-
Notifications
You must be signed in to change notification settings - Fork 354
SRE-4027 build: provide ZSCALER_CA_FILE arg for local docker builds #19045
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
soumagne
wants to merge
1
commit into
master
Choose a base branch
from
soumagne/zscaler_cont
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+44
−1
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do not make this type of change, it is not going to help you at all long term.
All access to the dockerfiles has to come from Artifactory.
If you are running your own docker host, in the lab you need to have it setup to use:
hub.daos.hpc.amslabs.hpecorp.net or it will not work reliably.
Docker is blocking most access from the corporate proxy from anonymous users. We have setup the CI docker builders to pull from alternative sources because of this and we use a trick to make it look like it is using images from the dockerhub.
Any use of HTTPS_PROXY to avoid using the internal Artifact Servers is a bug, that needs to be removed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just to be clear, this is not something I want to use in CI builds. I only want to use that option for my local docker builds on my laptop.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Then install the ZSCALER CA on laptop on what ever is running docker. It does not need to be in the dockerfile.
I have updated the ticket for this with how to access the internal docker hub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I understand more of what you are trying to do now, I think.
Now when you are doing this build on your laptop, are you using any lab resources at all?
If you are not using lab resources than you use:
DAOS_LAB_CA_FILE_URl to pass your zscaler cert contents.
And then the repo-helper scripts can see of DAOS_LAB_CA_FILE_URI starts with HTTP:// or HTTPS:// and then install the CA accordingly.
If you are using LAB resources like Artifactory, then you should be able to get what you need without the Zscaler CA.
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's right, I'm not using any of the lab resources in this case. I think I can try doing what you just proposed with DAOS_LAB_CA_FILE_URI.
Zscaler intercepts all HTTP traffic on HPE laptops so afaik there is no other solution than installing the Zscaler certificate, this is further described in https://docs.docker.com/guides/zscaler/