From 040e5e850c5069a5375e0ba28ed59179b1638a8d Mon Sep 17 00:00:00 2001 From: katelyn martin Date: Thu, 4 Dec 2025 00:00:00 +0000 Subject: [PATCH] refactor(Dockerfile): use `ghcr.io/linkerd/proxy` base image see linkerd/linkerd-proxy#4333 for previous context. this commit makes changes to the Dockerfile provided in this repository, for use in the proxy's development process. rather than using `debian:bookworm-slim` as the base image, this commit helps deduplicate the tricky business of setting networking capabilities on executables needed when running as an init container. this has one negative consequence, which is that we can no longer attach to a `bash` shell in a running pod when using this image. this is unfortunate, but in my experience isn't often needed by proxy developers. i believe that, should we need to revisit the need for a shell in this image, we should do instead make use of the `Dockerfile-debug` image provided in the linkerd2 repo. if we ran a command like `just docker --build-arg LINKERD2_IMAGE='ghcr.io/linkerd/debug:edge-25-11.3'` we could specify the debug image as a base image instead, providing developers not only with a shell, but also other helpful utilities like `curl`, `tcpdump`, and so on. unfortunately, this does not work today, because the image appears to no longer be published, and has drifted from our latest edge release. i have not pulled on that string further at the time of writing. one explicit _benefit_ of the changes in this commit is that we bring proxy development closer to the real world, meaning that CI in this repository runs using the same image that the proxy will run inside of in the linkerd2 repository and in typical clusters. --- * linkerd/linkerd2#14348 * linkerd/linkerd2#14577 * linkerd/linkerd-proxy#4333 Signed-off-by: katelyn martin --- Dockerfile | 20 ++------------------ 1 file changed, 2 insertions(+), 18 deletions(-) diff --git a/Dockerfile b/Dockerfile index a8242c3bc7..a12aa2942b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,8 +9,6 @@ ARG RUST_IMAGE=ghcr.io/linkerd/dev:v48-rust # identity-initializing and linkerd-await wrappers. ARG LINKERD2_IMAGE=ghcr.io/linkerd/proxy:edge-25.11.3 -FROM $LINKERD2_IMAGE as linkerd2 - FROM --platform=$BUILDPLATFORM $RUST_IMAGE as fetch ARG PROXY_FEATURES="" @@ -49,21 +47,7 @@ RUN --mount=type=cache,id=cargo,target=/usr/local/cargo/registry \ mv $(just --evaluate profile="$PROFILE" _target_bin) /out/ ; \ du -sh /out/* ) -# Install the proxy binary into a base image that we can at least get a shell -# for debugging. -FROM docker.io/library/debian:bookworm-slim as runtime - -RUN apt-get update && \ - apt-get install -y iptables libcap2-bin && \ - rm -rf /var/lib/apt/lists/* - -WORKDIR /linkerd -COPY --from=linkerd2 /usr/lib/linkerd/* /usr/lib/linkerd/ +# Install the proxy binary into the proxy image. +FROM $LINKERD2_IMAGE as linkerd2 COPY --from=build /out/* /usr/lib/linkerd/ - -USER root -RUN ["/usr/sbin/setcap", "cap_net_raw,cap_net_admin+eip", "/usr/sbin/xtables-legacy-multi"] -RUN ["/usr/sbin/setcap", "cap_net_raw,cap_net_admin+eip", "/usr/sbin/xtables-nft-multi"] -RUN ["/usr/sbin/setcap", "cap_net_raw,cap_net_admin+eip", "/usr/lib/linkerd/linkerd2-proxy-init"] - ENTRYPOINT ["/usr/lib/linkerd/linkerd2-proxy-identity"]