You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5d3fb37
Browse filesBrowse the repository at this point in the historyBrowse files
feat(webapp,cli): let self-hosted instances require deploy base images
Adds DEPLOY_BASE_IMAGES / DEPLOY_BUILD_BASE_IMAGES (runtime=image csv) to the
webapp. The deployment initialize response carries the images for the deploy's
runtime, and the CLI rewrites the Containerfile to build on them.
Self-hosted instances can require custom base images for deploys, such as FIPS-validated or hardened Node images, with the new `DEPLOY_BASE_IMAGES` webapp setting. The CLI builds on the base images the instance specifies.
Copy file name to clipboardExpand all lines: docs/self-hosting/env/webapp.mdx
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -97,6 +97,8 @@ mode: "wide"
97
97
|`DEPLOY_REGISTRY_NAMESPACE`| No | trigger | Deploy registry namespace. |
98
98
|`DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY`| No | — | Raw IAM policy JSON applied via SetRepositoryPolicy to every ECR repo created by the webapp. Use to grant cross-account pull access to EKS workers when the ECR account is separate from the cluster account. |
99
99
|`DEPLOY_IMAGE_PLATFORM`| No | linux/amd64 | Deploy image platform, same values as docker `--platform` flag. |
100
+
|`DEPLOY_BASE_IMAGES`| No | — | Base images every deploy must build on, per runtime, as `runtime=image` csv, e.g. `node-26=registry.example.com/node-fips:26@sha256:...`. Use for FIPS-validated or hardened images. See [custom base images](/self-hosting/overview#custom-base-images). |
101
+
|`DEPLOY_BUILD_BASE_IMAGES`| No | — | Build-stage toolchain images per runtime, same format as `DEPLOY_BASE_IMAGES`. Defaults to the published `-build` images. |
100
102
|`DEPLOY_TIMEOUT_MS`| No | 480000 (8m) | Deploy timeout (ms). |
Copy file name to clipboardExpand all lines: docs/self-hosting/overview.mdx
+22Lines changed: 22 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -100,6 +100,28 @@ All fields are optional. Partial overrides are supported:
100
100
}
101
101
```
102
102
103
+
## Custom base images
104
+
105
+
Deploys build on the published `triggerdotdev/node` and `triggerdotdev/bun` Debian images. To require a different base for every deploy to your instance, such as a FIPS-validated or hardened Node image, set `DEPLOY_BASE_IMAGES` on the webapp (and optionally `DEPLOY_BUILD_BASE_IMAGES` for the build stage):
The CLI builds with these images for any runtime that has an entry. Runtimes without one keep the published images. With the Helm chart, set them through `webapp.extraEnvVars`.
112
+
113
+
You own a custom base image. It must provide:
114
+
115
+
-`node` (or `bun`) on `PATH` at the runtime's major version
116
+
-`busybox`, `ca-certificates`, `dumb-init`, `git` and `openssl`
117
+
- a `node` user
118
+
- glibc, so native modules built in the build stage load at runtime
119
+
120
+
<Warning>
121
+
`image.pkgs` and build extensions that run `apt-get` (such as `aptGet` and `playwright`) assume a
122
+
Debian base. On other distributions, install those packages in your base image instead.
123
+
</Warning>
124
+
103
125
## Community support
104
126
105
127
It's dangerous to go alone! Join the self-hosting channel on our [Discord server](https://discord.gg/NQTxt5NA7s).
0 commit comments