dockerfile

package
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Dec 5, 2025 License: MulanPSL-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

View Source
const (
	FROM = iota + 1
	RUN
	CMD
	LABEL
	MAINTAINER
	EXPOSE
	ENV
	ADD
	COPY
	ENTRYPOINT
	VOLUME
	USER
	WORKDIR
	ARG
	ONBUILD
	STOPSIGNAL
	HEALTHCHECK
	SHELL
)

Variables

This section is empty.

Functions

This section is empty.

Types

type AddDirective

type AddDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Chown        string `json:"chown"`
	Source       string `json:"source"`
	Destination  string `json:"destination"`
}

func NewAddDirective

func NewAddDirective(rawContent string) *AddDirective

func (AddDirective) Get

func (d AddDirective) Get() map[string]interface{}

func (*AddDirective) GetType

type ArgDirective

type ArgDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Argument     string `json:"argument"`
}

func NewArgDirective

func NewArgDirective(rawContent string) *ArgDirective

func (ArgDirective) Get

func (d ArgDirective) Get() map[string]interface{}

func (*ArgDirective) GetType

type AuditException

type AuditException struct {
	Message string
}

AuditException is an error type for audit exceptions.

func (*AuditException) Error

func (e *AuditException) Error() string

type CmdDirective

type CmdDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
}

func NewCmdDirective

func NewCmdDirective(rawContent string) *CmdDirective

func (CmdDirective) Get

func (d CmdDirective) Get() map[string]interface{}

func (*CmdDirective) GetType

type CopyDirective

type CopyDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Chown        string `json:"chown"`
	Source       string `json:"source"`
	Destination  string `json:"destination"`
}

func NewCopyDirective

func NewCopyDirective(rawContent string) *CopyDirective

func (CopyDirective) Get

func (d CopyDirective) Get() map[string]interface{}

func (*CopyDirective) GetType

type DfDirective

type DfDirective interface {
	GetType() DockerfileDirectiveType
	Get() map[string]interface{}
}

type Dockerfile

type Dockerfile struct {
	Directives  []DfDirective
	Path        string
	Filename    string
	Maintainers []string
}

func NewDockerfile

func NewDockerfile(path string) (*Dockerfile, error)

func (*Dockerfile) AddDirective

func (df *Dockerfile) AddDirective(directive DfDirective)

func (*Dockerfile) GetDirectives

func (df *Dockerfile) GetDirectives() map[string][]DfDirective

func (*Dockerfile) GetFilename

func (df *Dockerfile) GetFilename() string

func (*Dockerfile) GetMaintainers

func (df *Dockerfile) GetMaintainers() string

func (*Dockerfile) GetPath

func (df *Dockerfile) GetPath() string

func (*Dockerfile) GetRaw

func (df *Dockerfile) GetRaw() []map[string]interface{}

func (*Dockerfile) GetRunDirectivesLastStage

func (df *Dockerfile) GetRunDirectivesLastStage() []DfDirective

type DockerfileAuditor

type DockerfileAuditor struct {
	Policy Policy
}

DockerfileAuditor is a struct for DockerfileMsg auditing.

func NewDockerfileAuditor

func NewDockerfileAuditor(policy Policy) *DockerfileAuditor

NewDockerfileAuditor creates a new instance of DfAuditor with the given policy.

func (*DockerfileAuditor) Audit

func (auditor *DockerfileAuditor) Audit(path string) (PolicyResult, error)

Audit performs the audit operation on the specified file path.

func (*DockerfileAuditor) ParseOnly

func (auditor *DockerfileAuditor) ParseOnly(path string) (ParseResult, error)

