diff --git a/beacon-chain/Dockerfile b/beacon-chain/Dockerfile index 673f793..8811fdc 100644 --- a/beacon-chain/Dockerfile +++ b/beacon-chain/Dockerfile @@ -1,13 +1,11 @@ ARG UPSTREAM_VERSION -FROM debian:bullseye-slim AS builder +FROM debian:bookworm-slim AS builder ARG NETWORK -# Use ldd to copy dependencies of grep -RUN mkdir /deps && \ - ldd /bin/grep | tr -s '[:space:]' '\n' | grep '^/' | xargs -I {} cp -v {} /deps || true && \ - apt-get update && \ - apt-get --yes install wget +RUN apt-get update && \ + apt-get --yes install --no-install-recommends ca-certificates wget && \ + rm -rf /var/lib/apt/lists/* ENV LUKSO_CONFIG_PATH=/configs/lukso \ LUKSO_SHARED_CONFIG_URL=https://raw.githubusercontent.com/lukso-network/network-configs/main/mainnet/shared/pectra \ @@ -23,7 +21,12 @@ RUN mkdir -p ${LUKSO_CONFIG_PATH} ${SEPOLIA_CONFIG_PATH} && \ wget ${SEPOLIA_GENESIS_URL} -O ${SEPOLIA_CONFIG_PATH}/genesis.ssz; \ fi -ARG UPSTREAM_VERSION +# Match Prysm's Bullseye runtime; this stage does not need APT repositories. +FROM debian:bullseye-slim AS tools + +RUN mkdir /deps && \ + ldd /bin/grep | tr -s '[:space:]' '\n' | grep '^/' | xargs -I {} cp -v {} /deps + FROM gcr.io/prysmaticlabs/prysm/beacon-chain:${UPSTREAM_VERSION} ARG NETWORK @@ -44,9 +47,9 @@ COPY entrypoint.sh /usr/local/bin/entrypoint.sh ADD ${STAKER_SCRIPTS_URL}/consensus_tools.sh /etc/profile.d/ -COPY --from=builder /bin/sh /bin/sh -COPY --from=builder /bin/grep /bin/grep -COPY --from=builder /deps/* /lib/ +COPY --from=tools /bin/sh /bin/sh +COPY --from=tools /bin/grep /bin/grep +COPY --from=tools /deps/* /lib/ COPY --from=builder /configs /configs @@ -59,4 +62,4 @@ ENV NETWORK=${NETWORK} \ LUKSO_GENESIS_FILE_PATH=${CONFIGS_PATH}/lukso/genesis.ssz \ LUKSO_CHAIN_CONFIG_FILE_PATH=${CONFIGS_PATH}/lukso/config.yaml -ENTRYPOINT [ "/usr/local/bin/entrypoint.sh" ] \ No newline at end of file +ENTRYPOINT [ "/usr/local/bin/entrypoint.sh" ] diff --git a/validator/Dockerfile b/validator/Dockerfile index f22afa1..81ba780 100644 --- a/validator/Dockerfile +++ b/validator/Dockerfile @@ -1,15 +1,12 @@ ARG UPSTREAM_VERSION -FROM debian:bullseye-slim AS builder +FROM debian:bookworm-slim AS builder ARG NETWORK -# Use ldd to copy dependencies of grep -RUN mkdir /deps -RUN ldd /bin/grep | tr -s '[:space:]' '\n' | grep '^/' | xargs -I {} cp -v {} /deps || true && \ - apt-get update && \ - apt-get --yes install wget && \ - apt-get clean +RUN apt-get update && \ + apt-get --yes install --no-install-recommends ca-certificates wget && \ + rm -rf /var/lib/apt/lists/* ENV LUKSO_CONFIG_URL=https://raw.githubusercontent.com/lukso-network/network-configs/main/mainnet/shared/pectra/config.yaml @@ -19,7 +16,12 @@ RUN if [ "${NETWORK}" = "lukso" ]; then \ touch /lukso-config.yaml; \ fi -ARG UPSTREAM_VERSION +# Match Prysm's Bullseye runtime; this stage does not need APT repositories. +FROM debian:bullseye-slim AS tools + +RUN mkdir /deps && \ + ldd /bin/grep | tr -s '[:space:]' '\n' | grep '^/' | xargs -I {} cp -v {} /deps + FROM gcr.io/prysmaticlabs/prysm/validator:${UPSTREAM_VERSION} ARG NETWORK @@ -32,9 +34,9 @@ ENV VALIDATOR_API_PORT=3500 \ LUKSO_CONFIG_PATH=/configs/lukso/shared/config.yaml \ STAKER_SCRIPTS_URL=https://github.com/dappnode/staker-package-scripts/releases/download/${STAKER_SCRIPTS_VERSION} -COPY --from=builder /bin/sh /bin/sh -COPY --from=builder /bin/grep /bin/grep -COPY --from=builder /deps/* /lib/ +COPY --from=tools /bin/sh /bin/sh +COPY --from=tools /bin/grep /bin/grep +COPY --from=tools /deps/* /lib/ COPY --from=builder /lukso-config.yaml ${LUKSO_CONFIG_PATH} RUN mkdir -p ${WALLET_DIR} $(dirname ${LUKSO_CONFIG_PATH}) @@ -50,4 +52,4 @@ RUN chmod +rx /usr/local/bin/entrypoint.sh /etc/profile.d/consensus_tools.sh # Placed at the end to regenerate the least amount of layers ENV NETWORK=${NETWORK} -ENTRYPOINT [ "/usr/local/bin/entrypoint.sh" ] \ No newline at end of file +ENTRYPOINT [ "/usr/local/bin/entrypoint.sh" ]