18044210f6
etcd(bitnamilegacy 동결 미러) → etcd.enabled=false + 카탈로그 자체 etcd 차트를 externalEtcd 기본값으로 연결. adc·apisix-ingress-controller·apisix(paasup/apisix) 세 이미지는 SUSE BCI 자체 빌드로 교체 — 전부 벤더 등급만으로는 안 보이던 벤더 하향 등급 CVE(NVD 재평가 시 드러남)가 원인이었다. - images/apisix-ingress-controller: 정적 링크 Go 모듈 취약 버전만 강제 업그레이드 - images/apisix: APISIX-Runtime(WASM·dubbo 등 커스텀 모듈 포함) 전체를 SUSE BCI 위에서 소스로 재현, keycloak-authz 플러그인 오버레이 - images/adc: 업스트림 빌더 스테이지는 그대로 두고 distroless 최종 베이스만 SUSE BCI+nodejs24 로 교체 scripts/build/patch-catalog-tag.py 의 TAG_BLOCK 이 점 구분 중첩 경로를 지원하도록 확장(apisix 서브차트 alias 때문에 필요). 세 이미지 모두 게이트 PASS(실효 CRITICAL/HIGH 0/0)와 배포 검증(테스트 클러스터)을 마쳤다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
65 lines
2.0 KiB
Bash
65 lines
2.0 KiB
Bash
#!/usr/bin/env bash
|
|
#
|
|
# Licensed to the Apache Software Foundation (ASF) under one or more
|
|
# contributor license agreements. See the NOTICE file distributed with
|
|
# this work for additional information regarding copyright ownership.
|
|
# The ASF licenses this file to You under the Apache License, Version 2.0
|
|
# (the "License"); you may not use this file except in compliance with
|
|
# the License. You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
#
|
|
|
|
set -eo pipefail
|
|
|
|
PREFIX=${APISIX_PREFIX:=/usr/local/apisix}
|
|
|
|
if [[ "$1" == "docker-start" ]]; then
|
|
if [ "$APISIX_STAND_ALONE" = "true" ]; then
|
|
# If the file is not present then initialise the content otherwise update relevant keys for standalone mode
|
|
if [ ! -f "${PREFIX}/conf/config.yaml" ]; then
|
|
cat > ${PREFIX}/conf/config.yaml << _EOC_
|
|
deployment:
|
|
role: data_plane
|
|
role_data_plane:
|
|
config_provider: yaml
|
|
_EOC_
|
|
fi
|
|
|
|
if [ ! -f "${PREFIX}/conf/apisix.yaml" ]; then
|
|
cat > ${PREFIX}/conf/apisix.yaml << _EOC_
|
|
routes:
|
|
-
|
|
#END
|
|
_EOC_
|
|
fi
|
|
/usr/bin/apisix init
|
|
else
|
|
/usr/bin/apisix init
|
|
/usr/bin/apisix init_etcd
|
|
fi
|
|
|
|
# For versions below 3.5.0 whose conf_server has not been removed.
|
|
if [ -e "/usr/local/apisix/conf/config_listen.sock" ]; then
|
|
rm -f "/usr/local/apisix/conf/config_listen.sock"
|
|
fi
|
|
|
|
if [ -e "/usr/local/apisix/logs/worker_events.sock" ]; then
|
|
rm -f "/usr/local/apisix/logs/worker_events.sock"
|
|
fi
|
|
|
|
if [ -e "/usr/local/apisix/logs/stream_worker_events.sock" ]; then
|
|
rm -f "/usr/local/apisix/logs/stream_worker_events.sock"
|
|
fi
|
|
|
|
exec /usr/local/openresty/bin/openresty -p /usr/local/apisix -g 'daemon off;'
|
|
fi
|
|
|
|
exec "$@"
|