ParseOnly 仅对指定的文件路径执行分析操作。

type DockerfileDirectiveType

type DockerfileDirectiveType int

func (DockerfileDirectiveType) String

func (d DockerfileDirectiveType) String() string

type DockerfileObject

type DockerfileObject struct {
	From               string
	Platform           string
	Registry           string
	ImageName          string
	ImageTag           string
	Digest             string
	LocalName          string
	User               string
	RunCommands        []string
	LabelCommands      []string
	ExposeCommands     []string
	MaintainerCommands []string
	AddCommands        []string
	CopyCommands       []string
	EnvCommands        []string
	CmdCommands        []string
	EntrypointCommands []string
	WorkdirCommand     string
	VolumeCommands     []string
	ShellCommand       string
	StopsignalCommand  string
	ArgCommands        []string
	HealthcheckCommand string
	HealthcheckOptions string
}

type DockerfileVisitor

type DockerfileVisitor struct {
	Dockerfile *Dockerfile
}

func NewDockerfileVisitor

func NewDockerfileVisitor(dockerfile *Dockerfile) *DockerfileVisitor

func (*DockerfileVisitor) VisitDockerfile

func (v *DockerfileVisitor) VisitDockerfile(visitedChildren *parser.Node) interface{}

type EnforceRegistryPolicy

type EnforceRegistryPolicy struct {
	GenericPolicyRule
	AllowedRegistries []string
	Enabled           bool
}

func NewEnforceRegistryPolicy

func NewEnforceRegistryPolicy(allowedRegistries []string, enabled bool) *EnforceRegistryPolicy

func (*EnforceRegistryPolicy) Details

func (r *EnforceRegistryPolicy) Details() string

func (*EnforceRegistryPolicy) Test

func (r *EnforceRegistryPolicy) Test(dockerfileDirectives map[string][]DfDirective) *[]Rule

type EntrypointDirective

type EntrypointDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
}

func NewEntrypointDirective

func NewEntrypointDirective(rawContent string) *EntrypointDirective

func (EntrypointDirective) Get

func (d EntrypointDirective) Get() map[string]interface{}

func (*EntrypointDirective) GetType

type EnvDirective

type EnvDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Variables    map[string]string `json:"variables"`
}

func NewEnvDirective

func NewEnvDirective(rawContent string) *EnvDirective

func (EnvDirective) Get

func (d EnvDirective) Get() map[string]interface{}

func (*EnvDirective) GetType

type ExposeDirective

type ExposeDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Ports        []string `json:"ports"`
}

func NewExposeDirective

func NewExposeDirective(rawContent string) *ExposeDirective

func (ExposeDirective) Get

func (d ExposeDirective) Get() map[string]interface{}

func (*ExposeDirective) GetType

type ForbidInsecureRegistries

type ForbidInsecureRegistries struct {
	GenericPolicyRule
	Enabled bool
}

func NewForbidInsecureRegistries

func NewForbidInsecureRegistries(enabled bool) *ForbidInsecureRegistries

func (*ForbidInsecureRegistries) Test

func (rule *ForbidInsecureRegistries) Test(dockerfileStatements map[string][]DfDirective) *[]Rule

type ForbidPackages

type ForbidPackages struct {
	ForbiddenPackages []string
	GenericPolicyRule
}

func NewForbidPackages

func NewForbidPackages(forbiddenPackages []string) *ForbidPackages

func (*ForbidPackages) Details

func (rule *ForbidPackages) Details() string

func (*ForbidPackages) Test

func (rule *ForbidPackages) Test(mapDirectives map[string][]DfDirective) *[]Rule

type ForbidPrivilegedPorts

type ForbidPrivilegedPorts struct {
	GenericPolicyRule
	Enabled bool
}

func NewForbidPrivilegedPorts

func NewForbidPrivilegedPorts(enabled bool) *ForbidPrivilegedPorts

func (*ForbidPrivilegedPorts) Test

func (rule *ForbidPrivilegedPorts) Test(dockerfileDirective map[string][]DfDirective) *[]Rule

type ForbidRoot

type ForbidRoot struct {
	GenericPolicyRule
	Enabled bool
}

func NewForbidRoot

func NewForbidRoot(enabled bool) *ForbidRoot

func (*ForbidRoot) Test

func (rule *ForbidRoot) Test(dockerfileStatements map[string][]DfDirective) *[]Rule

