- Dockerfile: openssh-client 换成 openssh-server - 新增 sshd-hardening.conf: 仅公钥认证,禁密码/转发 - 新增 authorized_keys: 授权公钥 - 构建期生成 host key,保证镜像内指纹稳定 - entrypoint.sh: exec opencode 前拉起 sshd,幂等且失败不阻断主服务 - compose: 发布 3333:22
114 lines
2.9 KiB
Docker
114 lines
2.9 KiB
Docker
FROM ubuntu:24.04
|
||
|
||
ENV DEBIAN_FRONTEND=noninteractive
|
||
|
||
SHELL ["/bin/bash", "-c"]
|
||
|
||
RUN rm -rf /etc/apt/sources.list.d/* \
|
||
&& echo "deb http://192.168.1.12:8081/repository/apt-ubuntu-proxy/ noble main restricted universe multiverse" > /etc/apt/sources.list \
|
||
&& echo "deb http://192.168.1.12:8081/repository/apt-ubuntu-proxy/ noble-updates main restricted universe multiverse" >> /etc/apt/sources.list \
|
||
&& echo "deb http://192.168.1.12:8081/repository/apt-ubuntu-proxy/ noble-security main restricted universe multiverse" >> /etc/apt/sources.list
|
||
|
||
RUN apt-get update && apt-get install -y \
|
||
curl \
|
||
wget \
|
||
git \
|
||
git-lfs \
|
||
unzip \
|
||
zip \
|
||
jq \
|
||
vim \
|
||
nano \
|
||
less \
|
||
tree \
|
||
htop \
|
||
procps \
|
||
sudo \
|
||
ca-certificates \
|
||
software-properties-common \
|
||
gnupg \
|
||
lsb-release \
|
||
openssh-server \
|
||
rsync \
|
||
tar \
|
||
xz-utils \
|
||
locales \
|
||
tzdata \
|
||
build-essential \
|
||
bash-completion \
|
||
python3 \
|
||
python3-pip \
|
||
python3-venv \
|
||
python-is-python3 \
|
||
maven \
|
||
gradle \
|
||
openjdk-21-jdk \
|
||
docker.io \
|
||
docker-compose-v2 \
|
||
&& rm -rf /var/lib/apt/lists/*
|
||
|
||
# 使用官方安装脚本安装 uv(放入 ~/.cargo/bin)
|
||
RUN curl -LsSf https://astral.sh/uv/install.sh | sh
|
||
# 将 uv 所在目录加入 PATH
|
||
ENV PATH="/root/.cargo/bin:${PATH}"
|
||
|
||
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - && \
|
||
apt-get update && \
|
||
apt-get install -y nodejs && \
|
||
rm -rf /var/lib/apt/lists/*
|
||
|
||
RUN npm config set registry http://192.168.1.12:8081/repository/npm-public/
|
||
RUN ONNXRUNTIME_NODE_INSTALL=skip npm install -g \
|
||
pnpm \
|
||
yarn \
|
||
opencode-ai@latest \
|
||
bun \
|
||
gitnexus@rc
|
||
RUN pnpm config set registry http://192.168.1.12:8081/repository/npm-public/
|
||
RUN yarn config set registry http://192.168.1.12:8081/repository/npm-public/
|
||
|
||
RUN mkdir -p /root/.pip
|
||
RUN printf "[global]\nindex-url=http://192.168.1.12:8081/repository/pypi-public\ntrusted-host=nexus\n" \
|
||
> /root/.pip/pip.conf
|
||
|
||
RUN opencode --version
|
||
RUN bun --version
|
||
|
||
ENV JAVA_HOME=/usr/lib/jvm/java-21-openjdk-amd64
|
||
|
||
ENV PATH=$JAVA_HOME/bin:$PATH
|
||
|
||
RUN mkdir -p \
|
||
/workspace \
|
||
/opt/android-sdk \
|
||
/root/.m2 \
|
||
/root/.gradle
|
||
|
||
COPY settings.xml /root/.m2/settings.xml
|
||
|
||
# ---------- SSH 服务端 ----------
|
||
# 加固配置:仅公钥认证,关闭密码与各类转发
|
||
COPY sshd-hardening.conf /etc/ssh/sshd_config.d/99-hardening.conf
|
||
|
||
# 授权公钥(公钥非机密,可安全入镜像;轮换需重建镜像)
|
||
COPY authorized_keys /root/.ssh/authorized_keys
|
||
|
||
# 构建期生成 host key,保证同一镜像内主机指纹稳定
|
||
RUN chmod 700 /root/.ssh && chmod 600 /root/.ssh/authorized_keys \
|
||
&& ssh-keygen -A \
|
||
&& mkdir -p /run/sshd
|
||
|
||
EXPOSE 3004
|
||
|
||
EXPOSE 3005
|
||
|
||
EXPOSE 22
|
||
|
||
RUN ln -fs /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && \
|
||
dpkg-reconfigure -f noninteractive tzdata
|
||
|
||
COPY entrypoint.sh /
|
||
|
||
RUN chmod +x /entrypoint.sh
|
||
|
||
ENTRYPOINT ["/entrypoint.sh"] |