doc: Suggest setting User in .ssh/config.
[arvados.git] / docker / mkimage-debootstrap.sh
1 #!/bin/bash
2 set -e
3
4 variant='minbase'
5 include='iproute,iputils-ping'
6 arch='amd64' # intentionally undocumented for now
7 skipDetection=
8 strictDebootstrap=
9 justTar=
10
11 usage() {
12         echo >&2
13         
14         echo >&2 "usage: $0 [options] repo suite [mirror]"
15         
16         echo >&2
17         echo >&2 'options: (not recommended)'
18         echo >&2 "  -p set an http_proxy for debootstrap"
19         echo >&2 "  -v $variant # change default debootstrap variant"
20         echo >&2 "  -i $include # change default package includes"
21         echo >&2 "  -d # strict debootstrap (do not apply any docker-specific tweaks)"
22         echo >&2 "  -s # skip version detection and tagging (ie, precise also tagged as 12.04)"
23         echo >&2 "     # note that this will also skip adding universe and/or security/updates to sources.list"
24         echo >&2 "  -t # just create a tarball, especially for dockerbrew (uses repo as tarball name)"
25         
26         echo >&2
27         echo >&2 "   ie: $0 username/debian squeeze"
28         echo >&2 "       $0 username/debian squeeze http://ftp.uk.debian.org/debian/"
29         
30         echo >&2
31         echo >&2 "   ie: $0 username/ubuntu precise"
32         echo >&2 "       $0 username/ubuntu precise http://mirrors.melbourne.co.uk/ubuntu/"
33         
34         echo >&2
35         echo >&2 "   ie: $0 -t precise.tar.bz2 precise"
36         echo >&2 "       $0 -t wheezy.tgz wheezy"
37         echo >&2 "       $0 -t wheezy-uk.tar.xz wheezy http://ftp.uk.debian.org/debian/"
38         
39         echo >&2
40 }
41
42 # these should match the names found at http://www.debian.org/releases/
43 debianStable=wheezy
44 debianUnstable=sid
45 # this should match the name found at http://releases.ubuntu.com/
46 ubuntuLatestLTS=precise
47
48 while getopts v:i:a:p:dst name; do
49         case "$name" in
50                 p)
51                         http_proxy="$OPTARG"
52                         ;;
53                 v)
54                         variant="$OPTARG"
55                         ;;
56                 i)
57                         include="$OPTARG"
58                         ;;
59                 a)
60                         arch="$OPTARG"
61                         ;;
62                 d)
63                         strictDebootstrap=1
64                         ;;
65                 s)
66                         skipDetection=1
67                         ;;
68                 t)
69                         justTar=1
70                         ;;
71                 ?)
72                         usage
73                         exit 0
74                         ;;
75         esac
76 done
77 shift $(($OPTIND - 1))
78
79 repo="$1"
80 suite="$2"
81 mirror="${3:-}" # stick to the default debootstrap mirror if one is not provided
82
83 if [ ! "$repo" ] || [ ! "$suite" ]; then
84         usage
85         exit 1
86 fi
87
88 # some rudimentary detection for whether we need to "sudo" our docker calls
89 docker=''
90 if docker version > /dev/null 2>&1; then
91         docker='docker'
92 elif sudo docker version > /dev/null 2>&1; then
93         docker='sudo docker'
94 elif command -v docker > /dev/null 2>&1; then
95         docker='docker'
96 else
97         echo >&2 "warning: either docker isn't installed, or your current user cannot run it;"
98         echo >&2 "         this script is not likely to work as expected"
99         sleep 3
100         docker='docker' # give us a command-not-found later
101 fi
102
103 # make sure we have an absolute path to our final tarball so we can still reference it properly after we change directory
104 if [ "$justTar" ]; then
105         if [ ! -d "$(dirname "$repo")" ]; then
106                 echo >&2 "error: $(dirname "$repo") does not exist"
107                 exit 1
108         fi
109         repo="$(cd "$(dirname "$repo")" && pwd -P)/$(basename "$repo")"
110 fi
111
112 # will be filled in later, if [ -z "$skipDetection" ]
113 lsbDist=''
114
115 target="/tmp/docker-rootfs-debootstrap-$suite-$$-$RANDOM"
116
117 cd "$(dirname "$(readlink -f "$BASH_SOURCE")")"
118 returnTo="$(pwd -P)"
119
120 set -x
121
122 # bootstrap
123 mkdir -p "$target"
124 sudo http_proxy=$http_proxy debootstrap --verbose --variant="$variant" --include="$include" --arch="$arch" "$suite" "$target" "$mirror"
125
126 cd "$target"
127
128 if [ -z "$strictDebootstrap" ]; then
129         # prevent init scripts from running during install/update
130         #  policy-rc.d (for most scripts)
131         echo $'#!/bin/sh\nexit 101' | sudo tee usr/sbin/policy-rc.d > /dev/null
132         sudo chmod +x usr/sbin/policy-rc.d
133         #  initctl (for some pesky upstart scripts)
134         sudo chroot . dpkg-divert --local --rename --add /sbin/initctl
135         sudo ln -sf /bin/true sbin/initctl
136         # see https://github.com/dotcloud/docker/issues/446#issuecomment-16953173
137         
138         # shrink the image, since apt makes us fat (wheezy: ~157.5MB vs ~120MB)
139         sudo chroot . apt-get clean
140         
141         # while we're at it, apt is unnecessarily slow inside containers
