Skip to content

Commit ebc82f6

Browse files
fix(docker): add writable /tmp to the scratch-based image (#1105)
Kosli's temp-dir usage (directory fingerprinting, evidence tarballing) relies on os.MkdirTemp, which fails when /tmp doesn't exist at all, as is the case in the scratch base image. Stage an empty dir in the builder stage and copy it into the final image as a world-writable /tmp. Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
1 parent 61b5742 commit ebc82f6

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

‎Dockerfile‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,12 @@ COPY . .
1717

1818
RUN make build
1919

20+
RUN mkdir -p /image-tmp
21+
2022
### Final Image ###
2123
FROM scratch
2224

2325
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
2426
COPY --from=builder /go/src/kosli/kosli /bin/kosli
27+
COPY --from=builder --chmod=1777 /image-tmp /tmp
2528
ENTRYPOINT ["/bin/kosli"]

0 commit comments

Comments
 (0)