diff --git a/controller/Containerfile b/controller/Containerfile index fd4b215f8..a6bcb5745 100644 --- a/controller/Containerfile +++ b/controller/Containerfile @@ -51,6 +51,7 @@ RUN --mount=type=cache,target=/opt/app-root/src/go/pkg/mod,sharing=locked,uid=1 FROM registry.access.redhat.com/ubi9/ubi-micro:9.8-1789345812@sha256:7a0454cbd9bd847e8f6a63b6f0254a6efbeb6e0ed71a5d824a4f6cccbe626650 WORKDIR / +COPY --from=builder /etc/pki/tls/certs/ca-bundle.crt /etc/pki/tls/certs/ca-bundle.crt COPY --from=builder /build/manager . COPY --from=builder /build/router . USER 65532:65532 diff --git a/controller/Containerfile.exporter-set-controller b/controller/Containerfile.exporter-set-controller index 0384fe291..68c60c329 100644 --- a/controller/Containerfile.exporter-set-controller +++ b/controller/Containerfile.exporter-set-controller @@ -37,6 +37,7 @@ RUN --mount=type=cache,target=/opt/app-root/src/go/pkg/mod,sharing=locked,uid=10 FROM registry.access.redhat.com/ubi9/ubi-micro:9.8-1789345812@sha256:7a0454cbd9bd847e8f6a63b6f0254a6efbeb6e0ed71a5d824a4f6cccbe626650 WORKDIR / +COPY --from=builder /etc/pki/tls/certs/ca-bundle.crt /etc/pki/tls/certs/ca-bundle.crt COPY --from=builder /build/exporter-set-controller . USER 65532:65532 diff --git a/controller/Containerfile.operator b/controller/Containerfile.operator index 30fca0169..39ec59b0a 100644 --- a/controller/Containerfile.operator +++ b/controller/Containerfile.operator @@ -43,6 +43,7 @@ RUN --mount=type=cache,target=/opt/app-root/src/go/pkg/mod,sharing=locked,uid=10 FROM registry.access.redhat.com/ubi9/ubi-micro:9.8-1789345812@sha256:7a0454cbd9bd847e8f6a63b6f0254a6efbeb6e0ed71a5d824a4f6cccbe626650 WORKDIR / +COPY --from=builder /etc/pki/tls/certs/ca-bundle.crt /etc/pki/tls/certs/ca-bundle.crt COPY --from=builder /opt/app-root/src/deploy/operator/manager . USER 65532:65532 diff --git a/controller/Containerfile.prebuilt b/controller/Containerfile.prebuilt index 62c58a1dd..4c170caab 100644 --- a/controller/Containerfile.prebuilt +++ b/controller/Containerfile.prebuilt @@ -3,9 +3,11 @@ # BIN selects which binary becomes the default entrypoint. # COPY ${BIN} /entrypoint works because COPY supports ARG expansion, # while ENTRYPOINT does not (and ubi-micro has no shell for shell-form). +FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8 AS certs FROM registry.access.redhat.com/ubi9/ubi-micro:9.8-1789345812@sha256:7a0454cbd9bd847e8f6a63b6f0254a6efbeb6e0ed71a5d824a4f6cccbe626650 ARG BIN WORKDIR / +COPY --from=certs /etc/pki/tls/certs/ca-bundle.crt /etc/pki/tls/certs/ca-bundle.crt COPY . . # ENTRYPOINT can't expand ARG; fixed path lets one file serve all three images COPY ${BIN} /entrypoint diff --git a/controller/Containerfile.telemetry.prebuilt b/controller/Containerfile.telemetry.prebuilt index 49560da38..ad2c08755 100644 --- a/controller/Containerfile.telemetry.prebuilt +++ b/controller/Containerfile.telemetry.prebuilt @@ -1,6 +1,8 @@ # CI-only runtime image for the jumpstarter-telemetry binary. +FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8 AS certs FROM registry.access.redhat.com/ubi9/ubi-micro:9.8-1786321990@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 WORKDIR / +COPY --from=certs /etc/pki/tls/certs/ca-bundle.crt /etc/pki/tls/certs/ca-bundle.crt COPY telemetry /telemetry USER 65532:65532 ENTRYPOINT ["/telemetry"]