142         #  this forces dpkg not to call sync() after package extraction and speeds up install
143         #    the benefit is huge on spinning disks, and the penalty is nonexistent on SSD or decent server virtualization
144         echo 'force-unsafe-io' | sudo tee etc/dpkg/dpkg.cfg.d/02apt-speedup > /dev/null
145         #  we want to effectively run "apt-get clean" after every install to keep images small
146         echo 'DPkg::Post-Invoke {"/bin/rm -f /var/cache/apt/archives/*.deb || true";};' | sudo tee etc/apt/apt.conf.d/no-cache > /dev/null
147         
148         # helpful undo lines for each the above tweaks (for lack of a better home to keep track of them):
149         #  rm /usr/sbin/policy-rc.d
150         #  rm /sbin/initctl; dpkg-divert --rename --remove /sbin/initctl
151         #  rm /etc/dpkg/dpkg.cfg.d/02apt-speedup
152         #  rm /etc/apt/apt.conf.d/no-cache
153         
154         if [ -z "$skipDetection" ]; then
155                 # see also rudimentary platform detection in hack/install.sh
156                 lsbDist=''
157                 if [ -r etc/lsb-release ]; then
158                         lsbDist="$(. etc/lsb-release && echo "$DISTRIB_ID")"
159                 fi
160                 if [ -z "$lsbDist" ] && [ -r etc/debian_version ]; then
161                         lsbDist='Debian'
162                 fi
163                 
164                 case "$lsbDist" in
165                         Debian)
166                                 # add the updates and security repositories
167                                 if [ "$suite" != "$debianUnstable" -a "$suite" != 'unstable' ]; then
168                                         # ${suite}-updates only applies to non-unstable
169                                         sudo sed -i "p; s/ $suite main$/ ${suite}-updates main/" etc/apt/sources.list
170                                         
171                                         # same for security updates
172                                         echo "deb http://security.debian.org/ $suite/updates main" | sudo tee -a etc/apt/sources.list > /dev/null
173                                 fi
174                                 ;;
175                         Ubuntu)
176                                 # add the universe, updates, and security repositories
177                                 sudo sed -i "
178                                         s/ $suite main$/ $suite main universe/; p;
179                                         s/ $suite main/ ${suite}-updates main/; p;
180                                         s/ $suite-updates main/ ${suite}-security main/
181                                 " etc/apt/sources.list
182                                 ;;
183                 esac
184         fi
185 fi
186
187 if [ "$justTar" ]; then
188         # create the tarball file so it has the right permissions (ie, not root)
189         touch "$repo"
190         
191         # fill the tarball
192         sudo tar --numeric-owner -caf "$repo" .
193 else
194         # create the image (and tag $repo:$suite)
195         sudo tar --numeric-owner -c . | $docker import - $repo:$suite
196         
197         # test the image
198         $docker run -i -t $repo:$suite echo success
199         
200         if [ -z "$skipDetection" ]; then
201                 case "$lsbDist" in
202                         Debian)
203                                 if [ "$suite" = "$debianStable" -o "$suite" = 'stable' ] && [ -r etc/debian_version ]; then
204                                         # tag latest
205                                         $docker tag $repo:$suite $repo:latest
206                                         
207                                         if [ -r etc/debian_version ]; then
208                                                 # tag the specific debian release version (which is only reasonable to tag on debian stable)
209                                                 ver=$(cat etc/debian_version)
210                                                 $docker tag $repo:$suite $repo:$ver
211                                         fi
212                                 fi
213                                 ;;
214                         Ubuntu)
215                                 if [ "$suite" = "$ubuntuLatestLTS" ]; then
216                                         # tag latest
217                                         $docker tag $repo:$suite $repo:latest
218                                 fi
219                                 if [ -r etc/lsb-release ]; then
220                                         lsbRelease="$(. etc/lsb-release && echo "$DISTRIB_RELEASE")"
221                                         if [ "$lsbRelease" ]; then
222                                                 # tag specific Ubuntu version number, if available (12.04, etc.)
223                                                 $docker tag $repo:$suite $repo:$lsbRelease
224                                         fi
225                                 fi
226                                 ;;
227                 esac
228         fi
229 fi
230
231 # cleanup
232 cd "$returnTo"
233 sudo rm -rf "$target"