type ForbidSecrets

type ForbidSecrets struct {
	GenericPolicyRule
	// contains filtered or unexported fields
}

func NewForbidSecrets

func NewForbidSecrets(secretsPatterns, allowedPatterns []string) *ForbidSecrets

func (*ForbidSecrets) Details

func (fs *ForbidSecrets) Details() string

func (*ForbidSecrets) Test

func (fs *ForbidSecrets) Test(dockerfileStatements map[string][]DfDirective) *[]Rule

type ForbidTags

type ForbidTags struct {
	GenericPolicyRule
	ForbiddenTags []string
}

func NewForbidTags

func NewForbidTags(tags []string) *ForbidTags

func (*ForbidTags) Details

func (rule *ForbidTags) Details() string

func (*ForbidTags) Test

func (r *ForbidTags) Test(directives map[string][]DfDirective) *[]Rule

type FromDirective

type FromDirective struct {
	Type           DockerfileDirectiveType `json:"type"`
	Content        string                  `json:"raw_content"`
	RunLastStage   []map[string]string
	Platform       string `json:"platform"`
	Registry       string `json:"registry"`
	ImageLocalName string `json:"local_name"`
	ImageTag       string `json:"tag"`
	ImageName      string `json:"image"`
}

func NewFromDirective

func NewFromDirective(rawContent string) *FromDirective

func (*FromDirective) Get

func (d *FromDirective) Get() map[string]interface{}

func (*FromDirective) GetType

type GenericPolicyRule

type GenericPolicyRule struct {
	Type        PolicyRuleType
	TestResult  PolicyTestResult
	Description string
}

func (*GenericPolicyRule) Describe

func (r *GenericPolicyRule) Describe() string

func (*GenericPolicyRule) Details

func (r *GenericPolicyRule) Details() string

func (*GenericPolicyRule) GetType

func (r *GenericPolicyRule) GetType() PolicyRuleType

func (*GenericPolicyRule) Test

func (r *GenericPolicyRule) Test(directives map[string][]DfDirective) *[]Rule

type HealthcheckDirective

type HealthcheckDirective struct {
	Type    DockerfileDirectiveType `json:"type"`
	Content string                  `json:"raw_content"`
}

func NewHealthcheckDirective

func NewHealthcheckDirective(rawContent string) *HealthcheckDirective

func (HealthcheckDirective) Get

func (d HealthcheckDirective) Get() map[string]interface{}

func (*HealthcheckDirective) GetType

type LabelDirective

type LabelDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Labels       map[string]string `json:"labels"`
}

func NewLabelDirective

func NewLabelDirective(rawContent string) *LabelDirective

func (*LabelDirective) Get

func (d *LabelDirective) Get() map[string]interface{}

func (*LabelDirective) GetType

type MaintainerDirective

type MaintainerDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Maintainers  []string `json:"maintainers"`
}

func NewMaintainerDirective

func NewMaintainerDirective(rawContent string) *MaintainerDirective

func (MaintainerDirective) Get

func (d MaintainerDirective) Get() map[string]interface{}

func (MaintainerDirective) GetMaintainers

func (d MaintainerDirective) GetMaintainers() []string

func (*MaintainerDirective) GetType

type ParseResult

type ParseResult struct {
	Filename    string                   `json:"filename"`
	Path        string                   `json:"path"`
	Maintainers string                   `json:"maintainers"`
	Directives  map[string][]DfDirective `json:"directives"`
}

type Policy

type Policy struct {
	PolicyRules []PolicyRule
	PolicyFile  string
}

func NewDockerfilePolicy

func NewDockerfilePolicy(policyFile string) (*Policy, error)

func (*Policy) EvaluateDockerfile

func (p *Policy) EvaluateDockerfile(dockerfileObject Dockerfile) PolicyResult

func (*Policy) GetPolicyRulesEnabled

func (p *Policy) GetPolicyRulesEnabled() []Rule

type PolicyResult

type PolicyResult struct {
	Filename     string
	Tests        []Rule
	AuditOutcome string
	Maintainers  string
	Path         string
}

