Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/governance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,4 @@ permissions:

jobs:
governance:
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
2 changes: 1 addition & 1 deletion .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,4 @@ permissions:

jobs:
scan:
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
49 changes: 49 additions & 0 deletions Containerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# SPDX-License-Identifier: MPL-2.0
#
# Containerfile — action-trust-layers (`atl` CLI)
#
# Nix retirement note: this repo's flake.nix predates the estate's
# 2026-06-01 Guix-primary ruling. flake.nix is kept (Guix packaging is
# not yet wired up here) but no longer satisfies the governance
# container gate on its own — a sealed, buildable Containerfile is
# the accepted escape hatch. This file is a real, non-stub build:
# every dependency install below is an active RUN step, and the
# binary produced here is the actual `atl` binary crate.
#
# Toolchain: Rust, edition 2021, single binary crate (see Cargo.toml).
# No rust-toolchain.toml pin exists in this repo to honour, so this
# uses Wolfi's rust-1.89 package (a recent stable release bundling
# both rustc and cargo; Wolfi does not ship a bare "cargo" package —
# `apk add cargo` fails with "no such package").
#
# Multi-stage build:
# Stage 1: compile the `atl` binary with cargo --release --locked
# Stage 2: copy the release binary into a minimal Chainguard glibc
# runtime image (dynamic, not static — Wolfi rust
# binaries are dynamically linked against glibc)
#
# Build: podman build -t action-trust-layers-verify:latest -f Containerfile .
# Run: podman run --rm -it action-trust-layers-verify:latest --help
# Seal: podman build --no-cache -t action-trust-layers:sealed -f Containerfile .

# --- Stage 1: Build (Rust) ---
FROM cgr.dev/chainguard/wolfi-base:latest AS builder

# Rust toolchain (rustc + cargo, rust-1.89 bundles both) as packaged by Wolfi
RUN apk add --no-cache rust-1.89 gcc

WORKDIR /build
COPY Cargo.toml Cargo.lock ./
COPY src ./src

RUN cargo build --release --locked && \
cp target/release/atl /build/atl

# --- Stage 2: Runtime ---
FROM cgr.dev/chainguard/glibc-dynamic:latest

COPY --from=builder /build/atl /usr/bin/atl

USER nonroot

ENTRYPOINT ["/usr/bin/atl"]