build-bundle.sh 695 B

1234567891011121314151617
  1. #!/bin/sh
  2. # Combine the runtime image's CA bundle with the extra certificates here.
  3. #
  4. # Read out of the image rather than off the host: the container trusts Debian's
  5. # CA set, and zeus is Void - splicing the host's bundle in would hand the
  6. # containers a different set of roots than the image was built with.
  7. set -eu
  8. cd "$(dirname "$0")"
  9. IMAGE="${IMAGE:-smartbotic-automation:current}"
  10. docker run --rm --entrypoint cat "$IMAGE" /etc/ssl/certs/ca-certificates.crt > bundle.crt
  11. for cert in *.crt; do
  12. [ "$cert" = "bundle.crt" ] && continue
  13. printf '\n# %s\n' "$cert" >> bundle.crt
  14. cat "$cert" >> bundle.crt
  15. done
  16. echo "bundle.crt: $(grep -c 'BEGIN CERTIFICATE' bundle.crt) certificates"