This commit is contained in:
Bernhard Radermacher
2026-02-18 13:01:27 +01:00
parent c2db670d35
commit c860ddd210

View File

@@ -1,34 +1,19 @@
#
# NOTE: THIS DOCKERFILE IS GENERATED VIA "apply-templates.sh"
#
# PLEASE DO NOT EDIT IT DIRECTLY.
#
FROM debian:trixie-slim FROM debian:trixie-slim
# explicitly set user/group IDs
RUN set -eux; \ RUN set -eux; \
groupadd -r postgres --gid=999; \ groupadd -r postgres --gid=5432; \
# https://salsa.debian.org/postgresql/postgresql-common/blob/997d842ee744687d99a2b2d95c1083a2615c79e8/debian/postgresql-common.postinst#L32-35 useradd -r -g postgres --uid=5432 --home-dir=/var/lib/postgresql --shell=/bin/bash postgres; \
useradd -r -g postgres --uid=999 --home-dir=/var/lib/postgresql --shell=/bin/bash postgres; \
# also create the postgres user's home directory with appropriate permissions
# see https://github.com/docker-library/postgres/issues/274
install --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql install --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql
RUN set -ex; \ RUN set -ex; \
apt-get update; \ apt-get update; \
apt-get install -y --no-install-recommends \ apt-get install -y --no-install-recommends \
gnupg \ gnupg \
# https://www.postgresql.org/docs/16/app-psql.html#APP-PSQL-META-COMMAND-PSET-PAGER
# https://github.com/postgres/postgres/blob/REL_16_1/src/include/fe_utils/print.h#L25
# (if "less" is available, it gets used as the default pager for psql, and it only adds ~1.5MiB to our image size)
less \ less \
; \ ; \
rm -rf /var/lib/apt/lists/* rm -rf /var/lib/apt/lists/*
# grab gosu for easy step-down from root ENV GOSU_VERSION=1.19
# https://github.com/tianon/gosu/releases
ENV GOSU_VERSION 1.19
RUN set -eux; \ RUN set -eux; \
savedAptMark="$(apt-mark showmanual)"; \ savedAptMark="$(apt-mark showmanual)"; \
apt-get update; \ apt-get update; \
@@ -49,10 +34,8 @@ RUN set -eux; \
gosu --version; \ gosu --version; \
gosu nobody true gosu nobody true
# make the "en_US.UTF-8" locale so postgres will be utf-8 enabled by default
RUN set -eux; \ RUN set -eux; \
if [ -f /etc/dpkg/dpkg.cfg.d/docker ]; then \ if [ -f /etc/dpkg/dpkg.cfg.d/docker ]; then \
# if this file exists, we're likely in "debian:xxx-slim", and locales are thus being excluded so we need to remove that exclusion (since we need locales)
grep -q '/usr/share/locale' /etc/dpkg/dpkg.cfg.d/docker; \ grep -q '/usr/share/locale' /etc/dpkg/dpkg.cfg.d/docker; \
sed -ri '/\/usr\/share\/locale/d' /etc/dpkg/dpkg.cfg.d/docker; \ sed -ri '/\/usr\/share\/locale/d' /etc/dpkg/dpkg.cfg.d/docker; \
! grep -q '/usr/share/locale' /etc/dpkg/dpkg.cfg.d/docker; \ ! grep -q '/usr/share/locale' /etc/dpkg/dpkg.cfg.d/docker; \
@@ -75,9 +58,6 @@ RUN set -eux; \
RUN mkdir /docker-entrypoint-initdb.d RUN mkdir /docker-entrypoint-initdb.d
RUN set -ex; \ RUN set -ex; \
# pub 4096R/ACCC4CF8 2011-10-13 [expires: 2019-07-02]
# Key fingerprint = B97B 0AFC AA1A 47F0 44F2 44A0 7FCC 7D46 ACCC 4CF8
# uid PostgreSQL Debian Repository
key='B97B0AFCAA1A47F044F244A07FCC7D46ACCC4CF8'; \ key='B97B0AFCAA1A47F044F244A07FCC7D46ACCC4CF8'; \
export GNUPGHOME="$(mktemp -d)"; \ export GNUPGHOME="$(mktemp -d)"; \
mkdir -p /usr/local/share/keyrings/; \ mkdir -p /usr/local/share/keyrings/; \
@@ -92,74 +72,43 @@ ENV PATH $PATH:/usr/lib/postgresql/$PG_MAJOR/bin
ENV PG_VERSION 15.16-1.pgdg13+1 ENV PG_VERSION 15.16-1.pgdg13+1
RUN set -ex; \ RUN set -ex; \
\
# see note below about "*.pyc" files
export PYTHONDONTWRITEBYTECODE=1; \ export PYTHONDONTWRITEBYTECODE=1; \
\
dpkgArch="$(dpkg --print-architecture)"; \ dpkgArch="$(dpkg --print-architecture)"; \
aptRepo="[ signed-by=/usr/local/share/keyrings/postgres.gpg.asc ] http://apt.postgresql.org/pub/repos/apt trixie-pgdg main $PG_MAJOR"; \ aptRepo="[ signed-by=/usr/local/share/keyrings/postgres.gpg.asc ] http://apt.postgresql.org/pub/repos/apt trixie-pgdg main $PG_MAJOR"; \
# we're on an architecture upstream doesn't officially build for echo "deb-src $aptRepo" > /etc/apt/sources.list.d/pgdg.list; \
# let's build binaries from their published source packages savedAptMark="$(apt-mark showmanual)"; \
echo "deb-src $aptRepo" > /etc/apt/sources.list.d/pgdg.list; \ tempDir="$(mktemp -d)"; \
\ cd "$tempDir"; \
savedAptMark="$(apt-mark showmanual)"; \ apt-get update; \
