fork 0

Refactor Dockerfile for multi-stage build and runtime optimization

- Implemented a two-stage Dockerfile: build environment with Python dependencies and lean runtime stage with HAProxy.
- Added custom entrypoint script for dynamic Docker group adjustment.
- Improved HAProxy command generation by introducing a static method for binary resolution.
- Updated tests and functional logic to dynamically resolve the `haproxy` binary path.
- Adjusted file permissions in E2E key generation script for better security.
- Streamlined `.gitignore` by removing unnecessary exclusions.
This commit is contained in:
Joao Gilberto Magalhaes 2026-02-18 01:53:27 -05:00
parent bfd38adea5
commit 44cb3dd5e0
7 changed files with 65 additions and 77 deletions

13
build/entrypoint.sh Normal file
View file

@ -0,0 +1,13 @@
#!/bin/sh
set -e
## When docker.sock is mounted its GID comes from the host and is unknown at
## build time. Detect it at startup and add the haproxy user to that group so
## Docker/Swarm discovery works without running the whole process as root.
#if [ -S /var/run/docker.sock ]; then
# SOCK_GID=$(stat -c '%g' /var/run/docker.sock)
# getent group "$SOCK_GID" >/dev/null 2>&1 || addgroup -g "$SOCK_GID" dockersock
# addgroup haproxy "$(getent group "$SOCK_GID" | cut -d: -f1)" 2>/dev/null || true
#fi
exec /scripts/.venv/bin/easy-haproxy "$@"