#!/bin/sh # Combine the runtime image's CA bundle with the extra certificates here. # # Read out of the image rather than off the host: the container trusts Debian's # CA set, and zeus is Void - splicing the host's bundle in would hand the # containers a different set of roots than the image was built with. set -eu cd "$(dirname "$0")" IMAGE="${IMAGE:-smartbotic-automation:current}" docker run --rm --entrypoint cat "$IMAGE" /etc/ssl/certs/ca-certificates.crt > bundle.crt for cert in *.crt; do [ "$cert" = "bundle.crt" ] && continue printf '\n# %s\n' "$cert" >> bundle.crt cat "$cert" >> bundle.crt done echo "bundle.crt: $(grep -c 'BEGIN CERTIFICATE' bundle.crt) certificates"