type PolicyRule

type PolicyRule interface {
	GetType() PolicyRuleType
	Details() string
	Describe() string
	Test(directives map[string][]DfDirective) *[]Rule
}

type PolicyRuleType

type PolicyRuleType int
const (
	GENERIC_POLICY PolicyRuleType = iota + 1
	ENFORCE_REGISTRY
	FORBID_TAGS
	FORBID_INSECURE_REGISTRIES
	FORBID_ROOT
	FORBID_PRIVILEGED_PORTS
	FORBID_PACKAGES
	FORBID_SECRETS
	FORBID_LAX_CHMOD
)

func (PolicyRuleType) String

func (t PolicyRuleType) String() string

type PolicyTestResult

type PolicyTestResult struct {
	Results []Rule
}

func NewPolicyTestResult

func NewPolicyTestResult() PolicyTestResult

func (*PolicyTestResult) AddPassResult

func (r *PolicyTestResult) AddPassResult(details string, ruleType PolicyRuleType, content string)

func (*PolicyTestResult) AddResult

func (r *PolicyTestResult) AddResult(details, mitigations string, ruleType PolicyRuleType, content string, directiveType ...string)

func (*PolicyTestResult) GetResult

func (r *PolicyTestResult) GetResult() *[]Rule

type Rule

type Rule struct {
	Type        PolicyRuleType `json:"Type"`
	Details     string         `json:"Details"`
	Mitigations string         `json:"Mitigations"`
	Statement   []string       `json:"Statement,omitempty"`
	Line        int            `json:"Line,omitempty"`
	Directive   string         `json:"Directive,omitempty"`
	Level       string         `json:"Level,omitempty"`
	Status      string         `json:"Status"` // 新增:"pass" 或 "fail"
}

func (Rule) MarshalJSON

func (r Rule) MarshalJSON() ([]byte, error)

添加MarshalJSON方法以自定义JSON序列化

type RunDirective

type RunDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
}

func NewRunDirective

func NewRunDirective(rawContent string) *RunDirective

func (*RunDirective) Get

func (d *RunDirective) Get() map[string]interface{}

func (*RunDirective) GetType

type ShellDirective

type ShellDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
}

func NewShellDirective

func NewShellDirective(rawContent string) *ShellDirective

func (ShellDirective) Get

func (d ShellDirective) Get() map[string]interface{}

func (*ShellDirective) GetType

type StopsignalDirective

type StopsignalDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Signal       string `json:"stopsignal"`
}

func NewStopsignalDirective

func NewStopsignalDirective(rawContent string) *StopsignalDirective

func (StopsignalDirective) Get

func (d StopsignalDirective) Get() map[string]interface{}

func (*StopsignalDirective) GetType

type UserDirective

type UserDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	User         string `json:"user"`
	Group        string `json:"group"`
}

func NewUserDirective

func NewUserDirective(rawContent string) *UserDirective

func (UserDirective) Get

func (d UserDirective) Get() map[string]interface{}

func (*UserDirective) GetType

type VolumeDirective

type VolumeDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
	Volumes      []string `json:"volumes"`
}

func NewVolumeDirective

func NewVolumeDirective(rawContent string) *VolumeDirective

func (VolumeDirective) Get

func (d VolumeDirective) Get() map[string]interface{}

func (*VolumeDirective) GetType

type WorkdirDirective

type WorkdirDirective struct {
	Type         DockerfileDirectiveType `json:"type"`
	Content      string                  `json:"raw_content"`
	RunLastStage []map[string]string
}

func NewWorkdirDirective

func NewWorkdirDirective(rawContent string) *WorkdirDirective

func (WorkdirDirective) Get

func (d WorkdirDirective) Get() map[string]interface{}

func (*WorkdirDirective) GetType

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL