Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,23 @@ updates:
labels:
- "dependencies"
- "github-actions"
# actions/*, docker/* and github/codeql-action are pinned at the major tag
# on purpose, so minor/patch PRs against them only narrow the pin. Actions
# pinned exactly (hadolint, shellcheck, trivy, sbom-action) still get the
# full range of updates.
ignore:
- dependency-name: "actions/*"
update-types:
- "version-update:semver-minor"
- "version-update:semver-patch"
- dependency-name: "docker/*"
update-types:
- "version-update:semver-minor"
- "version-update:semver-patch"
- dependency-name: "github/codeql-action"
update-types:
- "version-update:semver-minor"
- "version-update:semver-patch"

- package-ecosystem: "docker"
directory: "/"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:
- uses: actions/checkout@v7

- name: Lint Containerfile with hadolint
uses: hadolint/hadolint-action@v3.3.0
uses: hadolint/hadolint-action@v3.4.0
with:
dockerfile: Containerfile

Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@
## [Unreleased]

### Changed
- `hlds` user is now created with a fixed uid/gid (10001) and `USER` references it numerically, making bind-mount ownership deterministic under rootless Podman and resolving hadolint `DL3066`
- `HEALTHCHECK` `CMD` converted to JSON/exec notation (`/bin/sh -c ...`), resolving hadolint `DL3025`
- Bumped `hadolint/hadolint-action` in `ci.yml` from v3.3.0 to v3.4.0 (hadolint 2.14.0 → 2.15.0)
- `just lint` pins `ghcr.io/hadolint/hadolint:v2.15.0-debian` instead of tracking `:latest`, so local linting and CI run the same ruleset
- Dependabot no longer opens minor/patch PRs for `actions/*`, `docker/*` and `github/codeql-action`, which are pinned at the major tag on purpose
- Bumped AMX Mod X pin from build 5478 to 5479
- Bumped shellcheck pin in `ci.yml` from v0.10.0 to v0.11.0
- README stack list resynced to the versions actually pinned in the Containerfile (ReHLDS 3.15.0.896, ReGameDLL_CS 5.30.0.814, ReAPI 5.29.0.358, AMX Mod X build 5479)
Expand Down
8 changes: 5 additions & 3 deletions Containerfile
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,9 @@ RUN dpkg --add-architecture i386 && \
/var/tmp/* \
&& (find / -xdev -perm /6000 -type f -exec chmod a-s {} + 2>/dev/null || true)

RUN useradd --no-log-init -r -s /usr/sbin/nologin hlds
# Fixed uid/gid so bind-mount ownership is deterministic under rootless Podman
RUN groupadd --system --gid 10001 hlds && \
useradd --no-log-init --system --uid 10001 --gid 10001 -s /usr/sbin/nologin hlds

COPY --from=builder --chown=hlds:hlds /hlds /hlds
COPY --chmod=755 entrypoint.sh /entrypoint.sh
Expand All @@ -203,12 +205,12 @@ LABEL org.opencontainers.image.title="CS 1.6 ScoutzKnivez Server" \
org.opencontainers.image.licenses="MIT" \
org.opencontainers.image.vendor="KevinTCoughlin"

USER hlds
USER 10001:10001
WORKDIR /hlds

EXPOSE 27015/udp 27015/tcp

HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \
CMD grep -qs hlds_linux /proc/[0-9]*/comm || exit 1
CMD ["/bin/sh", "-c", "grep -qs hlds_linux /proc/[0-9]*/comm || exit 1"]

ENTRYPOINT ["/entrypoint.sh"]
6 changes: 5 additions & 1 deletion justfile
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Keep in sync with the hadolint version bundled by hadolint/hadolint-action
# in .github/workflows/ci.yml, so `just lint` and CI agree on the ruleset.
HADOLINT_IMAGE := "ghcr.io/hadolint/hadolint:v2.15.0-debian"

default:
@just --list

Expand Down Expand Up @@ -38,7 +42,7 @@ install:

# Lint Containerfile with hadolint
lint:
podman run --rm -i hadolint/hadolint < Containerfile
podman run --rm -i {{HADOLINT_IMAGE}} < Containerfile

# Lint shell scripts with shellcheck
shellcheck:
Expand Down