\ apt-get install -y --no-install-recommends dpkg-dev; \
tempDir="$(mktemp -d)"; \ echo "deb [ trusted=yes ] file://$tempDir ./" > /etc/apt/sources.list.d/temp.list; \
cd "$tempDir"; \ _update_repo() { \
\ dpkg-scanpackages . > Packages; \
# create a temporary local APT repo to install from (so that dependency resolution can be handled by APT, as it should be) apt-get -o Acquire::GzipIndexes=false update; \
apt-get update; \ }; \
apt-get install -y --no-install-recommends dpkg-dev; \ _update_repo; \
echo "deb [ trusted=yes ] file://$tempDir ./" > /etc/apt/sources.list.d/temp.list; \ nproc="$(nproc)"; \
_update_repo() { \ export DEB_BUILD_OPTIONS="nocheck parallel=$nproc"; \
dpkg-scanpackages . > Packages; \ apt-get build-dep -y postgresql-common-dev; \
# work around the following APT issue by using "Acquire::GzipIndexes=false" (overriding "/etc/apt/apt.conf.d/docker-gzip-indexes") apt-get source --compile postgresql-common-dev; \
# Could not open file /var/lib/apt/lists/partial/_tmp_tmp.ODWljpQfkE_._Packages - open (13: Permission denied) _update_repo; \
# ... apt-get build-dep -y "postgresql-$PG_MAJOR=$PG_VERSION"; \
# E: Failed to fetch store:/var/lib/apt/lists/partial/_tmp_tmp.ODWljpQfkE_._Packages Could not open file /var/lib/apt/lists/partial/_tmp_tmp.ODWljpQfkE_._Packages - open (13: Permission denied) apt-get source --compile "postgresql-$PG_MAJOR=$PG_VERSION"; \
apt-get -o Acquire::GzipIndexes=false update; \ apt-mark showmanual | xargs apt-mark auto > /dev/null; \
}; \ apt-mark manual $savedAptMark; \
_update_repo; \ ls -lAFh; \
\ _update_repo; \
# build .deb files from upstream's source packages (which are verified by apt-get) grep '^Package: ' Packages; \
nproc="$(nproc)"; \ cd /; \
export DEB_BUILD_OPTIONS="nocheck parallel=$nproc"; \
# we have to build postgresql-common-dev first because postgresql-$PG_MAJOR shares "debian/rules" logic with it: https://salsa.debian.org/postgresql/postgresql/-/commit/f4338a0d28cf4541956bddb0f4e444ba9dba81b9
apt-get build-dep -y postgresql-common-dev; \
apt-get source --compile postgresql-common-dev; \
_update_repo; \
apt-get build-dep -y "postgresql-$PG_MAJOR=$PG_VERSION"; \
apt-get source --compile "postgresql-$PG_MAJOR=$PG_VERSION"; \
\
# we don't remove APT lists here because they get re-downloaded and removed later
\
# reset apt-mark's "manual" list so that "purge --auto-remove" will remove all build dependencies
# (which is done after we install the built packages so we don't have to redownload any overlapping dependencies)
apt-mark showmanual | xargs apt-mark auto > /dev/null; \
apt-mark manual $savedAptMark; \
\
ls -lAFh; \
_update_repo; \
grep '^Package: ' Packages; \
cd /; \
\
apt-get install -y --no-install-recommends postgresql-common; \ apt-get install -y --no-install-recommends postgresql-common; \
sed -ri 's/#(create_main_cluster) .*$/\1 = false/' /etc/postgresql-common/createcluster.conf; \ sed -ri 's/#(create_main_cluster) .*$/\1 = false/' /etc/postgresql-common/createcluster.conf; \
apt-get install -y --no-install-recommends \ apt-get install -y --no-install-recommends \
"postgresql-$PG_MAJOR=$PG_VERSION" \ "postgresql-$PG_MAJOR=$PG_VERSION" \
; \ ; \
\
rm -rf /var/lib/apt/lists/*; \ rm -rf /var/lib/apt/lists/*; \
\ apt-get purge -y --auto-remove; \
if [ -n "$tempDir" ]; then \ rm -rf "$tempDir" /etc/apt/sources.list.d/temp.list; \
# if we have leftovers from building, let's purge them (including extra, unnecessary build deps)
apt-get purge -y --auto-remove; \
rm -rf "$tempDir" /etc/apt/sources.list.d/temp.list; \
fi; \
\
# some of the steps above generate a lot of "*.pyc" files (and setting "PYTHONDONTWRITEBYTECODE" beforehand doesn't propagate properly for some reason), so we clean them up manually (as long as they aren't owned by a package)
find /usr -name '*.pyc' -type f -exec bash -c 'for pyc; do dpkg -S "$pyc" &> /dev/null || rm -vf "$pyc"; done' -- '{}' +; \ find /usr -name '*.pyc' -type f -exec bash -c 'for pyc; do dpkg -S "$pyc" &> /dev/null || rm -vf "$pyc"; done' -- '{}' +; \
\
postgres --version postgres --version
# make the sample config easier to munge (and "correct by default") # make the sample config easier to munge (and "correct by default")